Omahub
← All plugins
N

Voxbox

by nousd

Reads anything on your screen aloud. 100% offline. 51 languages.

Security review

Review recommended · 4 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
fee2a33
Scanned
1 month ago
  • medium sudo install.sh:26

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S python ffmpeg) and re-run."
  • medium sudo install.sh:59

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S python-gobject gtk4 libadwaita) and re-run."
  • Docs external_hosts README.md:32

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/nousd/voxbox.git && cd voxbox && ./install.sh
  • Docs sudo README.md:38

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S --needed python python-gobject gtk4 libadwaita ffmpeg \

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
fee2a33
Reviewed
1 month ago

The plugin is a legitimate offline screen-reading/TTS tool. The deterministic scan's medium findings are documentation-only: the sudo commands appear in README instructions and in installer warning messages, but install.sh never executes sudo itself. Downloads are sha256-verified and size-capped, dependencies are hash-pinned, and no obfuscation, persistence, credential theft, or destructive behavior was found.

  • The installer downloads a large (~340 MB) model and installs Python packages, but all artifacts are verified against pinned sha256 hashes and the user must explicitly trigger installation.
  • The README's standalone install path runs a cloned install.sh, which is normal for this kind of tool but still executes third-party code; the script itself is transparent and non-destructive.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/nousd/voxbox --enable
Productivity #quickshell #media

Voxbox

Reads anything on your screen aloud. 100% offline — no cloud, no accounts, no privacy concerns.

Voxbox

  • Drag a box over anything on screen → OCR → speech
  • Read your text selection, or a PDF / EPUB / txt / HTML file
  • 51 languages offline, auto-detected per sentence — mixed-language text just works
  • Export to MP3 / WAV / FLAC / OGG
  • Omarchy shell plugin (bar widget + native panel) and standalone GTK4 app
  • Follows your Omarchy theme, live

Install

Omarchy plugin:

omarchy plugin add https://github.com/nousd/voxbox.git --enable

Click the new bar icon and press Install speech engine (one-time ~600 MB, sha256-verified) — or run ~/.config/omarchy/plugins/io.github.nousd.voxbox/install.sh.

Bar icon: click — panel · right-click — capture a region · middle — play/pause. No keybindings are installed — bind voxbox or omarchy-shell shell toggle io.github.nousd.voxbox however you like.

Standalone (any Wayland desktop):

git clone https://github.com/nousd/voxbox.git && cd voxbox && ./install.sh

System packages (Arch):

sudo pacman -S --needed python python-gobject gtk4 libadwaita ffmpeg \
  grim slurp hyprpicker tesseract tesseract-data-eng wl-clipboard poppler

More languages — voice and OCR data, no root:

voxbox-add-language el de      # no arguments lists what you can add

Uninstall

~/.config/omarchy/plugins/io.github.nousd.voxbox/uninstall.sh   # or ./uninstall.sh from a clone

Removes everything: bar widget, engine, voices, launcher entry. --purge removes your settings too. (The app launcher's own "Uninstall" only removes the launcher entry — that's how Omarchy treats local apps.)

Built on kokoro-onnx, piper, lingua and tesseract. MIT — see LICENSE.