# Security and trust model Portfolio Tracker runs as the signed-in user. Like every Omarchy shell plugin, its QML executes unsandboxed inside `omarchy-shell`; review the repository before enabling it. The installer uses no root privileges. It creates user-level symlinks, enables a user-level systemd timer, initializes local storage, validates the plugin, and enables it. Conflicting paths are moved to timestamped backups. The uninstaller removes only symlinks that still resolve into the same checkout and deliberately preserves portfolio data. New installations use a no-key Yahoo Finance compatibility provider. It calls Yahoo's unofficial chart endpoint and sends only quote symbols and currency pairs. Holdings, quantities, transactions, account names, and brokerage exports remain local. The project has no broker authentication flow and stores no API credential by default. Review Yahoo's current terms before enabling network refreshes; those terms currently restrict automated collection without express prior permission. The project cannot grant that permission. Manual and custom-provider modes are available. An explicitly configured command-provider adapter executes as the signed-in user. The tracker requires an absolute executable owned by that user and rejects group- or world-writable adapters, but it cannot sandbox trusted local code. Review adapters before enabling them. Keep provider credentials in separate user-only files, never in the checkout, snapshot, command output, or bug reports. ## Reporting a vulnerability Please report a suspected vulnerability privately through the repository's GitHub Security Advisory form. Do not include real holdings, exports, database files, account identifiers, or other personal financial information. When reporting, include the affected version, relevant command or QML entry point, impact, and a minimal reproduction using synthetic data.