Twenty-seven feeds make a useful watch screen, not verified intelligence
Crucix polls 27 sources covering markets, fires, flights, radiation, satellites, conflict events, sanctions, news, and social channels. Every 15 minutes it synthesizes a new briefing, computes changes, and pushes the result to browsers over server-sent events. The dashboard offers a globe, flat map, tickers, risk gauges, source status, and filters. For one person monitoring broad themes, that is an appealing amount of context on one screen.
The interface also compresses very different evidence into a common visual language. A satellite measurement, a financial quote, a Telegram post, and a geotag inferred from a headline do not carry equal reliability. Crucix can show where to look next. It cannot make those sources mutually confirming merely by drawing them together, so every consequential item needs a link back to its origin and an independent check.
A 14-second install hides the absence of build and test gates
We cloned commit 3db7068 into an unprivileged Debian container with 3 CPUs and 8 GB of RAM. The 3 MB checkout contained 93 files and about 10,202 source lines. Npm installed 89 packages in 14 seconds and used 31 MB on disk. The repository has 1 CI workflow, a Dockerfile, a Compose file, and a tests directory.
Package metadata did not define a build script or test script, so our harness skipped both steps. The presence of a tests directory therefore did not give us a runnable project-wide check. Npm audit found 6 known vulnerabilities in the installed dependency tree: 4 high, 1 moderate, and 1 low, with 0 critical. We did not determine whether each advisory is reachable from the server.
What happened when we ran it
Our sandbox measured installation only: 89 packages in 14 seconds and 31 MB on disk. We did not start port 3117, query the 27 feeds, wait for a sweep, render the WebGL globe, send a bot message, call an LLM, or connect a brokerage account. There are no lab timings for those operations, and the README's 30-to-60-second initial sweep estimate is not our measurement.
With no build or test target, the repository gave us no automated evidence that all source adapters parse current upstream responses or that failed feeds degrade safely. A serious evaluation should add fixture-based tests for every adapter, timestamp preservation, coordinate provenance, stale-data handling, authentication, alert deduplication, and trade-action approval before treating the dashboard as more than exploratory software.
Map coordinates may be approximate or deliberately displaced
Issue 112 points to code that adds random latitude and longitude offsets to geotagged news. A marker may therefore be moved by roughly a degree from the inferred anchor, according to the report. Issue 116 describes another path where an unmatched headline from selected publications receives a hardcoded source-level centroid. Both behaviors favor a populated, readable map over geographic truth.
That trade is unacceptable when the interface looks like an intelligence map and does not make the uncertainty obvious. Use markers as navigation cues only. Open the article, identify a stated place, and compare it with a trusted map before reporting an event location. If geographic accuracy matters, disable news markers until the selected commit has deterministic coordinates, an unknown-location state, and visible provenance.
Current-looking data can come from an older event or run
Issue 115 says GDELT items receive new Date().toISOString() when entering the unified ticker, replacing the article's source time with synthesis time. That can make an older story appear newly published whenever a sweep includes it. Issue 113 says empty OpenSky results can fall back to a prior non-empty run file and expose the old hotspot data with fallback metadata.
The latter report notes that source and prior timestamp information exist in the synthesized output, which is better than a wholly invisible replay. A user scanning the visual layer may still mistake presence for freshness. Panels should display source time, ingest time, and fallback state separately. Until then, treat any urgent-looking ticker or flight signal as unconfirmed and check the source service directly.
Port 3117 belongs on a private interface
The Docker and local instructions expose the dashboard at port 3117. Issue 111 reports that /api/data, /api/health, /api/locales, and /events have no authentication, rate limiting, or CORS restriction. The described data endpoint returns the full briefing, while the health endpoint exposes some configuration state. A public instance could therefore become a feed paid for by the operator's API keys.
Keep Crucix bound to localhost, a private network, or an authenticated reverse proxy whose behavior you have tested. Do not assume an obscure URL is access control. The same caution applies to Telegram, Discord, LLM, and Alpaca secrets in .env. A process with market data, messaging, model access, and trading credentials is a high-value target even if the application code has only one required runtime dependency.
May 2026 activity has no published release checkpoint
GitHub showed 11,566 stars, 75 combined issues and pull requests, and a last push on May 20, 2026. The latest-release endpoint returned Not Found, so there is no GitHub release to pin or use as a changelog checkpoint. The repository is AGPL-3.0 licensed. Teams distributing or offering a modified network service should review those license obligations with appropriate counsel.
Crucix is unusually easy to install for the breadth it attempts, and 18 or more sources reportedly work without keys. Its current trust defects matter more than its visual polish. Run it privately, remove unneeded integrations, retain raw source records, and regard every alert as a lead. A 27-feed collage can save browsing time; it cannot substitute for timestamp, location, transport, and source verification.

