Omahub
← All plugins
M

Resonance

by mystaryo

Live cava spectrum with 18 selectable visual styles in the bar. Click for Now Playing (any MPRIS player, cover art, transport), a cliamp radio tab, and settings.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
bd4951e
Scanned
5 days ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
bd4951e
Reviewed
5 days ago

No malicious or destructive behavior found. The widget's use of external processes (cava, parecord, cliamp) and local config writes is disclosed in the README and scoped to the bar widget, with no credential access, obfuscation, or hidden persistence.

  • The widget records the default PulseAudio sink monitor via parecord for the spectrum; audio stays local but users should be aware of the system-audio tap.
  • It can auto-start the cliamp daemon and writes settings to ~/.config/omarchy/mystaryo.media.json; both are expected, user-visible behavior.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/ShravyaKudlu/omarchy-plugin-resonance --enable

Resonance — spectrum bar widget + player popup

Live cava spectrum in the Omarchy bar. The strip is a stock WidgetButton, so hover tooltip, pointing-hand cursor, and click routing behave exactly like the built-in widgets. Hover shows the playing track in a pill below the bar (title — artist). Left-click opens a three-tab popup, right-click toggles Words/Spectrum.

Settings tab radio tab now_playing_tab

  • Now Playing: any MPRIS player, tracked directly (no dependency on the stock omarchy.media service) — cover art, title, artist, Prev/Play/Next/ Stop, all capability-gated. Auto follows whichever player is active; the gear tab locks a specific app (Firefox/Zen, Chromium/Chrome, Brave, Vivaldi, Opera, VLC, Spotify, mpv and more are always listed, anything else appears while running, offline picks are kept). cliamp has its own tab and never pollutes this one. Opens by default when something plays.
  • cliamp: now-playing header with play/pause toggle; curated top-12 streams (direct radio.cliamp.stream URLs via track.play — no search round-trip, so entries always resolve); search covers names and countries with most-listened-first ranking; lists scroll on overflow; cold-start buttons when the daemon is down. Opens by default when nothing plays.
  • Settings (gear): all 18 bar visuals in a grid plus the music-player picker. Both persist to ~/.config/omarchy/mystaryo.media.json.
  • Popup closes via outside-click (scrim) or Esc.

Bar visuals (18)

Wave (default), Bars, Bloom, Blocks, Dots, Blob, Radar, Tide, Stars, Helix, Aurora, Lightning, Orbit, Particles, Bounce, Pulse, ECG, Waveform. Pick in the gear tab; right-click toggles Words/Spectrum.

Files

  • manifest.json — plugin manifest (mystaryo.media, bar-widget).
  • MediaWidget.qml — bar strip, popup, MPRIS tracking, cliamp IPC.
  • Visualizer.qml — canvas painters for the 18 styles (graceful paintWave fallback on any paint error, so a bad frame can never crash the bar).
  • cava.conf — portable cava config, no user paths, no ~/.config/cava dependency.

Requires (all degrade gracefully if missing)

  • cava (omarchy pkg add cava) + parecord/pactl (libpulse, preinstalled): audio arrives via a low-latency parecord bridge (default sink monitor, raw s16le, 50ms latency) into a fifo that cava reads at the selected visualizer FPS (30 by default) — cava 0.10.x's native PipeWire/Pulse inputs attach but read zeros on this system. The wrapper uses a private per-user runtime fifo and cleans up only the recorder process it started, so hot-reloads cannot stack duplicate recorders. Without them, the bar shows a static ♪.
  • cliamp daemon (cliamp -d, auto-started from the cliamp tab) — without it, the widget is pure-MPRIS (spectrum + transport for any player).

Design rules

  • MPRIS + audio-tap data only. No notification listeners: unknown sounds can only move bars, never crash anything.
  • Every external boundary degrades: dead cava restarts with backoff (5 tries, then static ♪); missing players fall back to Auto; junk metadata gets "Unknown …" fallbacks; capability-gated buttons; debug logging behind a debug flag (default off).
  • Colors come from the live bar theme. No absolute paths, no hardcoded home directory.

Install

omarchy plugin add https://github.com/ShravyaKudlu/omarchy-plugin-resonance --enable
omarchy bar put mystaryo.media --section left
omarchy restart shell

Rollback

omarchy plugin disable mystaryo.media