Omahub
← All plugins
M

omaspeedmeter

by mt-shihab26

Omarchy bar widget showing CPU, memory, network, temperature, GPU, and process count stats.

Security review

Review recommended · 2 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
5fe6197
Scanned
1 month ago

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
5fe6197
Reviewed
1 month ago

This is a straightforward system-monitor bar widget that reads /proc and /sys metrics and invokes local tools like nvidia-smi, intel_gpu_top, and the omarchy CLI. The deterministic scan's medium findings are limited to GitHub Actions CI workflows (cloning the Omarchy repo and installing Prettier globally) and do not run on a user's machine during install or runtime. No obfuscation, network exfiltration, destructive commands, or hidden persistence were found in the sampled plugin code.

  • The deterministic scan flags external-host access and global npm installs, but both are confined to .github/workflows and never execute as part of plugin installation or normal use.
  • The right-click systemMonitor setting is user-configurable and is passed to a launcher command, so a maliciously edited local config could launch an arbitrary program; this requires explicit local tampering and is not a remote or install-time risk.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/mt-shihab26/omaspeedmeter --enable
System #bar

Omaspeedmeter

Omarchy 4.0+ Validate MIT License

Omarchy bar widget showing CPU, memory, swap, network, temperature, GPU, and process count stats.

Click the widget in the bar to open a settings popup where you can toggle metrics, reorder segments, split network into up/down segments, switch icons for word labels, move the widget between bar sections, and change the refresh interval, GPU vendor, temperature source, and network interface — all without editing config files by hand. Right-click the widget to open a system monitor (btop by default, or htop).

<table> <tr> <td><img src="preview.png" width="100%" alt="Omaspeedmeter bar widget preview"></td> <td><video src="https://github.com/user-attachments/assets/61c83f7d-98f9-4b38-8a60-5e8d97d5fa49" width="100%" controls></video></td> </tr> </table>

Installation

omarchy plugin add https://github.com/mt-shihab26/omaspeedmeter.git --enable

To remove it:

omarchy plugin remove mt-shihab26.omaspeedmeter

See the Omarchy plugin manual for more on omarchy plugin commands.

Metrics

Metric Source Notes
Network /sys/class/net/<iface>/statistics/*_bytes Combined or split into download/upload
CPU /proc/stat Usage % since the previous poll
Temp /sys/class/thermal/thermal_zone*/temp Prefers the CPU package/core sensor
Memory /proc/meminfo (MemTotal - MemAvailable) / MemTotal
Swap /proc/meminfo (SwapTotal - SwapFree) / SwapTotal; shows … if no swap is configured
GPU nvidia-smi, sysfs, or intel_gpu_top Vendor auto-detected
Procs /proc/[0-9]* Count of running process directories

Each metric shows as a Nerd Font glyph icon by default, from the glyph set Omarchy already ships for the bar, so they render consistently with the built-in widgets. Enable word labels in the settings popup to show CPU, MEM, etc. instead.

CPU and network are rate-based and need two polls to produce a real number, so they show … for the first tick after the widget loads or after the refresh interval changes.

Settings

All settings are toggled/edited from the bar widget's click popup, and are persisted via omarchy bar set.

Setting Default Description
net true Show network speed
cpu true Show CPU usage %
temp false Show CPU temperature
mem true Show memory usage %
swap false Show swap usage %
gpu false Show GPU usage %
procs false Show running process count
netSplit false Show download/upload as two separate segments
labels false Show word labels (CPU, MEM, ...) instead of icons
interval 2 Refresh interval, in seconds
gap 17 Spacing between segments, in pixels (matches Omarchy's own bar widget spacing)
gpuVendor auto auto, nvidia, amd, intel, or none
netIface auto auto, or a specific network interface name
tempZone auto auto, or a specific /sys/class/thermal/thermal_zone*/temp path
systemMonitor btop btop or htop; opened by right-clicking the widget
order (insertion order) Segment display order; set with the ▲/▼ buttons in the popup's METRICS list

auto for GPU vendor and temperature zone probes the system on each poll; pinning a specific value skips detection and avoids picking the wrong sensor on machines with multiple thermal zones or GPUs. The network interface and temperature zone dropdowns are populated live from /sys/class/net and /sys/class/thermal when the popup opens.

