SelineBLOCK
Selene is a desktop app that runs AI agents on your machine. Connect them to your WhatsApp, Telegram, Slack, or Discord. Write code, generate images, build personal assistants. All from one place. Your data stays on your device.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Selene is an agent-first desktop app that runs AI on your machine. Chat, write code, generate images, design UIs, control a browser — then pipe all of it into WhatsApp, Telegram, Slack, or Discord. Your data stays on your device. Every part of Selene — chat, embeddings, voice, images — lets you pick between local and cloud. Run fully offline or bring your own API keys. Mix and match.
d06600fb987fOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add app-mockup-kit --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env ANTHROPIC_UPSTREAM_API_KEY=${ANTHROPIC_UPSTREAM_API_KEY} --env APPLE_API_KEY=${APPLE_API_KEY} --env APPLE_API_KEY_ID=${APPLE_API_KEY_ID} -- npx -y [email protected]{
"mcpServers": {
"app-mockup-kit": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"ANTHROPIC_UPSTREAM_API_KEY": "${ANTHROPIC_UPSTREAM_API_KEY}",
"APPLE_API_KEY": "${APPLE_API_KEY}",
"APPLE_API_KEY_ID": "${APPLE_API_KEY_ID}"
}
}
}
}Exposed tools (25)
23 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Coda | write | Create and manage Coda docs, pages, and tables |
Composio | read | Connect many apps through Composio |
Everything | read | Sample server with many example tools |
GitHub | read | Manage repositories and search code |
InvalidName | read | Has uppercase |
Linear | read | Track issues and manage projects |
PostgreSQL | read | Connect to a PostgreSQL database |
Skill | read | Desc |
Supabase | read | Manage Supabase project data and APIs |
app | read | app/, components/, hooks/, i18n/, middleware/instrumentation |
code-review | read | Specialized agents for reviewing pull requests with code intelligence |
commit-commands | write | Git commit workflows including commit, push, and PR creation |
electron | read | electron/ main + preload |
folder-plugin | read | Imported from folder |
hookify | read | Hook management plugin |
lib | read | lib/ and shared type declarations |
no-server | read | missing server |
old-skill | read | Upgraded to full plugin |
plugin-a | read | Plugin A |
plugin-b | read | Plugin B |
reviewer | read | Code review specialist agent |
test-plugin | read | A comprehensive test plugin |
tooling | read | root config files and scripts/ |
versionless-plugin | read | Plugin without explicit version |
x | read | Single char |
Trust audit
BLOCKgrade F · trust 34/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (14 observation(s))
- Network
- declared (17 observation(s))
- Shell
- declared (10 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
exec(command, { timeout }, (error, stdout) => {const textContent = await session.page.$eval(input.selector, (el) => el.textContent ?? "");
return eval(expr);
const dynamicImport = new Function("specifier", "return import(specifier)") as (const dynamicImport = new Function("specifier", "return import(specifier)") as (hostname === "169.254.169.254" ||
hostname === "metadata.google.internal" ||
Important: When referencing code in the report, make sure to find and include line numbers for the code you are referencing.
clash.wav
ignition.wav
power-down.wav
sith-clash.wav
swing-1.wav
console.log("[AntigravityAuth] Token saved, expires at:", new Date(token.expires_at).toISOString());debugLog(`[H2Proxy] HTTP/2 reverse proxy listening on https://127.0.0.1:${listenPort} → http://localhost:${targetPort}`);? (process.env.ELECTRON_DEV_URL || "http://127.0.0.1:3000")
? (process.env.ELECTRON_DEV_URL || `http://127.0.0.1:3000`)
? (process.env.ELECTRON_DEV_URL || "http://127.0.0.1:3000")
const devProxyUrl = useH2 ? "https://127.0.0.1:3001" : "http://127.0.0.1:3000";
'🤷♂️': { dt: [1000,1500], rescale: [0,1], vs:{ gesture: [["shrug",2],null] } },'🤷♀️': { link: '🤷♂️' },'🤷': { link: '🤷♂️' },`export const token = "transitive-relative-marker";`,
apiKey: "selene-dario-test-key",
apiKey: "selene-dario-test-key",
Gates applied: no_behavioural_pass.
d06600fb987ffull audit observations/trust-audit/mcp-server/tercumantanumut__seline.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d06600fb987f | BLOCK | F | 34 | first audit |
Questions
What is the Seline MCP server?
Selene is a desktop app that runs AI agents on your machine. Connect them to your WhatsApp, Telegram, Slack, or Discord. Write code, generate images, build personal assistants. All from one place. Your data stays on your device.
What tools does Seline expose?
25 in total: 23 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Seline safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (34/100) and found 8 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Seline need?
It reads ANTHROPIC_API_KEY, ANTHROPIC_UPSTREAM_API_KEY, APPLE_API_KEY, APPLE_API_KEY_ID, APPLE_APP_SPECIFIC_PASSWORD, APPLE_ID_PASSWORD, APPLE_KEYCHAIN, APPLE_KEYCHAIN_PROFILE, BLACKBOXAI_API_KEY, BLACKBOX_API_KEY, DEEPSEEK_API_KEY and ELEVENLABS_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Seline run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as app-mockup-kit at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (d06600fb987f), read on 2026-10-07. The repository is watched and re-audited when it changes.