This module is an MCP agent exposing many powerful device-control and data-access endpoints over stdio. The snippet contains no explicit obfuscation or hardcoded secrets and no direct evidence of malicious payloads inside this file, but it creates a high-risk remote-control surface. If the stdio transport or the MCP controller is not strongly authenticated and isolated, these endpoints enable surveillance and exfiltration (contacts, messages, screenshots, recordings) and remote actions (calls, app launches). Recommend auditing the FastMCP transport configuration, ensuring authentication/authorization, reviewing the implementations of the imported tools for any outgoing network/I/O, and applying least-privilege principles before deploying.
Live on pypi for 5 hours and 58 minutes before removal. Socket users were protected even while the package was live.