AI called this Suspicious at 90.0% confidence as Dangerous Capability with low false-positive risk.
Evidence for warning
- src/install.ts explicitly writes MCP entries to detected IDE configs.
- The installer can target Claude, Cursor, VS Code, Windsurf, Kiro, Antigravity, and JetBrains configs.
- Configured server executes npx -y androjack-mcp@2.0.0 when an IDE starts it.
Evidence against
- package.json has no preinstall, install, or postinstall hook.
- src/index.ts only reaches installer after an explicit install command.
- src/http.ts permits HTTPS fetches only to a fixed official Android/Kotlin/Maven allowlist.
- No child-process, eval, dynamic payload loading, credential harvesting, or exfiltration found.
Behavioral surface
SourceChildProcessCryptoEnvironmentVarsFilesystemNetwork
Supply chainHighEntropyStringsUrlStrings
ManifestNo manifest risk signals triggered.
scanned 74 file(s), 918 KB of source, external domains: android-developers.googleblog.com, androjack-web.netlify.app, api.example.com, developer.android.com, developerconsole.googleapis.com, developers.google.com, dl.google.com, firebase.google.com, issuetracker.google.com, kiro.dev, kotlinlang.org, ktor.io, m3.material.io, play.google.com, plugins.gradle.org, search.maven.org, square.github.io, support.google.com, www.jetbrains.com