Omahub
← All plugins
Y

Snooze

by Yordan Yordanov

Snooze distracting sites for a while — hosts-file blocking with a timer, no browser extensions

Security review

Potentially dangerous behavior detected · 16 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
fc54245
Scanned
1 month ago
  • high destructive_filesystem tests/scripts.test.sh:38

    Destructive operation on the root filesystem or a block device.

    rm -rf /"
  • high persistence bin/snooze:161

    Registers scheduled or boot-time system tasks.

    systemd-run --user --quiet --collect --on-active="$((minutes * 60 + 5))s" --unit="$UNIT" \
  • medium external_hosts …/workflows/test.yml:30

    Downloads or connects to an external HTTP(S) host.

    git clone --depth 1 https://github.com/basecamp/omarchy.git omarchy
  • medium external_hosts …/workflows/test.yml:57

    Downloads or connects to an external HTTP(S) host.

    git clone --depth 1 https://github.com/basecamp/omarchy.git /omarchy
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo replaced by a recording stub ----------
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo would reject as a bad option), and the privileged
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo stub is not on PATH — skipped the privileged-plan tests"; fails=$((fails+1))
  • medium sudo bin/snooze:16

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo path uses HELPER_TARGET, the literal the sudoers rule names — the
  • medium sudo bin/snooze:374

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -Dm755 -o root -g root $PLUGIN_DIR/bin/snooze-helper $HELPER_TARGET${OFF}"
  • medium sudo bin/snooze:402

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -Dm755 -o root -g root "$PLUGIN_DIR/bin/snooze-helper" "$HELPER_TARGET"
  • medium sudo bin/snooze:409

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo install -Dm440 -o root -g root "$STAGED_SUDOERS" /etc/sudoers.d/snooze
  • medium sudo bin/snooze:433

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo rm -f /etc/sudoers.d/snooze "$HELPER_TARGET"
  • medium sudo bin/snooze:469

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo rule it
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo path can only ever operate on the real /etc/hosts.
  • Docs external_hosts CONTRIBUTING.md:12

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/yordanbuilds/snooze.git ~/.config/omarchy/plugins/yordanbuilds.snooze
  • Docs sudo README.md:107

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo rule

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
fc54245
Reviewed
1 month ago

Snooze is a transparent, well-engineered site blocker that edits /etc/hosts through a narrow root helper; the high deterministic score comes from a test string containing `rm -rf /` (an invalid-domain test case, never executed) and from the plugin's intended, documented systemd timer and sudo setup. The code is not obfuscated, contains no hidden persistence or credential theft, and all privileged actions require an explicit one-time setup with a password prompt.

  • Installing a NOPASSWD sudoers rule for a root-owned helper is a real privilege surface, though it grants only the ability to add/remove 0.0.0.0 entries inside a marked block of /etc/hosts; any %wheel user can block domains system-wide without a password.
  • The root helper is a bash script; a future update with a bug could corrupt /etc/hosts, though atomic writes and strict input validation mitigate this today.
  • The systemd user timer created by `snooze start` is an intentional, documented feature for expiring blocks, not hidden persistence.
  • User should verify the printed setup plan (`snooze setup --print`) before entering a password, especially after plugin updates.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/yordanbuilds/snooze --enable
Widgets #bar

Snooze

Snooze

Block the sites that eat your focus — for an hour, or until you say stop.

A bar widget for Omarchy. Pick the groups you want out of the way, pick a duration, and Snooze writes a marked block of 0.0.0.0 entries into /etc/hosts — then takes it out again when the time is up. The block sits in the system resolver, so it covers every browser, every profile, every Electron app and every terminal on the machine: no extensions, no proxy, nothing to install per browser.

Snooze is friction, not a wall. Anyone who really wants a feed can stop the session, use their phone, or edit a file. That is the point: it interrupts the reflex of opening a tab you didn't decide to open, and it never pretends to be more than that.

