Omahub
← All plugins
S

Sticky Keys Indicator

by Scott Pruett

Theme-aware bar badges for latched keyd modifier layers.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
89889dc
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs sudo README.md:56

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo systemctl restart keyd

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
89889dc
Reviewed
1 month ago

The plugin is a simple QML bar widget that runs `keyd listen` as the current user and displays badges for active modifier layers. The only flagged item is a `sudo systemctl restart keyd` command in the README, which is documentation for a manual system configuration step, not part of the plugin's executable code. No malicious or harmful behavior was found in the source.

  • The README instructs users to run `sudo systemctl restart keyd` after manually editing /etc/keyd config; this is a documented system-level setup step, not executed by the plugin, and requires explicit user action.
  • The plugin runs `keyd listen` continuously, which is a benign process but depends on the user having appropriate permissions; no elevated privileges are requested.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/scottpruett/omarchy-sticky-keys --enable
Widgets #bar #quickshell #system

Sticky Keys Indicator

A theme-aware sticky-modifier indicator for the Omarchy Quattro bar. It listens to keyd layer changes and displays badges for latched Control, Alt, Shift, and Super layers. Badges remain hidden while no sticky layer is active.

Double-tapping a configured modifier latches it until it is tapped again; the badge remains visible for the full latched state.

Requirements

  • Omarchy Quattro
  • keyd installed and running, with its socket readable by the desktop user (your user must be in the keyd group — check with groups)
  • Modifier layers named control, alt, shift, and meta, each latched by a double-tap

This last requirement is a system-level keyd config, not something the plugin installs for you. It lives in /etc/keyd/, outside this repo, so it does not travel with omarchy plugin add — you must add it by hand on every machine you install this plugin on. If the badges never appear no matter what you tap, this is almost always why: keyd listen is running but never emits a matching layer name.

Merge the following into your /etc/keyd/*.conf (add these sections; don't overwrite bindings you already have for other keys/devices):

[main]
control = oneshot(control)
meta = oneshot(meta)
shift = oneshot(shift)
leftalt = oneshot(alt)

[control]
control = toggle(control)

[meta]
meta = toggle(meta)

[shift]
shift = toggle(shift)

[alt]
leftalt = toggle(alt)

The [main] block makes a single tap of a modifier a one-shot (normal modifier-then-key behavior); a second tap while already in that layer enters the matching [control]/[meta]/[shift]/[alt] block, whose toggle(...) binding is what latches the layer — and is what this plugin's badges reflect.

After editing, apply it with:

sudo systemctl restart keyd

Then verify the events are actually firing before checking the bar:

keyd listen
# double-tap a modifier and confirm you see lines like +control / -control

Install

When this folder is published as a Git repository:

omarchy plugin add https://github.com/scottpruett/omarchy-sticky-keys.git --enable

Configure

omarchy bar move io.github.scottpruett.sticky-keys --section center

Remove

omarchy plugin remove io.github.scottpruett.sticky-keys

Security

The plugin runs keyd listen as the current desktop user. It does not request elevated privileges, alter key bindings, or transmit data.