Omahub
← All plugins
M

Kefir: KEF Speakers

by melonamin

Control KEF wireless speakers: power, volume, source, and playback

Security review

Review recommended · 4 findings

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
c36b5e6
Scanned
1 month ago
  • Augments a command with octal/hex escape sequences.

    \032II;AirPlay Remote Video;local',
  • Augments a command with octal/hex escape sequences.

    \032II;AirPlay Remote Video;local;kef_one-841715171e27.local;10.10.10.30;7000;"acl=0" "deviceid=84:17:15:17:1E:27" "model=LS50 Wireless II" "manufacturer=KEF" "serialNumber=24c0201d-0dcb-4d3d-a14e-c96
  • Augments a command with octal/hex escape sequences.

    \032II;AirPlay Remote Video;local;kef_one-841715171e27.local;10.10.10.30;7000;"acl=0" "deviceid=84:17:15:17:1E:27" "model=LS50 Wireless II" "manufacturer=KEF" "serialNumber=24c0201d-0dcb-4d3d-a14e-c96
  • Augments a command with octal/hex escape sequences.

    \032II"), "LS50 Wireless II")

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
c36b5e6
Reviewed
1 month ago

The plugin is a KEF speaker controller that uses curl and avahi-browse for local network communication. The deterministic scan flagged octal escape sequences in test data, but these are just avahi output examples and not obfuscation. No malicious behavior found.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/melonamin/omarchy-kefir --enable
Widgets #bar #quickshell #media

Kefir for Omarchy

Control KEF wireless speakers (LSX II, LS50 Wireless II, LS60) from the Omarchy bar. Talks directly to the speaker's KEF Connect HTTP API on the local network — no daemon, no CLI dependency. Same protocol as SwiftKEF / Kefir / KefirCLI.

Features

  • Bar pill showing speaker state (off/standby, on, muted), with tooltip
  • Popup panel: power switch, volume slider with mute, input source picker, and a now-playing card with album art, track/artist/album, a progress bar, and play/pause/next/previous
  • Transport buttons follow the speaker's own controls capability report, so they enable only on sources that support them (streaming, not passthrough); passthrough pseudo-tracks ("COAX", "OPT", ...) are filtered out of the card
  • Scroll the bar icon to change volume (with OSD), right-click to mute, middle-click to play/pause
  • Panel keys: h/l volume, m mute, Enter/Space play/pause, Esc close

Install

omarchy plugin add https://github.com/melonamin/omarchy-kefir.git --enable
omarchy bar set melonamin.kefir host <speaker-ip>

Or skip the second step: with no host configured, opening the panel scans the local network (mDNS via avahi) and lists the KEF speakers it finds — click one to adopt it. Setting the IP manually remains available for networks without mDNS.

To remove:

omarchy plugin remove melonamin.kefir

Removal deletes the plugin checkout and its bar entry; the plugin stores no other state.

Dependencies

Only curl and avahi-browse (for discovery), both shipped with Omarchy by default. The plugin talks HTTP to the speaker on your LAN and never contacts anything else. (node is used for the test suite only.)

IPC

For Hyprland keybindings:

omarchy-shell melonamin.kefir toggle      # open/close the panel
omarchy-shell melonamin.kefir volumeUp    # +5
omarchy-shell melonamin.kefir volumeDown  # -5
omarchy-shell melonamin.kefir mute
omarchy-shell melonamin.kefir playPause

Notes

  • Mute is volume-0 with the previous level remembered, matching Kefir.
  • Writes are POSTs with a JSON body; firmware p20.x rejects the older query-param setData with 405.
  • Selecting a source while in standby powers the speaker on (KEF behavior).

Tests

node --test tests/model.test.js        # unit: wire-format parsing/building
tests/integration.sh <speaker-ip>      # live read-only poll against a speaker