Drive Android & iOS mobile-app automation from your AI agent on locally connected devices.
This MCP tool comes from an official registry and has an auditable open-source repository, with no clear high-risk red flags in the provided materials. However, it requires an API token and launches local commands for mobile automation, while permission and data-boundary details are sparse, so least-privilege controls are recommended.
It requires QUASH_API_TOKEN, which is a sensitive credential. QUASH_SIDECAR_CMD and QUASH_TEST_GEN_AGENT_CMD are not traditional secrets, but they control which local commands are executed, so tampering could lead to misuse or unintended execution.
No remote endpoint is declared in the materials, and the system metadata lists no host, so there is no clear evidence of data being sent to third parties. However, the presence of an API token suggests some authenticated communication may exist, and the docs do not disclose the destination or payloads, leaving limited network transparency.
The system marks this tool as executes-code, and QUASH_SIDECAR_CMD and QUASH_TEST_GEN_AGENT_CMD indicate it can launch local processes. This is a standard high-privilege MCP capability and should be constrained to fixed, auditable commands rather than allowing arbitrary model-constructed execution.
The description says it can drive locally connected Android/iOS devices for automation, so it may interact with app UI, entered content, or device state during testing. The materials do not specify which local files, logs, or device data it can read or write; no obvious overreach is shown, but the data scope is under-documented.
Positive signals include the official registry source, an auditable open-source repository, and updates within the last year, all of which reduce supply-chain risk. However, the repo has 0 stars, no declared license, and no README, so community validation and compliance clarity are limited, making 'caution' more appropriate than 'safe'.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "Quash — Mobile App Automation" yet — see the docs or source repo.