Omahub
← All plugins
T

System Monitor

by tslove923

CPU / GPU / NPU / RAM / swap / disk meters (text or icons) with a hover details card.

Security review

Review recommended · 1 finding

Deterministic scan — not a security guarantee

Low
Risk level
Low
Analyzed commit
bb49abd
Scanned
1 month ago

Flagged patterns appear only in documentation files (README / docs) — descriptive examples, not executable code.

  • Docs sudo README.md:97

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo the RAM clock simply shows `—` (the SSD clock needs no

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
bb49abd
Reviewed
1 month ago

The plugin is a read-only system monitor: it polls /proc, /sys, and df via a fixed sh -c script, with no user input, network access, or destructive commands. The only elevated operation is a one-shot `sudo -n dmidecode -t memory` to read RAM speed, which is non-interactive, read-only, and disclosed in the README; the deterministic scan's medium finding is a documentation false positive. No malicious, obfuscated, or hidden behavior was found.

  • Startup runs `sudo -n dmidecode -t memory`; on systems with passwordless sudo this executes as root, though it is read-only and non-interactive (no prompt, no changes).
  • The deterministic scan flagged README.md:97 for `sudo`, but that snippet is documentation; the actual code uses `sudo -n` with fallback to an empty value.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/tslove923/omarchy-system-monitor --enable
Widgets #bar #system

System Monitor (Omarchy bar-widget)

CPU / GPU / NPU / RAM / swap / disk monitoring for the Omarchy shell bar, ported from the illogical-impulse QuickShell config.

Compact meters in the bar — cpu: 25% gpu: 12% ram: 41% etc. in text mode, or a Nerd glyph + percentage in icon mode. Click the widget to toggle text <-> icons (the choice is persisted to shell.json). GPU and NPU only appear when the device is present. Hovering the row opens a details card with CPU, GPU, NPU, RAM, swap, disk rows (load, frequency, used/free/total). A meter flips to a warning color (bar.urgent) above its configured threshold.

Install

omarchy plugin add https://github.com/tslove923/omarchy-system-monitor --enable
omarchy-shell shell rescanPlugins
omarchy bar move trevor.system-monitor --section left

Settings

Per-widget settings live in the inline shell.json entry for the widget (edit with omarchy bar set trevor.system-monitor <key> <value> or the config UI):

key default meaning
updateInterval 3000 poll interval (ms)
cpuThreshold 90 CPU warning %
gpuThreshold 95 GPU warning %
npuThreshold 95 NPU warning %
memoryThreshold 95 RAM warning %
swapThreshold 85 swap warning %
diskThreshold 90 disk warning %
showCpu Auto CPU meter: Auto / Show / Hide
showGpu Auto GPU meter: Auto / Show / Hide
showNpu Auto NPU meter: Auto / Show / Hide
showRam Auto RAM meter: Auto / Show / Hide
showSwap Auto Swap meter: Auto / Show / Hide
showDisk Auto Disk meter: Auto / Show / Hide
displayMode Text Text / Icons (click the widget to toggle)

Data sources

One sh -c snapshot per poll, all read-only:

metric source
CPU load /proc/stat aggregate line delta
CPU freq /sys/devices/system/cpu/cpu0/cpufreq/scaling_{cur,max}_freq
RAM / swap /proc/meminfo (MemTotal/MemAvailable/SwapTotal/SwapFree)
GPU load /sys/class/drm/card0/device/tile0/gt0/gtidle/idle_residency_ms delta
GPU freq /sys/class/drm/card0/device/tile0/gt0/freq0/{act,max}_freq
NPU load /sys/class/accel/accel0/device/npu_busy_time_us delta
NPU freq /sys/class/accel/accel0/device/npu_{current,max}_frequency_mhz
NPU mem /sys/class/accel/accel0/device/npu_memory_utilization (bytes)
NPU status /sys/class/accel/accel0/device/power/runtime_status
disk df -P /
RAM clock sudo -n dmidecode -t memory (Configured Memory Speed)
SSD clock /sys/class/nvme/nvme*/device/current_link_speed (first NVMe)

Paths are the Intel Lunar Lake layout (Arc iGPU tile0/gt0, accel0 NPU). If a sysfs path is missing the corresponding meter hides rather than erroring.

Hardware portability

The plugin never crashes on other hardware. Every GPU/NPU sysfs read falls back to an NA sentinel; a missing device just means gpuAvailable/npuAvailable are false and those meters hide. CPU, RAM, swap, and disk are universal.

  • GPU load is read from the Intel tile0/gt0 gtidle residency counter — on AMD or NVIDIA machines this auto-hides. There's no vendor-agnostic load source.
  • NPU is read from the Intel accel0 driver (npu_busy_time_us) — on machines without an NPU it auto-hides.
  • Swap auto-hides on systems with no swap device.
  • Every meter has a show<X> setting (Auto/Show/Hide): Auto follows detection, Show forces the meter on any hardware, Hide removes it (bar and hover card). The config UI or omarchy bar set trevor.system-monitor showGpu Show set them.

Notes

  • Disk is btrfs allocation. The root filesystem is btrfs, so df reports subvolume/allocated space and used + free ≠ total is normal (reserved blocks). The disk meter is still useful for runaway usage.
  • NPU suspend. When the NPU is suspended the busy counter is frozen, so usage is forced to 0 and the card shows Suspended.
  • Icons. The bar glyphs live in the bar's Nerd Font, except NPU (fa-brain) and RAM (fa-memory), which come from Font Awesome 7 Free — install otf-font-awesome if those two render as blank; fontconfig falls back to it.
  • Safety. The plugin spawns one sh -c per poll with a fixed, literal script (no user input, no shell interpolation). All sources are world-readable /proc and /sys files plus df. No network, no persistent state. A separate one-shot sh -c at startup reads the RAM clock via sudo -n dmidecode -t memory — it never prompts, and without dmidecode or passwordless sudo the RAM clock simply shows — (the SSD clock needs no privileges).

License

MIT