Omahub
← All plugins
Q

NVMe Health

by qadram

Disk SMART health in the Omarchy bar via UDisks2: power-on hours, reallocated sectors, TBW, and remaining life.

Security review

Potentially dangerous behavior detected · 1 finding

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
f15f1aa
Scanned
1 month ago
  • high destructive_filesystem status.py:285

    Destructive operation on the root filesystem or a block device.

    /dev/sda

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
f15f1aa
Reviewed
1 month ago

The deterministic scan's 'high' finding is a false positive: the `/dev/sda` string at status.py:285 is a block-device path used for read-only SMART health lookups via UDisks2 D-Bus, not a destructive operation. The plugin only reads SMART attributes and disk metadata; there is no write, format, mount, or destructive filesystem operation anywhere in the code. The code is notably defensive (timeouts, output size caps, input sanitization, no shell invocation), and the QML/Python/JS are all consistent with a legitimate read-only system monitor.

  • The deterministic scanner flagged `/dev/sda` as a destructive filesystem operation, but this is a device path used to match/display SMART data from UDisks2 — a read-only operation.
  • status.py is truncated in the sample, but the visible code and the scan results show only read-only D-Bus property access with proper bounds and timeout handling.
  • The QML executes `python3 status.py` with a sanitized device argument (single argv element, length-capped), so there is no command injection risk.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/qadram/omarchy-nvme-health --enable
Hardware #bar #quickshell #system

NVMe Health

NVMe Health panel on Omarchy

SMART disk health for the Omarchy Quattro bar: remaining life, power-on hours, media errors / reallocated sectors, and TBW.

Reads SMART through UDisks2 (already on Omarchy). No smartctl, no root, no sudoers.

Install

omarchy plugin add https://github.com/qadram/omarchy-nvme-health.git --enable

Or from a local checkout:

PLUGIN_ID=io.github.qadram.nvme-health
PLUGIN_DIR="$HOME/.config/omarchy/plugins/$PLUGIN_ID"
mkdir -p "$PLUGIN_DIR"
cp -a manifest.json BarWidget.qml Panel.qml Model.js status.py "$PLUGIN_DIR/"
chmod +x "$PLUGIN_DIR/status.py"
omarchy plugin validate "$PLUGIN_DIR"
omarchy-shell shell rescanPlugins
omarchy plugin enable "$PLUGIN_ID" --section right

Usage

  • Left click: open the details panel
  • Middle click (bar) or R / Enter (panel): refresh
  • Bar label: remaining life %, or ! when something looks wrong

Configure

omarchy bar move io.github.qadram.nvme-health --section right

Optional settings on the widget entry in ~/.config/omarchy/shell.json:

  • refreshIntervalSec — 60–3600 (default 300)
  • device — e.g. /dev/nvme0n1 (empty = first NVMe)

Remove

omarchy plugin remove io.github.qadram.nvme-health

License

MIT