Omahub
← All plugins
R

PredatorSense

by Rezwoan

Predator laptop control center: one power profile selector, CPU/GPU/fan/battery controls, and keyboard RGB.

Security review

Potentially dangerous behavior detected · 7 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
7123d25
Scanned
1 month ago
  • high persistence setup.sh:106

    Registers scheduled or boot-time system tasks.

    systemctl enable --now nvidia-powerd.service ;;
  • high persistence setup.sh:107

    Registers scheduled or boot-time system tasks.

    systemctl disable --now nvidia-powerd.service ;;
  • high persistence setup.sh:309

    Registers scheduled or boot-time system tasks.

    systemctl enable omarchy-perf-restore.service >/dev/null 2>&1 || true
  • high persistence setup.sh:295

    Writes to system scheduling or boot configuration.

    cat > /etc/systemd/system/omarchy-perf-restore.service <<UNIT
  • high persistence setup.sh:296

    Bundles a systemd unit file.

    [Unit]
  • Docs sudo README.md:109

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo rm -f /usr/local/bin/omarchy-perf-helper \
  • Docs sudo README.md:112

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo systemctl daemon-reload

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Medium
AI risk level
Medium
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
7123d25
Reviewed
1 month ago

No malicious, obfuscated, or credential-stealing code was found; the deterministic high score is largely driven by intentional, user-consented privileged operations (a polkit-gated helper, a boot-time restore service, and nvidia-powerd toggles) plus README sudo examples that are documentation only. The real concerns are the persistent kernel-module blacklist written by enable-keyboard.sh, which the uninstall instructions do not remove, and the E-cores-only CPU control, which could leave a non-hybrid Intel system with only one online CPU. A human should review the full setup.sh and polkit policy before publishing.

  • setup.sh installs and enables a systemd service (omarchy-perf-restore.service) that reapplies the last profile at boot; this is disclosed in the README, but the full unit contents were not visible in the sampled files and should be verified.
  • enable-keyboard.sh writes persistent /etc/modprobe.d and /etc/modules-load.d configuration to blacklist acer_wmi and load linuwu_sense, but the README uninstall instructions do not remove these files, leaving persistent system changes after uninstall.
  • The helper's cpu-cores ecore / profile ultra path can offline all but cpu0 on non-hybrid SMT Intel systems, potentially making the machine unusable; the README claims general Intel intel_pstate + RAPL compatibility, so this is a real safety concern on unsupported hardware.
  • Privileged setup runs `pkexec bash` on a script located in the user-writable plugin directory; the polkit policy was not fully sampled and should be confirmed to be scoped exactly to the helper path with no NOPASSWD rules.
  • The deterministic scan's README sudo findings are documentation-only, and the systemctl enable/disable nvidia-powerd findings are user-invoked helper verbs rather than install-time persistence.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Rezwoan/Omarchy-PredatorSense --enable
System #system

PredatorSense — for Acer Predator laptops

An Omarchy omarchy-shell plugin: a real power/CPU/GPU/battery/keyboard control center in your bar, built specifically for Acer Predator laptops (and useful, minus the Acer-only bits, on any Intel intel_pstate + RAPL laptop).

Tested on: Acer Predator Helios Neo 16 (PHN16-71), Intel i5-13500HX, NVIDIA RTX 4050. Every control below — the Profile selector, CPU turbo/cores/frequency/power-limit, thermal profile, GPU mode switching, 80% battery charge limit, fan speed, and all keyboard-RGB modes — was verified working end to end on that exact model before this was published.

General tab

This is an independent, unofficial project — not affiliated with, endorsed by, or supported by Acer Inc. "Predator" and the Predator logo are trademarks of Acer Inc., used here only to identify the hardware this plugin targets. See NOTICE.md.

Why

Windows has Acer's own PredatorSense app. Omarchy didn't have anything, so this ports the useful parts of it — plus a few things the original doesn't even do (CPU core-count control, RAPL power-limit presets) — into a proper bar widget that matches your theme, under the same name.

Install

omarchy plugin add https://github.com/Rezwoan/Omarchy-PredatorSense.git --enable --yes

That's it — no terminal, no sudo, nothing else to run. The panel works immediately in read-only mode (live status only). The first time you want to actually change something, click Enable privileged controls in the panel — that's a single native password prompt (via polkit), not a command you type. See How it works for why this is safe.

