Run, diagnose, and extend bitchat Android Mesh Lab physical-device tests.

GPL-3.0Auto-check passedTesting & QA

Install Mesh Lab

skills CLI
$ npx skills add permissionlesstech/bitchat-android --skill mesh-lab -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install permissionlesstech/bitchat-android mesh-lab --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/permissionlesstech/bitchat-android.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/mesh-lab .claude/skills/mesh-lab && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
mesh-lab
GitHub stars
7.8k
Token cost
~2.9k tokens
SKILL.md length
1,364 words
Files
2
Skills in repo
3
Repo updated
First seen
Licence
GPL-3.0

At a glance

Run, diagnose, and extend bitchat Android Mesh Lab physical-device tests.

  • Works in 5 steps: Read the Mesh Lab section of AGENTS.md. → Read the "mesh lab" appendix in… → Use python3… → …
  • Work capable of changing physical peer behavior touches mesh discovery
  • SKILL.md covers Establish current ground truth, Decide the physical coverage, Protect devices and evidence and Run a two-phone batch, plus 3 more sections
  • Calls python3 and adb

What it does

Mesh Lab is an agent skill from permissionlesstech/bitchat-android. Run, diagnose, and extend bitchat Android Mesh Lab physical-device tests. Use this skill whenever work capable of changing physical peer behavior touches mesh discovery or routing, BLE or Wi-Fi transport, Noise/crypto/identity, foreground-service or power behavior, public or private messaging, file/media transfer, protocol packets, or fragmentation; whenever a user asks for physical-device validation, ADB test hooks, hardware regression reproduction, or a new Mesh Lab scenario; and before claiming that such…

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `evals/evals.json`).

It sits in Testing & QA, covering Mobile testing and debugging and Unit testing. It works with Android. The repository describes itself as: decentralized mesh chat. The licence is GPL-3.0.

When your agent uses it

  • Work capable of changing physical peer behavior touches mesh discovery
  • Wi-Fi transport
  • Noise/crypto/identity
  • Foreground-service

Example prompts

  • “/mesh-lab”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Read the Mesh Lab section of AGENTS.md.
  2. Read the "mesh lab" appendix in docs/release-gate-runbook.md.
  3. Use python3 tools/release_gate/mesh_lab.py --help and the relevant
  4. Inspect the selected scenario function in tools/release_gate/mesh_lab.py;
  5. Inspect

What it can do on your machine

Read from SKILL.md and the folder at commit 6803d6d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • adb

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Mesh Lab loads about 2.9k tokens when it runs. Until then it costs about 178 tokens; SKILL.md has 1,364 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~178
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from permissionlesstech/bitchat-android at commit 6803d6d, republished under its GPL-3.0 licence (© permissionlesstech). 1,364 words, ~2,853 tokens.

Download SKILL.mdSave it as .claude/skills/mesh-lab/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
mesh-lab
description
Run, diagnose, and extend bitchat Android Mesh Lab physical-device tests. Use this skill whenever work capable of changing physical peer behavior touches mesh discovery or routing, BLE or Wi-Fi transport, Noise/crypto/identity, foreground-service or power behavior, public or private messaging, file/media transfer, protocol packets, or fragmentation; whenever a user asks for physical-device validation, ADB test hooks, hardware regression reproduction, or a new Mesh Lab scenario; and before claiming that such changes work on real devices, even if the user does not name Mesh Lab explicitly. Do not use it for docs-only, unit-test-only, or pure UI changes that cannot affect mesh or service behavior.

Mesh Lab

Use the repository's debug-only ADB harness to validate mesh behavior on physical devices. Treat it as a development integration test, not as the privacy-checked release gate and not as proof about a release APK.

Establish current ground truth

Run from the repository root.

Before choosing commands or changing a scenario:

  1. Read the Mesh Lab section of AGENTS.md.
  2. Read the "mesh lab" appendix in docs/release-gate-runbook.md.
  3. Use python3 tools/release_gate/mesh_lab.py --help and the relevant subcommand help.
  4. Inspect the selected scenario function in tools/release_gate/mesh_lab.py; its current CLI and assertions are authoritative if documentation has drifted.
  5. Inspect app/src/debug/java/com/bitchat/android/testhook/TestHookDriver.kt before using an ad-hoc command, diagnosing hook behavior, or extending coverage.

Do not infer a physical pass from unit tests, compilation, old evidence, or a successful local send call.

Decide the physical coverage

Inspect the change or requested behavior first. Select the smallest scenario set that exercises the affected physical contract, expanding to all for broad, cross-cutting, or release-sensitive changes.

