Skip to content

Add unirate-currency-converter package - #241

Open
rob-browncc wants to merge 1 commit into
espanso:mainfrom
rob-browncc:add-unirate-currency-converter
Open

rob-browncc wants to merge 1 commit into
espanso:mainfrom
rob-browncc:add-unirate-currency-converter

Conversation

@rob-browncc

Copy link
Copy Markdown

New package: unirate-currency-converter

Adds a small package for inline currency conversion and live exchange-rate lookups, powered by the UniRate API via its zero-dependency unirate CLI.

Triggers

Trigger Behaviour Example
:fx Form (amount / from / to) → converts 100 USD = 92.5 EUR
:rate Form (from / to) → unit rate 1 USD = 150 JPY

On the script-review policy

Both matches use a shell var, so flagging the relevant bits for review up front:

  • The only commands run are unirate convert … and unirate rate … — read-only HTTPS GETs against the UniRate API that print a result to stdout. Nothing is written to disk, nothing is deleted, no rm/redirect/pipe-to-shell.
  • The unirate binary is a separate, published, zero-third-party-dependency Go CLI (Homebrew/Scoop/go install/prebuilt release binaries). The README explains installing it plus setting a free UNIRATE_API_KEY.
  • Form input is limited to an amount and ISO-4217 currency codes; if the CLI or key is missing the trigger simply expands to nothing.

Checklist

  • packages/unirate-currency-converter/0.1.0/ with _manifest.yml, package.yml, README.md
  • Manifest has name, title, description, version, author; name/version match the path
  • Package name is lowercase-hyphen; only the 0.1.0 version dir under the package folder
  • .yml extensions; YAML parses cleanly

Happy to adjust triggers, tags, or category if you'd prefer something else.

Inline currency conversion and live exchange-rate lookups via the
zero-dependency unirate CLI (UniRate API). Two form-based triggers
(:fx, :rate); read-only HTTPS GETs only.
go install github.com/UniRate-API/unirate-cli@latest
```

Prebuilt binaries for linux/macOS/windows are also attached to each

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This could be a little clearer. I had to follow the link to see what you meant. Perhaps change to:

"Prebuilt unirate binaries for Linux, macOS & Windows are available at the project's Release page."

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

One or more issues must be addressed before approval.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Adds a new versioned Espanso package for live currency conversion and exchange-rate lookups using the UniRate CLI.

Changes:

  • Adds :fx and :rate form triggers.
  • Documents CLI/API-key setup.
  • Adds package metadata and tags.
File summaries
File Description
packages/unirate-currency-converter/0.1.0/README.md Updated as part of this pull request.
packages/unirate-currency-converter/0.1.0/package.yml Updated as part of this pull request.
packages/unirate-currency-converter/0.1.0/_manifest.yml Updated as part of this pull request.
Review details

Suppressed comments (1)

packages/unirate-currency-converter/0.1.0/package.yml:47

  • The form fields are free text, but their values are interpolated directly into a shell command. Entering a value such as USD; <command> in from or to causes the shell to execute the injected command, so this is not limited to unirate rate as documented. Invoke the CLI with separate script arguments (or strictly validate/escape every field) so form values cannot become shell syntax.
          cmd: "unirate rate {{form.from}} {{form.to}}"
  • Files reviewed: 3/3 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +25 to +28
type: shell
params:
cmd: "unirate convert {{form.amount}} {{form.from}} {{form.to}}"
trim: true

@smeech smeech Sep 21, 2026 •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not overly concerned about this - the package only acts upon user-entered data, although there's a non-zero risk of pasting unsanitised text into the form. Use of the above suggestion or quoted "$ESPANSO_ENVIRONMENT_VARIABLES" would reduce the risk of command injection, however.

@smeech smeech left a comment •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

An interesting package that should work across platforms. I've made a couple of comments about the README.md file, let Copilot do its stuff and run the automated checks, however.

It does require installation of the unirate command-line program, registering for an API from unirate.com, and registering said API on ones system.

I have a similar regex: trigger I use regularly: https://gist.github.com/smeech/556e0ae86495f3342de38a021f604904#file-currency-yml, which may be of interest.

Prebuilt binaries for linux/macOS/windows are also attached to each
[GitHub release](https://github.com/UniRate-API/unirate-cli/releases).

2. **Set a free API key** — [get one here](https://unirateapi.com) (no credit

@smeech smeech Sep 17, 2026 •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The unirate website looks horrible - I tried two browsers - which doesn't inspire confidence!

Perhaps take people directly to the registration page at https://unirateapi.com/register, please?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants