Is agent-device safe?
Probably. Read the findings first.
Use with care. Some checks failed or could not be verified.
What to know before installing
- highShell command built from a string (injection risk)
- highBase64 decoded then executed
Public scan report
scanner v0.1.3 · 2026-09-19 · same rubric, same numbers if you re-run it
2 high1 medium
- Code scan432 source files scanned0/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner; GitHub account older than a year9/10
Findings (3)
- highShell command built from a string (injection risk)
exec.shell-concatdist/src/interactor.js: …/\b(light|dark|unsupported|unknown)\b/i.exec(`${e}\n${t}`);if(!n)return null;let r=n[1]?.toLow… - highBase64 decoded then executed
obf.base64-execdist/src/ios-client.js: …ta:`,e)}if(t.stderr)try{e._handleStderr(Buffer.from(t.stderr,`base64`))}catch(e){x.error(`Failed to decode stderr data:`,e)}t.exitCode!==void 0&&(x.debug(`Simctl execution ${t.id} completed with exit code $… - mediumNetwork call to a raw IP address
net.raw-ipdist/src/provider-webdriver.js: …sion,provider:m.awsDeviceFarm,endpoint:`http://127.0.0.1/`,platform:`android`,deviceName:`AWS Dev…
Overall 55/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON