# Safety boundary This plugin runs unsandboxed inside `omarchy-shell`; review the source before enabling it. It performs read-only discovery by default. The only automated write eligible in this release is a typed change to an already-advertised power profile. Recommend mode requires visible consent; Guarded Automatic additionally requires a valid persisted policy. Each action is allowlisted, re-discovered immediately before use, verified afterward, and automatically rolled back when verification or execution fails. Bluetooth is manual/recommend-only. The plugin never uses sudo, installs packages, edits boot/initramfs/udev/modprobe files, writes arbitrary sysfs or PCI paths, unbinds devices, changes drivers, forces ASPM, runs PowerTOP auto-tune, reboots, or starts a competing power manager. Display persistence, runtime-PM, GPU/driver, Wi-Fi tuning, and root-required changes are guidance only. Powercap is read only when the current user can access it; permission denial is a normal degraded result. NVIDIA vendor telemetry is skipped unless the GPU is already runtime-active, because querying a suspended device could itself alter the measurement. Live QML profile state is display-only and never substitutes for backend rediscovery at the action boundary. Backend protocol output is bounded at the producer and at both Quickshell stdio streams. If stdout or stderr exceeds the limit, the child is terminated and reaped before any response is parsed. The UI reports a fixed error and does not retain the oversized payload.