Dep Validate
blokadaorg/blokada
A skill your agent uses to validate risky dependency bumps end to end as a local or cloud-launched agent.
Run, diagnose, and extend bitchat Android Mesh Lab physical-device tests.
$ npx skills add permissionlesstech/bitchat-android --skill mesh-lab -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install permissionlesstech/bitchat-android mesh-lab --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/permissionlesstech/bitchat-android.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/mesh-lab .claude/skills/mesh-lab && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "mesh-lab" agent skill from https://github.com/permissionlesstech/bitchat-android/tree/main/.agents/skills/mesh-lab into .claude/skills/mesh-lab/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mesh-lab", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/permissionlesstech/bitchat-android/tree/main/.agents/skills/mesh-labType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add permissionlesstech/bitchat-android --skill mesh-lab -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install permissionlesstech/bitchat-android mesh-lab --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/permissionlesstech/bitchat-android.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/mesh-lab .agents/skills/mesh-lab && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "mesh-lab" agent skill from https://github.com/permissionlesstech/bitchat-android/tree/main/.agents/skills/mesh-lab into .agents/skills/mesh-lab/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mesh-lab", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add permissionlesstech/bitchat-android --skill mesh-lab -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install permissionlesstech/bitchat-android mesh-lab --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/permissionlesstech/bitchat-android.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/mesh-lab .cursor/skills/mesh-lab && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "mesh-lab" agent skill from https://github.com/permissionlesstech/bitchat-android/tree/main/.agents/skills/mesh-lab into .cursor/skills/mesh-lab/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mesh-lab", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/permissionlesstech/bitchat-android.git --path .agents/skills/mesh-lab--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add permissionlesstech/bitchat-android --skill mesh-lab -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install permissionlesstech/bitchat-android mesh-lab --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/permissionlesstech/bitchat-android.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/mesh-lab .gemini/skills/mesh-lab && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "mesh-lab" agent skill from https://github.com/permissionlesstech/bitchat-android/tree/main/.agents/skills/mesh-lab into .gemini/skills/mesh-lab/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mesh-lab", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install permissionlesstech/bitchat-android mesh-labInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add permissionlesstech/bitchat-android --skill mesh-lab -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/permissionlesstech/bitchat-android.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/mesh-lab .github/skills/mesh-lab && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "mesh-lab" agent skill from https://github.com/permissionlesstech/bitchat-android/tree/main/.agents/skills/mesh-lab into .github/skills/mesh-lab/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mesh-lab", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add permissionlesstech/bitchat-android --skill mesh-lab -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install permissionlesstech/bitchat-android mesh-lab --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/permissionlesstech/bitchat-android.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/mesh-lab .opencode/skills/mesh-lab && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "mesh-lab" agent skill from https://github.com/permissionlesstech/bitchat-android/tree/main/.agents/skills/mesh-lab into .opencode/skills/mesh-lab/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "mesh-lab", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
mesh-labRun, diagnose, and extend bitchat Android Mesh Lab physical-device tests.
Mesh Lab is an agent skill from permissionlesstech/bitchat-android. Run, diagnose, and extend bitchat Android Mesh Lab physical-device tests. Use this skill whenever work capable of changing physical peer behavior touches mesh discovery or routing, BLE or Wi-Fi transport, Noise/crypto/identity, foreground-service or power behavior, public or private messaging, file/media transfer, protocol packets, or fragmentation; whenever a user asks for physical-device validation, ADB test hooks, hardware regression reproduction, or a new Mesh Lab scenario; and before claiming that such…
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `evals/evals.json`).
It sits in Testing & QA, covering Mobile testing and debugging and Unit testing. It works with Android. The repository describes itself as: decentralized mesh chat. The licence is GPL-3.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 6803d6d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
python3adbFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Mesh Lab loads about 2.9k tokens when it runs. Until then it costs about 178 tokens; SKILL.md has 1,364 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from permissionlesstech/bitchat-android at commit 6803d6d, republished under its GPL-3.0 licence (© permissionlesstech). 1,364 words, ~2,853 tokens.
.claude/skills/mesh-lab/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Use the repository's debug-only ADB harness to validate mesh behavior on physical devices. Treat it as a development integration test, not as the privacy-checked release gate and not as proof about a release APK.
Run from the repository root.
Before choosing commands or changing a scenario:
AGENTS.md.docs/release-gate-runbook.md.python3 tools/release_gate/mesh_lab.py --help and the relevant
subcommand help.tools/release_gate/mesh_lab.py;
its current CLI and assertions are authoritative if documentation has drifted.app/src/debug/java/com/bitchat/android/testhook/TestHookDriver.kt before
using an ad-hoc command, diagnosing hook behavior, or extending coverage.Do not infer a physical pass from unit tests, compilation, old evidence, or a successful local send call.
