Omahub
← All plugins
B

Glucomarchy

by boyoyooo

Live blood glucose (FreeStyle Libre via LibreLinkUp) in the Omarchy bar: current reading, trend arrow, color-coded range status, and a detail panel with a history graph and time-in-range.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
725f582
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
725f582
Reviewed
1 month ago

This is a well-engineered, read-only glucose widget that polls the LibreLinkUp API. It handles credentials carefully (sourced from a user-controlled file with ownership/permission checks, never passed via argv/environ, cached tokens with backoff) and performs no destructive or hidden actions. The only residual risk is that the credentials file is sourced as shell code, but the script mitigates this by refusing to run if the file is not owned by the user or is group/other-writable.

  • The credentials file is sourced as bash, so if a user points the plugin at a file they do not fully control, it could execute arbitrary code; the script's ownership/permission checks mitigate this but the user must still keep the file secure.
  • The plugin relies on a reverse-engineered, unofficial API that could change or be abused, but this is a functional risk rather than a security one.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/boyoyooo/glucomarchy --enable
Widgets #bar #quickshell #system

Glucomarchy

A bar widget for Omarchy Quattro showing live blood glucose readings from a FreeStyle Libre sensor (via LibreLinkUp) — current value, trend arrow, and range status at a glance.

The bar shows the current reading and a trend arrow, colored yellow (low), green (in range), or red (high) against your target range; it flashes a few times whenever a reading crosses into or out of range. Click it for a panel with a history graph (area fill + smoothed trend line, axis labels), the share of time in range, min/max/average, and remaining sensor life.

<img src="docs/bar-widget.png" alt="Bar widget: current reading and trend arrow" width="140"> <img src="docs/panel.png" alt="Panel: reading, trend, history graph, time-in-range stats, sensor life" width="300">

How it works

FreeStyle Libre's LibreView site only supports uploading a sensor's history, not live polling. LibreLinkUp — the companion app diabetics use to share readings with a caregiver — does have a (reverse-engineered, unofficial) API, and that's what this plugin polls.

You do not use your main FreeStyle Libre account here. You need a separate LibreLinkUp follower account:

  1. Open the FreeStyle Libre / LibreLink app on the phone paired with the sensor.
  2. Go to Settings → "LibreLinkUp" / "Share my data" → invite a follower.
  3. Accept that invite using a different email address — that's your LibreLinkUp account (install the LibreLinkUp app, or use the emailed link, to set its password).
  4. Use that account's email + password for this plugin, not your main one.

The poller script (bin/glucose-status.sh) logs in, caches the session token (valid for months) in ~/.cache/omarchy-glucose/, and on every poll makes a single read-only API call. Nothing is ever written back to LibreView/LibreLinkUp.

Setup

  1. Create a credentials file (not inside this plugin folder):

    mkdir -p ~/.config/omarchy/glucose
    cat > ~/.config/omarchy/glucose/credentials <<'EOF'
    LIBRELINKUP_EMAIL=you@example.com
    LIBRELINKUP_PASSWORD=your-librelinkup-password
    EOF
    chmod 600 ~/.config/omarchy/glucose/credentials
    
  2. Enable the widget:

    omarchy plugin enable io.github.boyoyooo.glucomarchy --section right
    
  3. Point it at your credentials file — edit the widget's entry in ~/.config/omarchy/shell.json (bar.layout.right) and add:

    { "id": "io.github.boyoyooo.glucomarchy", "credentialsFile": "/home/you/.config/omarchy/glucose/credentials" }
    

Settings

Key Default Description
credentialsFile (required) Path to the file with LIBRELINKUP_EMAIL / LIBRELINKUP_PASSWORD
interval 60 Poll interval in seconds (floored at 20s)
label (none) Optional label shown in the panel title and tooltip
targetLow 0 Low threshold override in mg/dL. 0 = use the range configured on your LibreView account
targetHigh 0 High threshold override in mg/dL. 0 = use the range configured on your LibreView account
sensorLifetimeDays 14 Sensor duration used to compute "days left" — check your sensor's box/app, it varies by model and region (commonly 14, 15, or 16)
notifyOnRangeChange false Also send a desktop notification when crossing into/out of range (the bar flash always happens)

Removal

omarchy plugin remove io.github.boyoyooo.glucomarchy

Then delete ~/.config/omarchy/glucose/ and ~/.cache/omarchy-glucose/ if you want the credentials file and cached session token gone too — neither is touched by plugin remove since they live outside the plugin folder.

Security notes

  • Credentials are read from a file you control, sourced into shell variables — never exported to the environment, never passed as a command-line argument. Neither is readable by another process on the same machine via /proc/<pid>/environ or /proc/<pid>/cmdline. The poller refuses to run if that file is owned by someone else or writable by group/other, since sourcing it is effectively running it.
  • The session token is cached per-account (~/.cache/omarchy-glucose/, chmod 600, directory chmod 700, umask 077 for the whole script) so your password is sent to Abbott's servers only on first run or after the cached token expires — not on every poll. A rejected login (e.g. a typo'd password) backs off for up to an hour instead of retrying — and resending the password — on every single poll.
  • No glucose data is ever written to disk outside of QML's in-memory state; the only thing this plugin persists is the session token.
  • The only write request this plugin ever makes is the LibreLinkUp authentication call itself (email + password, over TLS, to Abbott's own servers). Every other request is a read-only GET. Nothing is ever uploaded to or modified on your LibreView/LibreLinkUp account.
  • A missing current reading (sensor warming up, momentarily no data) is reported as an error, never displayed as a fabricated 0 mg/dL — for a glucose widget, a false low is a worse failure than showing nothing.

This is an unofficial, community-built integration. It has no affiliation with Abbott, FreeStyle Libre, or LibreView; it uses the same reverse-engineered API relied on by other open-source glucose tools (e.g. Nightscout bridges). Abbott can change or break that API at any time.

License

MIT