
Product
Microsoft Teams Notifications Are Now Available in Socket
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.
dsh-android-agent
Advanced tools
Android phone test automation for the dsh web GUI: persist phone-agent devices (~/.dsh/dsh-phone.json), keep WebSocket connections to the on-phone agent, drive JSON-RPC methods (openApp / tap / inputText / swipe / screenshot / getUI) from the web panel, a
中文 | English
A mobile-app testing plugin for DeepSeek Harness: it connects over WebSocket to an Android phone running dsh-android-agent on the same LAN and lets you open apps, tap at coordinates, input text, swipe, send key events, take screenshots and dump the UI tree from the dsh-web「Phone」panel, with the same phone_* tools exposed to agents. Built entirely on official NPM SDK packages — no dsh source changes.
| Feature | Description |
|---|---|
| Device management | CRUD phone devices (alias / WebSocket URL / token / notes); stored in ~/.dsh/dsh-phone.json (0600) |
| Connections | One WebSocket per device (ws://phone-ip:8080/ws?token=...), auto-reconnect (max 3), 5s status refresh |
| Open app | openApp by package name (e.g. com.android.settings) |
| Tap / swipe | tap/swipe at pixel coordinates, configurable gesture duration |
| Input text | inputText — optional tap-to-focus first (accessibility ACTION_SET_TEXT / paste based) |
| Key events | keyevent (back=4, home=3, recents=187, enter=66, delete=67 ...) |
| Screenshot | preview + download from the panel; agent tool saves into ~/.dsh/phone-screenshots |
| UI tree | getUI dumps accessibility nodes (text / class / bounds / actions) to locate elements |
| Agent tools | phone_list / phone_rpc / phone_open_app / phone_tap / phone_input / phone_swipe / phone_keyevent / phone_screenshot / phone_get_ui / phone_ui_find / phone_ui_tap / phone_ui_input / phone_ui_back — same device config as the GUI |
| UI-tree-driven actions | phone_ui_find (contains / resourceId) locates nodes in the accessibility tree and returns bounds + tap center; phone_ui_tap clicks the best matching node; phone_ui_input focuses a field by label and types; phone_ui_back sends the Android back key or the edge-swipe back gesture. The GUI panel now renders the UI tree as a clickable row list (tap / input buttons per node) — no manual coordinate typing needed. |
/api/dsh-phone/* routes are loopback-only (with same-origin checks) — the execution
surface that drives a real phone is never exposed to the LAN.~/.dsh/dsh-phone.json (0700 dir / 0600 file, atomic writes) —
same trust model as dsh-ssh.ws://phone-ip:8080/ws and its token.This plugin is a standalone package (not part of the @linxin666/dsh-web-ui-all aggregate), installed via a local link:
### npm (not yet published — available once published)
dsh plugin --profile web add dsh-android-agent
### local standalone package (development, at D:\code\dsh\dsh-android-agent)
cd D:\code\dsh\dsh-android-agent
pnpm install && pnpm build
dsh plugin --profile web add link:D:\code\dsh\dsh-android-agent
Windows users can install with one command (build + link, PowerShell):
powershell -ExecutionPolicy Bypass -File D:\code\dsh\dsh-android-agent\scripts\install.ps1
Full install & verification checklist (build → tests → install → GUI/device checks) lives in
docs/VERIFY.md.
Restart dsh web afterwards: the「Phone」entry appears in the sidebar and the agent prompt picks
up the plugin announcement automatically.
~/.dsh/dsh-phone.json~/.dsh/phone-screenshots/pnpm install
pnpm typecheck
pnpm build
inputText relies on accessibility injection (ACTION_SET_TEXT / clipboard paste); some input
fields may reject it — under root/Shizuku you can fall back to adb-style input via shell.FAQs
Android phone test automation for the dsh web GUI: persist phone-agent devices (~/.dsh/dsh-phone.json), keep WebSocket connections to the on-phone agent, drive JSON-RPC methods (openApp / tap / inputText / swipe / screenshot / getUI) from the web panel, a
We found that dsh-android-agent demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.

Security News
Socket CTO Ahmad Nassri joins AppSec leaders at Black Hat to discuss active malware, package manager risks, and software supply chain defense.