Affected behaviorStart with
Discovery, connection management, routing, foreground-service lifecyclebroadcast, dm, session_recovery
Background, doze, or power-duty-cycle behaviorExisting setup keeps devices awake and foregrounded; add a focused workflow or use the full release gate
Wi-Fi Aware or transport-selection behaviorExisting setup enables BLE and does not pin Wi-Fi; add a transport-specific control/assertion or use the full release gate
Noise, crypto, authenticated peer state, identity persistencedm, file_private, session_recovery, identity_reset
Public messaging or message deliverybroadcast, then dm if shared routing changed
File/media encoding, transfer, fragmentation, admission limitsfile, file_private, file_oversize
Packet parsing, bridge/routing, TTL, or protocol changesraw, plus a receiving scenario such as broadcast or dm
Broad mesh or transport refactorall
UI-only work with no service, state, or delivery effectUsually no Mesh Lab run; explain why

When the selected scenarios do not exercise the new contract, add a focused scenario instead of treating unrelated green tests as coverage.

Protect devices and evidence

Mesh Lab setup is destructive to the app's local data. It force-stops the app, clears package data, regenerates identity, cycles Bluetooth, grants permissions, and changes wake/lock-screen timeout settings without restoring them.

  • Use only designated disposable lab app data and deterministic test content.
  • Use two authorized physical Android BLE devices on API 26 or newer. Emulators do not exercise the required BLE mesh behavior.
  • Before setup, identity_reset, or all, confirm that the selected devices may have bitchat app data cleared. identity_reset clears device B even when setup was skipped. If the user has not already established authorization, ask.
  • Never attempt to defeat a secure lock screen. Ask the operator to unlock it.
  • Keep every device unlocked, awake, foregrounded, and preferably charging.
  • Treat ADB selectors as ephemeral secrets. Do not put serials, device names, peer IDs, addresses, fingerprints, local home paths, or raw logcat in commits, pull requests, issues, or published artifacts.
  • Write raw evidence under /tmp, keep it local, and never commit it. Failure evidence can include unsanitized logcat and lab identifiers.
  • Use debug APKs only. The exported test-hook receiver intentionally has no production security boundary and must never be moved into src/main.
  • Use an authorized, controlled lab area. After setup, inspect peer state locally and stop if an unexpected peer is present before sending broadcasts, files, or raw packets.
  • On a non-dedicated device, record the prior Bluetooth, stay-awake, screen timeout, and lock-screen-disabled settings locally. Restore only those recorded values after the run, or tell the operator exactly what remains changed.

If the hardware, operator confirmation, or prerequisites are unavailable, report the physical result as blocked (not run) and provide the exact handoff command. Never soften this to "pass" or "probably works."

Run a two-phone batch

Preflight the environment without copying device selectors into durable output:

sh
python3 --version
adb devices
./gradlew assembleDebug

Set up the disposable pair:

sh
python3 tools/release_gate/mesh_lab.py setup \
  --serial-a "$MESH_SERIAL_A" \
  --serial-b "$MESH_SERIAL_B" \
  --apk app/build/outputs/apk/debug/app-arm64-v8a-debug.apk

Build and pass the current-tree debug APK during normal use. If setup intentionally omits --apk, first verify on both devices that the installed package is debuggable via run-as and that its package dump contains TestHookReceiver; do this before any command that clears data.

Inspect peers on both devices after setup. Continue only when every discovered participant belongs to the controlled lab.

Run either the selected scenario or the full suite. Run this entire block in one shell invocation so the temporary-directory variable cannot disappear between agent shell calls. Abort the block if the directory is empty or missing before passing it to --out; otherwise an empty path can put private evidence in the repository. Replace dm with all only when full-suite data clearing has been authorized.

sh
MESH_EVIDENCE_DIR="$(mktemp -d /tmp/meshlab-evidence.XXXXXX)"
if [ -z "$MESH_EVIDENCE_DIR" ] || [ ! -d "$MESH_EVIDENCE_DIR" ]; then
  echo "mktemp failed; aborting so evidence cannot land in the repository" >&2
  exit 1
fi
chmod 700 "$MESH_EVIDENCE_DIR"

python3 tools/release_gate/mesh_lab.py scenario dm \
  --serial-a "$MESH_SERIAL_A" \
  --serial-b "$MESH_SERIAL_B" \
  --out "$MESH_EVIDENCE_DIR"

Rerun setup before a fresh scenario batch when prior churn, stale identities, or zombie GATT links could contaminate the result.

Keep the private evidence only as long as the active investigation needs it. Do not delete failure evidence that the user still needs; when it is no longer needed, remove it or move it to an explicitly approved protected location.