The bar position dropdown (left/center/right) reads and writes the widget's placement via omarchy-shell/ omarchy bar move, independent of the defaultSection set on first install.

Each row in the popup's METRICS list has ▲/▼ buttons to move that metric up or down; the bar segments re-render in the new order immediately, and it persists the same way as every other setting. The ↺ button next to the popup title resets every setting in the table above back to its default, including the segment order.

Config file

Every setting above (plus the bar position) is also mirrored to a hand-editable JSON file at ~/.config/omaspeedmeter/config.json ($XDG_CONFIG_HOME/omaspeedmeter/config.json if set), kept in sync with the popup in both directions:

  • Changing a setting in the popup updates the config file.
  • Editing the config file (with the widget running) applies the change live — through the same path a popup click would use, so it also updates via omarchy bar set/omarchy bar move and stays consistent with the popup.
{
    "cpu": true,
    "mem": true,
    "swap": false,
    "net": true,
    "temp": false,
    "gpu": false,
    "procs": false,
    "labels": false,
    "netSplit": false,
    "interval": 2,
    "gap": 17,
    "gpuVendor": "auto",
    "tempZone": "auto",
    "netIface": "auto",
    "systemMonitor": "btop",
    "order": ["net", "cpu", "temp", "mem", "swap", "gpu", "procs"],
    "section": "right"
}

order and section accept the same values as the order setting and bar position dropdown above; unknown keys are ignored and missing keys keep their current value.

How it works

Each metric is collected by a small standalone bash script in bin/, run on a timer by BarWidget.qml and merged into a single stats object:

Each script only runs when its metric is enabled, and only prints a single line of JSON (e.g. {"cpu":42}), which Model.js parses and formats into the bar segments. Model.js holds all the pure logic (settings resolution, formatting, segment building) separately from the QML so it can be reasoned about — and unit tested — without a Quickshell runtime.

Right-clicking the widget opens the configured systemMonitor (btop by default, or htop) via omarchy-launch-or-focus-tui, focusing an existing window for it instead of spawning a duplicate if one is already open.

~/.config/omaspeedmeter/config.json is watched with a Quickshell FileView, the same mechanism the Omarchy shell itself uses to hot-reload ~/.config/omarchy/shell.json. A change to either side — the popup or the file — is serialized through the same setSetting/setSection calls, so both stay consistent with each other and with omarchy bar set/omarchy bar move.

Requirements

  • Linux with /proc and /sys available (standard on any distro).
  • awk, bash, ip — present on virtually every system.
  • GPU stats additionally require, depending on vendor:
  • Right-click requires whichever systemMonitor is configured (btop or htop) to be installed.

If a required tool is missing, that metric's script emits null and the segment is skipped rather than erroring.

Project structure

.
├── .github/workflows/validate.yml  # CI: lint/format check on push and PR
├── CHANGELOG.md                    # notable changes per version
├── bin/                            # standalone stat-collector scripts, one per metric
│   ├── omaspeedmeter-cpu
│   ├── omaspeedmeter-gpu
│   ├── omaspeedmeter-mem
│   ├── omaspeedmeter-net
│   ├── omaspeedmeter-procs
│   ├── omaspeedmeter-swap
│   └── omaspeedmeter-temp
├── BarWidget.qml                   # bar segment UI, settings popup, polling timer
├── Model.js                        # pure logic: settings resolution, formatting, segments
├── manifest.json                   # Omarchy plugin manifest (id, defaults, settings schema)
├── format.sh                       # qmlformat + Prettier, run before committing
├── link.sh                         # symlinks the repo into ~/.config/omarchy/plugins
└── preview.png                     # screenshot used in this README

Development

git checkout dev

Development happens on dev. Run ./rebase.sh to keep it current with main: it pulls main, rebases dev onto it, and force-pushes dev.

./link.sh

Symlinks ~/.config/omarchy/plugins/omaspeedmeter to this repo, so Omarchy loads the plugin straight from your working tree instead of a copy. Run ./link.sh --remove to remove the symlink.

omarchy restart shell

Restarts the Omarchy shell to pick up changes (BarWidget.qml is not hot-reloaded).

./format.sh

Formats the repo: qmlformat for BarWidget.qml, Prettier for Markdown/JSON/JS. Run before committing.

Changelog

See CHANGELOG.md for notable changes per version.

License

This project is licensed under the MIT License.