Repository navigation
Add unirate-currency-converter package - #241
rob-browncc wants to merge 1 commit into
Conversation
Inline currency conversion and live exchange-rate lookups via the zero-dependency unirate CLI (UniRate API). Two form-based triggers (:fx, :rate); read-only HTTPS GETs only.
| go install github.com/UniRate-API/unirate-cli@latest | ||
| ``` | ||
|
|
||
| Prebuilt binaries for linux/macOS/windows are also attached to each |
There was a problem hiding this comment.
This could be a little clearer. I had to follow the link to see what you meant. Perhaps change to:
"Prebuilt unirate binaries for Linux, macOS & Windows are available at the project's Release page."
There was a problem hiding this comment.
🟡 Changes recommended
One or more issues must be addressed before approval.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Adds a new versioned Espanso package for live currency conversion and exchange-rate lookups using the UniRate CLI.
Changes:
- Adds
:fxand:rateform triggers. - Documents CLI/API-key setup.
- Adds package metadata and tags.
File summaries
| File | Description |
|---|---|
| packages/unirate-currency-converter/0.1.0/README.md | Updated as part of this pull request. |
| packages/unirate-currency-converter/0.1.0/package.yml | Updated as part of this pull request. |
| packages/unirate-currency-converter/0.1.0/_manifest.yml | Updated as part of this pull request. |
Review details
Suppressed comments (1)
packages/unirate-currency-converter/0.1.0/package.yml:47
- The form fields are free text, but their values are interpolated directly into a shell command. Entering a value such as
USD; <command>infromortocauses the shell to execute the injected command, so this is not limited tounirate rateas documented. Invoke the CLI with separate script arguments (or strictly validate/escape every field) so form values cannot become shell syntax.
cmd: "unirate rate {{form.from}} {{form.to}}"
- Files reviewed: 3/3 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| type: shell | ||
| params: | ||
| cmd: "unirate convert {{form.amount}} {{form.from}} {{form.to}}" | ||
| trim: true |
There was a problem hiding this comment.
I'm not overly concerned about this - the package only acts upon user-entered data, although there's a non-zero risk of pasting unsanitised text into the form. Use of the above suggestion or quoted "$ESPANSO_ENVIRONMENT_VARIABLES" would reduce the risk of command injection, however.
There was a problem hiding this comment.
An interesting package that should work across platforms. I've made a couple of comments about the README.md file, let Copilot do its stuff and run the automated checks, however.
It does require installation of the unirate command-line program, registering for an API from unirate.com, and registering said API on ones system.
I have a similar regex: trigger I use regularly: https://gist.github.com/smeech/556e0ae86495f3342de38a021f604904#file-currency-yml, which may be of interest.
| Prebuilt binaries for linux/macOS/windows are also attached to each | ||
| [GitHub release](https://github.com/UniRate-API/unirate-cli/releases). | ||
|
|
||
| 2. **Set a free API key** — [get one here](https://unirateapi.com) (no credit |
There was a problem hiding this comment.
The unirate website looks horrible - I tried two browsers - which doesn't inspire confidence!
Perhaps take people directly to the registration page at https://unirateapi.com/register, please?
New package:
unirate-currency-converterAdds a small package for inline currency conversion and live exchange-rate lookups, powered by the UniRate API via its zero-dependency
unirateCLI.Triggers
:fx100 USD = 92.5 EUR:rate1 USD = 150 JPYOn the script-review policy
Both matches use a
shellvar, so flagging the relevant bits for review up front:unirate convert …andunirate rate …— read-only HTTPS GETs against the UniRate API that print a result to stdout. Nothing is written to disk, nothing is deleted, norm/redirect/pipe-to-shell.uniratebinary is a separate, published, zero-third-party-dependency Go CLI (Homebrew/Scoop/go install/prebuilt release binaries). The README explains installing it plus setting a freeUNIRATE_API_KEY.Checklist
packages/unirate-currency-converter/0.1.0/with_manifest.yml,package.yml,README.mdname,title,description,version,author;name/versionmatch the path0.1.0version dir under the package folder.ymlextensions; YAML parses cleanlyHappy to adjust triggers, tags, or category if you'd prefer something else.