Atlas / MCP servers / tercumantanumut / Selene

SeleneBLOCK

mcp/tercumantanumut/selene

Selene is a desktop app that runs AI agents on your machine. Connect them to your WhatsApp, Telegram, Slack, or Discord. Write code, generate images, build personal assistants. All from one place. Your data stays on your device.

Verdict
BLOCK
Grade
F
Trust score
34 /100
Exposed tools
25 23r · 2w · 0d
Transport
streamable-http
License
MIT
Stars
169
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Selene is an agent-first desktop app that runs AI on your machine. Chat, write code, generate images, design UIs, control a browser — then pipe all of it into WhatsApp, Telegram, Slack, or Discord. Your data stays on your device. Every part of Selene — chat, embeddings, voice, images — lets you pick between local and cloud. Run fully offline or bring your own API keys. Mix and match.

Read from source at commit d06600fb987fOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add app-mockup-kit --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env ANTHROPIC_UPSTREAM_API_KEY=${ANTHROPIC_UPSTREAM_API_KEY} --env APPLE_API_KEY=${APPLE_API_KEY} --env APPLE_API_KEY_ID=${APPLE_API_KEY_ID} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "app-mockup-kit": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "ANTHROPIC_UPSTREAM_API_KEY": "${ANTHROPIC_UPSTREAM_API_KEY}",
        "APPLE_API_KEY": "${APPLE_API_KEY}",
        "APPLE_API_KEY_ID": "${APPLE_API_KEY_ID}"
      }
    }
  }
}
03

Exposed tools (25)

23 read · 2 write · 0 destructive.

ToolRiskDescription
CodawriteCreate and manage Coda docs, pages, and tables
ComposioreadConnect many apps through Composio
EverythingreadSample server with many example tools
GitHubreadManage repositories and search code
InvalidNamereadHas uppercase
LinearreadTrack issues and manage projects
PostgreSQLreadConnect to a PostgreSQL database
SkillreadDesc
SupabasereadManage Supabase project data and APIs
appreadapp/, components/, hooks/, i18n/, middleware/instrumentation
code-reviewreadSpecialized agents for reviewing pull requests with code intelligence
commit-commandswriteGit commit workflows including commit, push, and PR creation
electronreadelectron/ main + preload
folder-pluginreadImported from folder
hookifyreadHook management plugin
libreadlib/ and shared type declarations
no-serverreadmissing server
old-skillreadUpgraded to full plugin
plugin-areadPlugin A
plugin-breadPlugin B
reviewerreadCode review specialist agent
test-pluginreadA comprehensive test plugin
toolingreadroot config files and scripts/
versionless-pluginreadPlugin without explicit version
xreadSingle char
04

Trust audit

BLOCKgrade F · trust 34/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (14 observation(s))
Network
declared (17 observation(s))
Shell
declared (10 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
electron/metadata-collector.ts:7
exec(command, { timeout }, (error, stdout) => {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
lib/ai/tools/chromium-workspace-tool.ts:383
const textContent = await session.page.$eval(input.selector, (el) => el.textContent ?? "");
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
lib/ai/tools/chromium-workspace-tool.ts:413
return eval(expr);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
lib/ai/transformers-runtime.ts:40
const dynamicImport = new Function("specifier", "return import(specifier)") as (
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
lib/documents/pdf-parse-runtime.ts:40
const dynamicImport = new Function("specifier", "return import(specifier)") as (
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
app/api/browser/[sessionId]/interact/route.ts:181
hostname === "169.254.169.254" ||
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
app/api/browser/[sessionId]/interact/route.ts:182
hostname === "metadata.google.internal" ||
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHPrompt injection · prompt.tool_poisoning · CWE-94, CWE-1427
lib/skills/catalog/bundled/security-best-practices.md:56
Important: When referencing code in the report, make sure to find and include line numbers for the code you are referencing.
Why it matters. a tool description carrying instructions to the agent
Fix. tool descriptions describe the tool; nothing else
MEDIUMInventory / provenance · inv.binary · CWE-1104
selene-plugins/starwars-soundfx/sounds/clash.wav
clash.wav
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
selene-plugins/starwars-soundfx/sounds/ignition.wav
ignition.wav
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
selene-plugins/starwars-soundfx/sounds/power-down.wav
power-down.wav
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
selene-plugins/starwars-soundfx/sounds/sith-clash.wav
sith-clash.wav
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
selene-plugins/starwars-soundfx/sounds/swing-1.wav
swing-1.wav
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
lib/auth/antigravity-auth.ts:282
console.log("[AntigravityAuth] Token saved, expires at:", new Date(token.expires_at).toISOString());
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
electron/h2-proxy.ts:258
debugLog(`[H2Proxy] HTTP/2 reverse proxy listening on https://127.0.0.1:${listenPort} → http://localhost:${targetPort}`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
electron/ipc-browser-session-handlers.ts:78
? (process.env.ELECTRON_DEV_URL || "http://127.0.0.1:3000")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
electron/ipc-unified-capture-handlers.ts:152
? (process.env.ELECTRON_DEV_URL || `http://127.0.0.1:3000`)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
electron/ipc-voice-hotkey-handlers.ts:21
? (process.env.ELECTRON_DEV_URL || "http://127.0.0.1:3000")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
electron/main.ts:374
const devProxyUrl = useH2 ? "https://127.0.0.1:3001" : "http://127.0.0.1:3000";
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
public/talkinghead/talkinghead.mjs:674
'🤷♂️': { dt: [1000,1500], rescale: [0,1], vs:{ gesture: [["shrug",2],null] } },
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
public/talkinghead/talkinghead.mjs:675
'🤷♀️': { link: '🤷♂️' },
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
public/talkinghead/talkinghead.mjs:676
'🤷': { link: '🤷♂️' },
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
lib/design/workspace/__tests__/tsconfig-paths.test.ts:315
`export const token = "transitive-relative-marker";`,
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/lib/ai/providers/claudecode-client.test.ts:12
apiKey: "selene-dario-test-key",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/lib/ai/providers/claudecode-client.test.ts:18
apiKey: "selene-dario-test-key",

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha d06600fb987ffull audit observations/trust-audit/mcp-server/tercumantanumut__selene.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06d06600fb987fBLOCKF34first audit
06

Questions

What is the Selene MCP server?

Selene is a desktop app that runs AI agents on your machine. Connect them to your WhatsApp, Telegram, Slack, or Discord. Write code, generate images, build personal assistants. All from one place. Your data stays on your device.

What tools does Selene expose?

25 in total: 23 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Selene safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (34/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Selene need?

It reads ANTHROPIC_API_KEY, ANTHROPIC_UPSTREAM_API_KEY, APPLE_API_KEY, APPLE_API_KEY_ID, APPLE_APP_SPECIFIC_PASSWORD, APPLE_ID_PASSWORD, APPLE_KEYCHAIN, APPLE_KEYCHAIN_PROFILE, BLACKBOXAI_API_KEY, BLACKBOX_API_KEY, DEEPSEEK_API_KEY and ELEVENLABS_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Selene run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as app-mockup-kit at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (d06600fb987f), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement