Omahub
← All plugins
T

MSI GP66 Fan Control

by Tommaso Piazza

MSI GP66 MS-1542 EC fan monitoring and Cooler Boost

Security review

Potentially dangerous behavior detected · 3 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
b2d350b
Scanned
1 month ago
  • high persistence install.sh:29

    Registers scheduled or boot-time system tasks.

    systemctl disable --now msi-gp66-fan-control.service 2>/dev/null || true
  • high persistence install.sh:49

    Registers scheduled or boot-time system tasks.

    systemctl enable msi-gp66-fan-control.service
  • Bundles a systemd unit file.

    [Unit]

Automated analysis only — not a security guarantee.

AI advisory review

Review recommended

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Medium
AI risk level
Medium
Recommendation
review
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
b2d350b
Reviewed
1 month ago

This is a legitimate-looking hardware utility that installs a root systemd service to read MSI EC telemetry and toggle Cooler Boost. The deterministic scan's 'high' findings are expected consequences of the plugin's stated purpose (installing a systemd unit and enabling it at boot), not evidence of malicious behavior. However, the code has real security weaknesses: the Unix socket has no authentication or CSRF-style protection, the helper runs as root and can write to EC registers, and the install script has a minor path-injection issue, so a human should review before publishing.

  • The root service exposes an unauthenticated Unix socket at /run/msi-gp66-fan-control.sock. Any local user can connect and toggle Cooler Boost, which is a denial-of-service / hardware-abuse vector on a laptop.
  • The helper runs as root and writes to EC registers (0xF4, 0x98) with only a board-name check. A bug in the EC write path or a malicious local user could potentially corrupt EC state, though the code does validate board and register addresses.
  • install.sh uses `install -o "$install_uid" -g "$install_gid"` where install_uid/install_gid come from SUDO_UID/SUDO_GID. If SUDO_UID is set but SUDO_GID is not, install_gid will be empty, causing install to fail or misbehave. This is a robustness issue, not a security hole.
  • The service file runs `modprobe ec_sys write_support=0` at boot, which is expected for this hardware, but it means the EC is accessible via debugfs. The helper does not verify the integrity of the EC snapshot, so a malicious EC could return arbitrary data, but this is a low-risk concern.
  • The socket accepts any JSON with a 'command' field and only whitelists 'status' and 'cooler-boost', which is good. However, the 'cooler-boost' command does not validate the value type beyond 'on'/'off', and the helper's run() function accepts 'set-mode' and other commands via the CLI, but the socket only exposes the two whitelisted commands. This is acceptable but worth noting.
  • The install script copies BarWidget.qml and manifest.json to the user's config directory, but it does not copy the Python helper/client to the plugin directory; it installs them to /usr/local/libexec. This is fine, but the uninstaller removes the entire plugin directory with `rm -rf "$plugin_dir"`, which could delete user data if the path is ever misconfigured. The path is derived from the user's home, so it's low risk.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/tmspzz/omarchy-msi-gp66-fan-control --enable
Hardware #bar

Omarchy MSI GP66 Fan Control

Beta release — 0.1.0-beta

An Omarchy bar widget for MSI GP66 Leopard MS-1542 laptops. The plugin manifest and BarWidget.qml are at the repository root, as required for a Git-hosted Omarchy plugin.

The plugin uses the kernel ec_sys interface with the reviewed G1_3 register layout. A root-owned system service provides read-only status over a local Unix socket. Explicit Cooler Boost writes use the fixed root-owned helper and are validated against the board and allow-listed registers.

Install

sudo ./install.sh
omarchy restart shell

Remove the installed service, helper, client, and widget with:

sudo ./install.sh --uninstall

For a Git-hosted plugin, install it with omarchy plugin add, then enable msi.gp66-fan-control in the bar. The system installer is still required because the MSI embedded controller is protected by the kernel.

The installer loads ec_sys read-only at boot and enables the telemetry service. It does not install Python packages or GUI dependencies.

Controls

  • Fan icon: status and temperatures in the tooltip
  • Left-click: enable Cooler Boost through the privileged service
  • Right-click: disable Cooler Boost through the privileged service
  • Middle-click: refresh status

This plugin specifically targets the MSI GP66 Leopard MS-1542 family (10UH/10UE/10UG). It is not a generic MSI fan controller.

The implementation, including Cooler Boost writes, has been hardware-validated only on an MSI GP66 Leopard 10UH in the MS-1542 family. Cooler Boost writes are hardware-specific and must not be enabled on other models or firmware versions unless separately validated. Unsupported boards refuse operation. EC writes can affect hardware; use at your own risk.