Installation

Snooze needs Omarchy 4 or newer.

omarchy plugin add https://github.com/yordanbuilds/snooze.git --enable

The icon appears with a dot on it: click it, then Run setup. A floating terminal shows the plan and asks for your password once. Setup installs:

  • the helper, root-owned at /usr/local/bin/snooze-helper
  • /etc/sudoers.d/snooze (visudo-checked): %wheel ALL=(root) NOPASSWD: /usr/local/bin/snooze-helper
  • the snooze CLI in ~/.local/bin, default groups in ~/.config/snooze/groups.json

The passwordless rule covers one small root-owned script that can only write 0.0.0.0 <domain> lines inside its own marked block of /etc/hosts — the worst anything can do through it is block a site. Audit it first with snooze setup --print.

Updating? omarchy plugin update yordanbuilds.snooze — if the helper changed, the panel asks for setup again.

Usage

Click the bar icon: groups, a duration, one button.

The Snooze panel

Once a session is running, the panel is the countdown.

A running session

Timed sessions end themselves; an ∞ session runs until you press Stop, which is behind a confirm. +30 min is there whenever a deadline is.

The time left rides along in the bar:

Snooze in the bar

Turn that off with the widget's Show remaining time in bar setting.

Shortcut What happens
<kbd>←</kbd> / <kbd>→</kbd> Pick a duration
<kbd>Enter</kbd> Snooze — or run setup, whichever is up
<kbd>Esc</kbd> Back out of the confirm, the editor, the panel
middle-click the bar icon Re-read the status now

Groups

Editing a group

Three groups ship by default; the pencil edits everything, and anything that isn't a domain is refused. It all lands in ~/.config/snooze/groups.json — plain JSON, dotfile-friendly, hand-editable while the panel is open:

{
  "version": 1,
  "groups": [
    { "id": "social", "name": "Social", "icon": "󰡉",
      "sites": ["facebook.com", "instagram.com", "x.com"] }
  ]
}

Sites are bare domains; x.com also covers www.x.com. Deeper names are taken as written — that's why Video ships youtube.com, m.youtube.com and youtu.be separately.

A session is a snapshot: edits apply to the next one, never to the block already in place.

The CLI

Everything the panel does is also a command:

snooze start --group social --for 2h   block those groups (default: all) for that long
snooze start --forever                 block until you stop it
snooze extend 30m                      push the current deadline further out
snooze stop                            unblock everything now
snooze status                          what is blocked, and for how long
snooze status --json                   the same, for scripts
snooze sweep                           drop the block if its time is up
snooze setup [--force] [--print]       install the helper and its one sudo rule
snooze uninstall                       remove Snooze and the plugin (asks about your groups)

Durations: 30m, 2h, 1h30m. --group takes the group's id from groups.json and repeats; leave it out and every group is in.

The CLI works without the shell running. A user timer ends timed sessions; if the machine slept through the deadline, the widget sweeps the leftover on the next shell start.

Known limits

Worth knowing before you trust it with a deadline:

  • An already-open tab can outlive the whole session. Blocking stops new DNS lookups; it cannot reach connections that already exist. A loaded SPA — X, YouTube — keeps clicking along on its live sockets and service worker without ever asking for the name again. Close its tabs and it's gone: the next lookup hits the block.
  • Secure DNS bypasses /etc/hosts entirely. With DNS-over-HTTPS on, the browser resolves names over the network and never consults the system resolver, so Snooze cannot touch it. In Chromium: Settings → Privacy and security → Security → Use secure DNS, off. Firefox has the same switch under Privacy & Security → DNS over HTTPS.
  • No wildcards. /etc/hosts matches exact names, so reddit.com says nothing about old.reddit.com. The defaults ship the variants that matter; add your own in the edit view.
  • Docker containers inherit the block. Omarchy points Docker's DNS at the host ("dns": ["172.17.0.1"] in /etc/docker/daemon.json, answered by systemd-resolved), so container lookups see the same hosts entries. A container started with its own --dns does not.
  • It is bypassable, deliberately. snooze stop is one click, your phone is right there, and /etc/hosts is a text file. Friction, not a wall.

Uninstall

snooze uninstall

It prints what it will remove and asks first: unblocks anything still blocked, removes the helper, the sudoers rule, the link and the session state, then hands the plugin to omarchy plugin remove. One sudo prompt. Your groups are a separate question — answer no and ~/.config/snooze/ stays put.

License

Snooze is open-source software licensed under the MIT license.