Optionally move it in the bar or bind a key to summon it:

omarchy bar move io.github.rezwoan.performance --section right

Unlocking the Acer-only sections

Two optional AUR packages unlock more of the panel — everything else works without them:

Package Unlocks
linuwu-sense-dkms Keyboard tab (RGB), 80% battery charge limit, fan speed
envycontrol GPU mode switching (Integrated / Hybrid / Nvidia)

If linuwu-sense-dkms is installed but the Keyboard tab still says it isn't detected, its kernel module probably lost the race to the stock acer_wmi driver at boot — the panel detects this and shows an Enable keyboard RGB now button that fixes it with, again, one click and one password prompt. No manual modprobe/blacklist editing.

What it does

General tab

  • One unified Profile selector — Ultra Saver / Saver / Balanced / Performance / Ultra Performance / Custom — each named preset bundling CPU cores, turbo, frequency cap, RAPL power limit, thermal profile, fan, keyboard color, and screen brightness. Persisted and silently reapplied on every boot. Custom isn't a real preset — it's a passive indicator that lights up whenever a raw control below (or in the Advanced popover) has been hand-tuned since the last named preset was applied.
  • Advanced (small gear ⚙ button next to the GPU-stats/battery-info icons): the raw power profile (power-profiles-daemon) and thermal profile (every platform_profile your firmware exposes, not a hardcoded list) controls, for manual overrides outside the named presets.
  • CPU: turbo boost, core mode (all / no hyperthreading / E-cores only), max frequency cap, RAPL package power limit
  • GPU: mode switching (needs envycontrol, reboot required), Nvidia dynamic-boost toggle
  • Battery: live percentage/status, 80% charge-limit toggle, fan speed

CPU, GPU, battery, and fan controls

Keyboard tab (4-zone RGB)

  • Brightness (5 steps)
  • Static colors: theme accent, live Predator-mode color (green/magenta/blue, matching whatever the bar icon is currently tinted), plus 9 fixed swatches
  • 7 animated effects (Breathing / Neon / Wave / Shifting / Zoom / Meteor / Twinkling)
  • Quick actions: match Omarchy theme, match Predator mode

The bar icon is the Predator claw mark, recolored live to match your active mode — green for battery saver, neon magenta for performance, blue for balanced, your theme's foreground color otherwise.

Keyboard tab

How it works

Every privileged write goes through one root-owned, verb-whitelisted script (/usr/local/bin/omarchy-perf-helper) — it only accepts an exact, hardcoded set of verbs/values (turbo on|off, cpu-cores all|no-smt|ecore, six-digit hex colors validated by regex, etc.) and refuses everything else. It can't be redirected into running arbitrary commands even though it runs as root.

Authorization is a polkit action scoped to that exact binary path (org.freedesktop.policykit.exec.path), not a sudoers file. There is no passwordless (NOPASSWD) rule anywhere — that's a deliberately avoided anti-pattern, not an oversight. polkit's auth_admin_keep means you authenticate once and it's remembered for a few minutes, not on every single click, the same mechanism tools like GParted and Timeshift use. setup.sh (what the "Enable privileged controls" button runs, via pkexec) installs the helper and this policy — nothing is installed until you click that button.

Uninstall

omarchy plugin remove io.github.rezwoan.performance
sudo rm -f /usr/local/bin/omarchy-perf-helper \
           /usr/share/polkit-1/actions/io.github.rezwoan.performance.helper.policy \
           /etc/systemd/system/omarchy-perf-restore.service
sudo systemctl daemon-reload

(The last three lines only apply if you'd clicked "Enable privileged controls" — skip them if you never did.)

Compatibility

Feature Requires
Bar icon, status, Profile selector, power profile Any Omarchy 4.0.1+ install
Thermal profile, CPU turbo/cores/frequency, RAPL power limit Intel CPU with intel_pstate + RAPL (most 8th-gen+ Intel laptops)
GPU mode switching, dynamic boost NVIDIA Optimus laptop + envycontrol
Keyboard RGB, 80% battery limit, fan speed Acer laptop + linuwu-sense-dkms

Not an Acer Predator? The General tab (minus GPU/battery-limit/fan) still works on any Intel laptop. The Keyboard tab and those two General-tab rows will just stay hidden.

Issues & contributing

Found a bug, or your Predator model behaves differently? Open an issue — bug report or feature request. PRs welcome; see CONTRIBUTING.md for the project layout and how to test a change for real (hot-reload on an already-placed bar widget is unreliable — that file explains the actual verification loop).

License

MIT