Inspect the change or requested behavior first. Select the smallest scenario set
that exercises the affected physical contract, expanding to all for broad,
cross-cutting, or release-sensitive changes.
| Affected behavior | Start with |
|---|---|
| Discovery, connection management, routing, foreground-service lifecycle | broadcast, dm, session_recovery |
| Background, doze, or power-duty-cycle behavior | Existing setup keeps devices awake and foregrounded; add a focused workflow or use the full release gate |
| Wi-Fi Aware or transport-selection behavior | Existing setup enables BLE and does not pin Wi-Fi; add a transport-specific control/assertion or use the full release gate |
| Noise, crypto, authenticated peer state, identity persistence | dm, file_private, session_recovery, identity_reset |
| Public messaging or message delivery | broadcast, then dm if shared routing changed |
| File/media encoding, transfer, fragmentation, admission limits | file, file_private, file_oversize |
| Packet parsing, bridge/routing, TTL, or protocol changes | raw, plus a receiving scenario such as broadcast or dm |
| Broad mesh or transport refactor | all |
| UI-only work with no service, state, or delivery effect | Usually no Mesh Lab run; explain why |
When the selected scenarios do not exercise the new contract, add a focused scenario instead of treating unrelated green tests as coverage.
Mesh Lab setup is destructive to the app's local data. It force-stops the app, clears package data, regenerates identity, cycles Bluetooth, grants permissions, and changes wake/lock-screen timeout settings without restoring them.
setup, identity_reset, or all, confirm that the selected devices
may have bitchat app data cleared. identity_reset clears device B even when
setup was skipped. If the user has not already established authorization, ask./tmp, keep it local, and never commit it. Failure
evidence can include unsanitized logcat and lab identifiers.src/main.If the hardware, operator confirmation, or prerequisites are unavailable,
report the physical result as blocked (not run) and provide the exact handoff
command. Never soften this to "pass" or "probably works."
Preflight the environment without copying device selectors into durable output:
python3 --version
adb devices
./gradlew assembleDebugSet up the disposable pair:
python3 tools/release_gate/mesh_lab.py setup \
--serial-a "$MESH_SERIAL_A" \
--serial-b "$MESH_SERIAL_B" \
--apk app/build/outputs/apk/debug/app-arm64-v8a-debug.apkBuild and pass the current-tree debug APK during normal use. If setup
intentionally omits --apk, first verify on both devices that the installed
package is debuggable via run-as and that its package dump contains
TestHookReceiver; do this before any command that clears data.
Inspect peers on both devices after setup. Continue only when every discovered
participant belongs to the controlled lab.
Run either the selected scenario or the full suite. Run this entire block in one
shell invocation so the temporary-directory variable cannot disappear between
agent shell calls. Abort the block if the directory is empty or missing before
passing it to --out; otherwise an empty path can put private evidence in the
repository. Replace dm with
all only when full-suite data clearing has been authorized.
MESH_EVIDENCE_DIR="$(mktemp -d /tmp/meshlab-evidence.XXXXXX)"
if [ -z "$MESH_EVIDENCE_DIR" ] || [ ! -d "$MESH_EVIDENCE_DIR" ]; then
echo "mktemp failed; aborting so evidence cannot land in the repository" >&2
exit 1
fi
chmod 700 "$MESH_EVIDENCE_DIR"
python3 tools/release_gate/mesh_lab.py scenario dm \
--serial-a "$MESH_SERIAL_A" \
--serial-b "$MESH_SERIAL_B" \
--out "$MESH_EVIDENCE_DIR"Rerun setup before a fresh scenario batch when prior churn, stale identities,
or zombie GATT links could contaminate the result.
Keep the private evidence only as long as the active investigation needs it. Do not delete failure evidence that the user still needs; when it is no longer needed, remove it or move it to an explicitly approved protected location.
dm, broadcast, file, and file_private include receiver-side assertions.file and file_private currently validate a 1 KB deterministic fixture and
SHA-256 integrity, not sustained or boundary-sized transfer performance.file_oversize validates sender rejection and receiver absence for a 512 KB
broadcast, not the exact 256/257-fragment boundary.raw proves that the local transport bridge accepted the injected packet. It
does not prove that another device received or accepted it.session_recovery proves recoverability after process death, but may fall
back to an explicit handshake; it does not prove a fully automatic recovery.identity_reset proves new-identity recovery after pm clear; stale state for
the old identity is diagnostic evidence rather than a purge assertion.status: ok can mean the command completed without
satisfying the requested state. Inspect fields such as reached_min_peers,
direct, established, or cancelled.all runs scenarios sequentially on evolving device state. In the current
runner it writes combined evidence only, and a failed sub-scenario can abort
aggregation without clean structured evidence. Run selected scenarios
individually first when durable per-scenario evidence matters, then use
all as broader regression coverage.A scenario exits zero on pass and non-zero on failure. On failure, preserve the local evidence, inspect its error first, then use state dumps and filtered logcat:
python3 tools/release_gate/mesh_lab.py cmd \
--serial "$MESH_SERIAL_A" state
adb -s "$MESH_SERIAL_A" logcat -d -t 200 -s \
TestHook MessageHandler FragmentManager BitchatFilePacketCommon first checks are screen/foreground state, mutual discovery, direct-peer
state, Noise session state, and stale Bluetooth connections. Rerun setup only
after preserving useful diagnostics.
