Omahub
← All plugins
L

Omastonk

by Luca Nerlich

Omarchy bar widget for a rotating market watchlist

Security review

Review recommended · 4 findings

Deterministic scan — not a security guarantee

Medium
Risk level
Medium
Analyzed commit
f3843ca
Scanned
1 month ago

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
f3843ca
Reviewed
1 month ago

The plugin is a legitimate market watchlist widget: the QML frontend runs a bundled Rust backend that fetches quotes from Yahoo Finance over HTTPS with size caps and no destructive operations. The deterministic scan's medium findings are all in GitHub Actions CI workflows (sudo apt-get install musl-tools), which never run on the user's machine and are unrelated to plugin runtime behavior. No obfuscation, persistence, credential theft, or harmful install-time commands were found.

  • The deterministic scan flags sudo apt-get in CI, but those are build-time steps on GitHub runners, not part of the plugin's install or runtime.
  • The backend uses curl to reach Yahoo Finance; this is expected functionality and the code enforces HTTPS and response size limits.
  • The bundled binary is attested via reproducible builds and is not stripped, aiding review.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/LucaNerlich/omastonk --enable
Widgets #bar #system

Omastonk

CI GitHub Release

Omastonk is a multi-symbol market widget for the Omarchy bar. It rotates through a watchlist of symbols, showing the current quote and daily direction for each, with a chart panel (one day to five years) per symbol.

<img width="766" height="750" alt="preview" src="https://github.com/user-attachments/assets/caaef0c6-9584-4f2a-9696-2a0f2b7f0f83" /> <img width="756" height="566" alt="screenshot-2026-08-21_10-11-24" src="https://github.com/user-attachments/assets/e0a6a192-6562-4005-baed-fe6880807a29" />

Forked from brianblakely/omastonk.

Install

omarchy plugin add https://github.com/LucaNerlich/omastonk.git --enable --yes

Update to the latest release:

omarchy plugin update luca.omastonk

Usage

Omastonk starts with an empty watchlist. Right-click it to add symbols; the bar rotates through them every rotateSeconds seconds (default 5). Left-click the widget to open the chart panel. Scroll the wheel or middle-click to cycle symbols without opening the panel.

In the chart panel:

  • Click a symbol tab or press Up/Down (or J/K) to switch symbols.
  • Press 1–9 to jump to the Nth symbol.
  • Click an interval or press Left/Right (or H/L) to switch between 5Y, 1Y, YTD, 6M, 1M, 5D, and 1D (the last choice is remembered).
  • Press Escape to close.

Right-click the widget to edit the watchlist: add symbols in the field at the bottom (space-separated works too; suggestions appear as you type), rename rows inline, reorder with ▲/▼, and remove entries with the ✕ button. Save commits whatever is typed in the add field.

Each widget instance keeps its own watchlist, so multiple instances can track different markets. Enable extra instances with omarchy plugin enable luca.omastonk (the manifest sets allowMultiple). Overlapping symbols share one backend poller automatically.

Settings

Widget settings live inline on the entry in ~/.config/omarchy/shell.json:

Key Default Description
symbols [] Watchlist of market symbols to rotate through, e.g. AAPL, SPY, BTC-USD, ^GSPC. A legacy single symbol string is migrated to this list on first save.
activeSymbol first symbol Symbol shown when the widget loads.
rotateSeconds 5 Seconds each symbol stays on the bar before rotating. 0 disables rotation.
displayMode full Bar label density: full (symbol, price, daily %, glyph), symbolPrice, priceOnly, or symbolOnly.
pollIntervalSecs 60 Seconds between refreshes of each individual symbol (minimum 5).
chartInterval 1D Last selected chart range (5Y, 1Y, YTD, 6M, 1M, 5D, 1D).

Quotes are fetched from Yahoo Finance and refreshed on the poll interval per symbol, staggered so requests are spread out.

Architecture

  • Rust backend (omastonk-qs): fetches Yahoo Finance quotes for the whole watchlist with staggered round-robin polling and streams JSON lines; also serves chart close-series and symbol search. Multiple watch clients share one local serve daemon over a Unix socket (in-process fallback if the socket cannot start).
  • QML frontend (omarchy/): a bar-widget plugin. BarWidget.qml runs omastonk-qs watch once and updates from its JSON lines; Panel.qml renders charts via omastonk-qs chart, offers search autocomplete, and owns the watchlist editor. All data collection stays in Rust; the QML is pure presentation.
omastonk-qs watch ──(JSON lines)──▶ BarWidget ─▶ Panel
omastonk-qs chart ──(JSON line)───▶ Panel
omastonk-qs search ─(JSON line)───▶ Panel editor

The plugin bundles a statically linked x86_64 musl build of its backend (omarchy/bin/omastonk-qs). If the bundled binary cannot start, the widget falls back to an omastonk-qs binary on PATH (cargo install --path .).

Development

make test            # cargo tests
make plugin-test     # node omarchy/model.test.mjs
make clippy          # clippy -D warnings
make fmt             # rustfmt
make validate        # omarchy plugin validate . + qmllint (on an Omarchy machine)
make bundle          # rebuild omarchy/bin/omastonk-qs + hashes
make verify-bundle   # marketplace attestation (reproducible musl rebuild)

Any edit under src/, Cargo.toml, Cargo.lock, or rust-toolchain.toml changes the bundled ELF — including comments. Run make bundle in the same change as the Rust edit; do not merge while the marketplace bundle CI job is red.

Releasing

  1. Bump version in Cargo.toml and manifest.json (they must match), add a ## [X.Y.Z] section to CHANGELOG.md, then run make bundle.
  2. Open a PR and wait for CI — including the independent marketplace bundle job — to pass on the merged SHA.
  3. Tag the merged commit vX.Y.Z and push it. The Release workflow re-runs the bundle checks, packages omastonk-qs-X.Y.Z-linux-x86_64.tar.gz, and publishes the GitHub Release with the changelog section as release notes.

Uninstall

omarchy plugin remove luca.omastonk

License

MIT. Original single-symbol widget by Brian Blakely, also MIT.