AI called this Suspicious at 90.0% confidence as Dangerous Capability with low false-positive risk.
Evidence for warning
- MCP tool execute_in_app accepts and evaluates caller-supplied JS in a connected React Native app.
- Runtime use also controls simulators/devices through ADB and xcrun commands.
- Startup creates a persistent installation ID and posts telemetry; tool use triggers license validation with a device fingerprint.
Evidence against
- package.json has no preinstall, install, or postinstall hook.
- Entrypoint is an explicit CLI/MCP server; HTTP mode listens only on localhost.
- No source evidence of hidden payload download, credential-file harvesting, or foreign AI-agent configuration mutation.
Behavioral surface
SourceChildProcessCryptoEnvironmentVarsFilesystemNetworkShellWebSocket
Supply chainHighEntropyStringsTelemetryUrlStrings
ManifestNo manifest risk signals triggered.
scanned 78 file(s), 1.16 MB of source, external domains: app.example.com, demo.example.com, demo.example.comhttps, developer.android.com, example.com, execbro.com, github.com, rn-debugger-ocr.500griven.workers.dev, rn-debugger-telemetry.500griven.workers.dev, us.i.posthog.com, www.w3.org