Omahub
← All plugins
S

air-Q

by Stefan Gründel

Live indoor air quality from a local air-Q device

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
18e0514
Scanned
6 days ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

None
AI risk level
None
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
18e0514
Reviewed
6 days ago

This is a straightforward local-network air-quality widget with no install-time scripts, no obfuscated or hidden code, and no evidence of persistence, credential exfiltration, or destructive behavior. It stores the device password in the desktop keyring via a small readable helper and performs AES decryption in QML/JS to support the device protocol; the deterministic scan's "none" finding matches this review. The only platform caveat is that Quickshell plugins are unsandboxed, which the README explicitly discloses, but nothing in this plugin exploits that.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/sgruendel/omarchy-airq --enable
Widgets #bar #quickshell

air-Q for Omarchy

air-Q bar indicators and sensor detail panel in Omarchy

A Quickshell bar widget for local air-Q air quality monitors. Two dots show the health index first and performance index second. Each dot is green at or above 80%, yellow from 60% to 80%, and red below 60%; unavailable or stale readings are gray.

Clicking the widget opens a panel with all measurements exposed by the device, sensor status, measurement age, health, and performance. The last good reading remains visible and is marked stale during connection failures while the plugin retries automatically.

Requirements

  • Omarchy with the Quickshell desktop shell
  • An air-Q device reachable on the local network
  • curl
  • xdg-open to open the device page from the widget

Install

omarchy plugin add https://github.com/sgruendel/omarchy-airq.git --enable
omarchy bar set sgruendel.airq host YOUR_AIRQ_HOST
omarchy bar set sgruendel.airq serial YOUR_AIRQ_SERIAL

Use the hostname or IP address only for host, without http:// or a trailing slash. Open the widget and enter the device password when prompted. The plugin stores it in GNOME Keyring using the Secret Service tools included with Omarchy.

Controls

  • Left click: open or close the detail panel
  • Middle click: refresh now
  • Right click: open the air-Q device page
  • R in the panel: refresh now
  • O in the panel: open the device page
  • Esc: close the panel

The widget also exposes refresh, open, close, show, hide, and toggle over Omarchy shell IPC. For example:

omarchy shell sgruendel.airq refresh

Configuration

Settings can be changed through the Omarchy bar widget settings or with omarchy bar set sgruendel.airq KEY VALUE.

Key Default Purpose
host empty Device hostname or IP address
serial empty Device serial number
refreshSeconds 30 Polling interval in seconds (10–3600)
radonWarning 100 Radon warning threshold in Bq/m³ (10–10000)
indexGreenThreshold 80 Minimum green health/performance index (0–100)
indexYellowThreshold 60 Minimum yellow health/performance index (0–100)

Security and privacy

The plugin talks directly to the air-Q device over the local network and does not use a cloud service. The device password is looked up in the desktop Secret Service and is never stored in Omarchy's shell.json or passed in process arguments. Passwords entered in the panel are masked, sent to the keyring over stdin, and cleared from the field as soon as the storage helper starts. The encrypted API response is decrypted inside the plugin. Responses are capped at 64 KiB before the shell collects, decodes, or decrypts them, and device-provided status text is always rendered as inert text.

Like other Quickshell plugins, this plugin is not sandboxed. Review the source before installing it.

Remove

omarchy plugin remove sgruendel.airq
secret-tool clear application omarchy-airq serial YOUR_AIRQ_SERIAL

The second command is optional and removes the saved device password from the desktop keyring.

Development

Run the model and decryption tests with:

node --test

License

MIT