# Security Zonitor is a display-only Omarchy bar widget. It is not a wallet. ## What this plugin never does - No sudo or pkexec is required, and none is used. - It does not read, store, or transmit spending keys, viewing keys, seed phrases, or wallet files. - It does not talk to a local Zebra / zcashd node. - It does not install packages, services, timers, or binaries. - It does not download and execute remote code. - It does not write anywhere except its own entry in `~/.config/omarchy/shell.json`. ## Network The plugin runs `curl` as your user against three public HTTPS endpoints: | Host | Data | When | | --- | --- | --- | | `api-pub.bitfinex.com` | ZEC/USD ticker and candles for the selected range | every `pollSeconds` (default 10s); candles while the panel is open | | `api.mainnet.cipherscan.app` | Shielded-pool and height stats | every 5 minutes | | `query1.finance.yahoo.com` | Nasdaq `CYPH` quote | only if you turn CYPH on, every 60 seconds | URLs are hardcoded in `Model.js`. There is no user-supplied URL, no API key, and no telemetry. Failed fetches keep the last good values on screen. Each `curl` is bounded with `--max-time` and `--max-filesize` (256 KiB). Payloads larger than that, or JSON that is truncated, are rejected before they are applied. Omarchy plugins run unsandboxed inside `omarchy-shell`. Review this repository at a specific commit before you enable it. ## Marketplace baseline target The plugin is written to produce an Automated Security Baseline outcome of `passed`: - no installer / setup files - no package-manager commands - no privilege helpers - no remote build - no bundled executables - no systemd units Listing is still not a security audit. Pin a commit if that matters to you.