Omahub
← All plugins
E

SongRec

by Elliot

Identify the song playing on your computer or around you, like Shazam in iOS Control Center.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
bec2686
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
bec2686
Reviewed
1 month ago

This plugin is a straightforward SongRec wrapper: it captures audio via `songrec`, parses matches, downloads cover art with `curl`, and shows notifications with optional click-to-open actions. The only elevated action is an optional, user-triggered `pkexec pacman -S songrec` install that is clearly documented and requires polkit approval. I found no obfuscation, hidden persistence, credential theft, or destructive commands; external input is passed as argv or shell-quoted.

  • On first use, if `songrec` is not installed, the plugin runs `pkexec pacman -S --noconfirm --needed songrec`, which modifies the system as root; this is disclosed in the README and gated by the desktop polkit prompt, but it is still a privileged side effect.
  • The plugin runs in the unsandboxed user shell and executes external commands (`songrec`, `curl`, `xdg-open`, `busctl`, `spotify`) using data from Shazam responses; I saw no shell injection because arguments are either argv-separated or quoted, but remote data does influence what is opened or downloaded.
  • Cover art is downloaded from a URL supplied by the recognition service into `~/.cache/omarchy/songrec`; it is shell-quoted and limited with `--max-time`, so the risk is low.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/cempack/SongRec --enable
Widgets #bar #quickshell #media

SongRec for Omarchy

Identify the song playing on your computer or around you from the Omarchy bar, like Shazam in iOS Control Center.

Click the waveform icon to start listening. It uses the theme accent and pulses while SongRec runs. On a match, a notification shows album art, title, and artist. Click the notification to play the track in Spotify (or open Shazam if no Spotify link is available).

Tap again while listening to cancel. After about 20 seconds with no match, listening stops and a “No match found” notification appears.

Requirements

If SongRec is missing, the first click (or the hotkey) installs songrec with pkexec pacman. Omarchy’s polkit dialog asks for your fingerprint or password. After it succeeds, listening starts automatically.

By default it listens to computer playback (the default speaker/headphone monitor) and the microphone at the same time, and uses whichever match arrives first. Set audioDevice to force a single device from songrec recognize -l.

Optional: the official Spotify desktop client, so notification clicks can play the match in the running app.

Install

omarchy plugin add https://github.com/cempack/SongRec.git --enable

Usage

  • Left click the bar icon — start or cancel listening
  • Super+Shift+Z — same toggle, if you bind it (see below)
  • omarchy-shell io.github.cempack.songrec toggle

Settings

Inline on the bar layout entry in ~/.config/omarchy/shell.json:

Key Default Meaning
audioDevice "" Device from songrec recognize -l. Empty listens to playback and the microphone.
timeoutSec 20 Seconds to listen before giving up (5–60).
omarchy bar move io.github.cempack.songrec --section right

Keyboard shortcut

o.bind("SUPER + SHIFT + Z", "Identify song", "omarchy-shell io.github.cempack.songrec toggle")

Privileges and external commands

This plugin runs inside the Omarchy shell (your user session, unsandboxed). It may run:

  • songrec recognize --json to identify audio
  • pkexec pacman -S --noconfirm --needed songrec only when SongRec is not installed
  • curl to download cover art into ~/.cache/omarchy/songrec
  • omarchy-notification-send for match and status toasts
  • busctl / omarchy-launch-spotify / spotify --uri= / xdg-open when you click a match notification

It does not change system files except the optional polkit-authorized songrec package install.

Tests

./tests/run

Remove

omarchy plugin remove io.github.cempack.songrec

License

MIT. See LICENSE.