What it doesAI
Android phone testing plugin for DSH, connecting over WebSocket to control devices via the web Phone panel.
- Connects to Android devices over WebSocket on LAN
- Lets agents open apps, tap, swipe, input text, send keys
- Take screenshots and dump UI tree for phone testing
AI-generated from the repo README — for reference only.
Installation
dsh plugin --profile web add dsh-android-agentInstall method: npm · not yet tested in container (L3+)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
Requirements
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
No critical or warning findings in the automated scan. The result is valid only for the commit hash shown.
0.1.0dsh manifest486c1e8c8eaa2026-08-20486c1e8c8eaaThe scan result is valid for the scanned commit. New commits within 7 days are tolerated (the rating still counts); after 7 days without a rescan the badge shows outdated.
Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
vet verdict: vet: suspicious · score 80
- R2 · info [likely] — require()(客户端加载器 factory 形参注入,DSH bundle 标准写法)
- R2 · info [likely] — require()(客户端加载器 factory 形参注入,DSH bundle 标准写法)
- R2 · info [likely] — require()(客户端加载器 factory 形参注入,DSH bundle 标准写法)
- R2 · high [certain] — new Function / new AsyncFunction 动态执行
- R6 · info [heuristic] — 字符串特征:混淆特征 String.fromCharCode
vet is advisory and does not change dsh’s four-tier level.
• Static heuristic scan: done (15 files)
• Dependency vulnerabilities: requires deep audit (L3+)
• Permission sandboxing: requires runtime testing (L4+)
Activity
Last commit 2026-08-20 · activity: Active
• Repo created: 2026-08-20
• Stars: ★ 0 · Forks: 0
• Health: Active — committed within last 30 days
