Omahub
← All plugins
V

SysProcess Manager

by Vivek Joshi

Bar widget for live CPU, RAM, swap, processes, systemd services, and installed packages.

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
4f1f88c
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs sudo README.md:19

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo or pkexec is required.
  • Docs sudo README.md:68

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo or pkexec is required. Process signals and `systemctl` actions run as the logged-in user and cannot escalate privileges.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
4f1f88c
Reviewed
1 month ago

The plugin is a system monitoring widget that reads /proc and runs standard user-level commands like ps, journalctl, and kill. It does not use sudo or pkexec, and the deterministic scan's medium findings are false positives from the README text stating 'No sudo or pkexec is required.' The code is transparent, has no obfuscation, and performs no network calls or credential access.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/joshivivek67/omarchy-sys-process-manager --enable
System #bar #quickshell #system

SysProcess Manager

Omarchy Quattro bar widget for live CPU, RAM, swap, processes, systemd services, and installed packages.

Click the chip on the bar to open a dashboard with telemetry cards, tabs, search, filters, process end, service start/stop/restart, and journal logs.

Preview

SysProcess Manager dashboard

This plugin runs inside omarchy-shell (unsandboxed, with your user permissions). Review the code before you enable it.

Install

omarchy plugin add https://github.com/joshivivek67/omarchy-sys-process-manager.git --enable

Omarchy clones the repository, validates manifest.json, and asks before enabling it. No sudo or pkexec is required.

Place or move the widget if it is not already on the bar:

omarchy bar put io.github.joshivivek67.sys-process-manager --section right

Usage

  • Left-click the bar chip to toggle the panel.
  • Processes — search, filter (running / dead / CPU / RAM / your user), end a process with confirmation (SIGTERM).
  • System Services — start, stop, restart, and view journalctl logs as the logged-in user.
  • Libraries & Packages — browse installed packages (pacman -Q or dpkg-query). Read-only; this plugin does not install or remove packages.
  • Start Process — run a command in the background as your user.

Keyboard while the panel is open:

Key Action
1 / 2 / 3 Processes / Services / Packages
/ Focus search
n Start process
r Refresh
Escape Close

Remove

omarchy plugin remove io.github.joshivivek67.sys-process-manager

That disables the plugin, then deletes the git checkout. Your other Omarchy config is left alone.

Dependencies

Required:

  • Omarchy Quattro (omarchy-shell / Quickshell)
  • python3
  • bash
  • ps

Optional, used only if present:

  • systemctl — list units and start/stop/restart as the current user
  • journalctl — service logs
  • pacman or dpkg-query — list installed packages (query only)

No network calls. No sudo or pkexec is required. Process signals and systemctl actions run as the logged-in user and cannot escalate privileges.

License

MIT. See LICENSE.