The generic cmd --extra wrapper does not encode every Android extra type
correctly: Boolean enabled and integer min_peers/ttl are notable cases.
Use a direct adb shell am broadcast with --ez or --ei, after reading the
driver, when exact types matter. Use the top-level --timeout-ms 30000 option
for command timeouts; never pass --extra timeout_ms=..., because it duplicates
the runner's timeout_ms keyword and fails before dispatch.
Prefer extending tools/release_gate/mesh_lab.py with existing hook commands.
Add or change an Android hook only when the public mesh API cannot express the
required action or observation.
Design the scenario around an observable remote contract:
src/debug.all to detect state contamination.Do not add test-only branches to production mesh code merely to make a scenario easy to drive.
End with a compact physical-test report:
pass, fail, or blocked (not run)Keep device selectors and raw evidence out of the report, commit, and pull request.
© permissionlesstech, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .agents/skills/mesh-lab of permissionlesstech/bitchat-android.
Open the folder on GitHubat commit 6803d6d
Mesh Lab next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Mesh Lab this skillpermissionlesstech/bitchat-android | 7.8k | — | ~2.9k | Automated safety check: Pass | GPL-3.0 | |
| Dep Validateblokadaorg/blokada | 3.3k | — | ~5.7k | Automated safety check: Notes | MPL-2.0 | |
| SoloPi AI Controlalipay/SoloPi | 6.3k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | |
| BrowserStack Live Testinghandsontable/handsontable | 22k | — | ~950 | Automated safety check: Pass | Custom licence | |
| Ha Android E2E Debugginghome-assistant/android | 4k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Teswiz Projectznsio/teswiz | 105 | — | ~977 | Automated safety check: Pass | MIT |
blokadaorg/blokada
A skill your agent uses to validate risky dependency bumps end to end as a local or cloud-launched agent.
alipay/SoloPi
Drives Android devices through SoloPi's typed command line to record, replay and verify app behavior, with device pools and signed on-device decision models.
handsontable/handsontable
Opens a live BrowserStack session on a real Android, iOS or desktop browser for a local or public URL, tunneling localhost through Cloudflare when needed.
home-assistant/android
Home Assistant Android end-to-end (Maestro) failure triage. An agent skill from home-assistant/android.
znsio/teswiz
A skill your agent uses when working in the znsio/teswiz repository to modify framework code, Cucumber/TestNG hooks, Applitools visual testing flows, configs/caps, or related docs/tests.
dotnet/maui
Builds and runs .NET MAUI device tests locally on iOS simulators, MacCatalyst, Android emulators or Windows, with optional category filtering.
permissionlesstech/bitchat-android
Analyze an Android pull request, branch, commit, or patch for user-visible changes and produce reproducible before/after screenshots from isolated builds.
permissionlesstech/bitchat-android
Create or refresh polished, high-resolution screenshots of the Bitchat Android app for README and repository showcase use.
Works with
Categories
Run, diagnose, and extend bitchat Android Mesh Lab physical-device tests. Mesh Lab is an agent skill from permissionlesstech/bitchat-android. Run, diagnose, and extend bitchat Android Mesh Lab physical-device tests.
Mesh Lab fits situations like: work capable of changing physical peer behavior touches mesh discovery; wi-Fi transport; noise/crypto/identity; foreground-service.
Run `npx skills add permissionlesstech/bitchat-android --skill mesh-lab -a claude-code`. Or copy the skill folder (.agents/skills/mesh-lab in permissionlesstech/bitchat-android) into .claude/skills/mesh-lab in your project. Claude Code loads it when a task matches its description.
Run `npx skills add permissionlesstech/bitchat-android --skill mesh-lab -a codex`. Or copy the skill folder (.agents/skills/mesh-lab in permissionlesstech/bitchat-android) into .agents/skills/mesh-lab in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add permissionlesstech/bitchat-android --skill mesh-lab -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mesh-lab, .gemini/skills/mesh-lab, .github/skills/mesh-lab and .opencode/skills/mesh-lab in your project.
Going by SKILL.md and its folder, Mesh Lab needs the command-line tools its instructions call (python3 and adb). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Mesh Lab is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Mesh Lab: Dep Validate (blokadaorg/blokada, 3.3k stars), SoloPi AI Control (alipay/SoloPi, 6.3k stars), BrowserStack Live Testing (handsontable/handsontable, 22k stars) and Ha Android E2E Debugging (home-assistant/android, 4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
permissionlesstech (a GitHub organization) maintains it in permissionlesstech/bitchat-android, which has 7,763 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 6, 2026.
Source: permissionlesstech/bitchat-android on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.