Show full SKILL.md (562 more words)Show less

Interpret results precisely

  • dm, broadcast, file, and file_private include receiver-side assertions.
  • file and file_private currently validate a 1 KB deterministic fixture and SHA-256 integrity, not sustained or boundary-sized transfer performance.
  • file_oversize validates sender rejection and receiver absence for a 512 KB broadcast, not the exact 256/257-fragment boundary.
  • raw proves that the local transport bridge accepted the injected packet. It does not prove that another device received or accepted it.
  • session_recovery proves recoverability after process death, but may fall back to an explicit handshake; it does not prove a fully automatic recovery.
  • identity_reset proves new-identity recovery after pm clear; stale state for the old identity is diagnostic evidence rather than a purge assertion.
  • The current CLI drives exactly two phones. It does not validate a three-hop topology, transport-specific Wi-Fi Aware behavior, permission denial, doze, endurance, resource bounds, transfer cancellation, release builds, or cross-client compatibility.
  • For ad-hoc commands, status: ok can mean the command completed without satisfying the requested state. Inspect fields such as reached_min_peers, direct, established, or cancelled.
  • all runs scenarios sequentially on evolving device state. In the current runner it writes combined evidence only, and a failed sub-scenario can abort aggregation without clean structured evidence. Run selected scenarios individually first when durable per-scenario evidence matters, then use all as broader regression coverage.

A scenario exits zero on pass and non-zero on failure. On failure, preserve the local evidence, inspect its error first, then use state dumps and filtered logcat:

sh
python3 tools/release_gate/mesh_lab.py cmd \
  --serial "$MESH_SERIAL_A" state

adb -s "$MESH_SERIAL_A" logcat -d -t 200 -s \
  TestHook MessageHandler FragmentManager BitchatFilePacket

Common first checks are screen/foreground state, mutual discovery, direct-peer state, Noise session state, and stale Bluetooth connections. Rerun setup only after preserving useful diagnostics.

The generic cmd --extra wrapper does not encode every Android extra type correctly: Boolean enabled and integer min_peers/ttl are notable cases. Use a direct adb shell am broadcast with --ez or --ei, after reading the driver, when exact types matter. Use the top-level --timeout-ms 30000 option for command timeouts; never pass --extra timeout_ms=..., because it duplicates the runner's timeout_ms keyword and fails before dispatch.

Add a physical-device scenario

Prefer extending tools/release_gate/mesh_lab.py with existing hook commands. Add or change an Android hook only when the public mesh API cannot express the required action or observation.

Design the scenario around an observable remote contract:

  1. Generate a unique token or deterministic fixture so stale state cannot pass.
  2. Start the receiver wait before sending.
  3. Assert remote sender identity, content, session state, digest, or expected absence—not merely that the sender accepted a call.
  4. Use bounded timeouts and return structured JSON evidence.
  5. For negative tests, assert both the expected sender error and that the receiver did not observe the artifact.
  6. Keep hook code and manifest registration under src/debug.
  7. Update the runbook scenario table and troubleshooting guidance.
  8. Run the new scenario individually, then run relevant neighboring scenarios or all to detect state contamination.

Do not add test-only branches to production mesh code merely to make a scenario easy to drive.

Report the outcome

End with a compact physical-test report:

  • Change or contract tested
  • Device topology: logical roles only, such as phone A to phone B
  • Build and scenario names
  • Result: pass, fail, or blocked (not run)
  • Local evidence directory, clearly marked private and uncommitted
  • On failure: the exact violated invariant and the next diagnostic
  • Coverage limits and any scenario fallback that weakens the claim

Keep device selectors and raw evidence out of the report, commit, and pull request.

© permissionlesstech, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/mesh-lab of permissionlesstech/bitchat-android.

  • SKILL.md
  • evals/evals.json

Open the folder on GitHubat commit 6803d6d

Compare with similar skills

Mesh Lab next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Mesh Lab compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Mesh Lab this skillpermissionlesstech/bitchat-android7.8k—~2.9kAutomated safety check: PassGPL-3.0
Dep Validateblokadaorg/blokada3.3k—~5.7kAutomated safety check: NotesMPL-2.0
SoloPi AI Controlalipay/SoloPi6.3k—~3.6kAutomated safety check: PassApache-2.0
BrowserStack Live Testinghandsontable/handsontable22k—~950Automated safety check: PassCustom licence
Ha Android E2E Debugginghome-assistant/android4k—~1.5kAutomated safety check: PassApache-2.0
Teswiz Projectznsio/teswiz105—~977Automated safety check: PassMIT

Similar skills

  • Dep Validate

    blokadaorg/blokada

    A skill your agent uses to validate risky dependency bumps end to end as a local or cloud-launched agent.

    3.3k GitHub stars~5.7k tokensUpdated today
    DevelopmentAuto-check: notes
  • SoloPi AI Control

    alipay/SoloPi

    Drives Android devices through SoloPi's typed command line to record, replay and verify app behavior, with device pools and signed on-device decision models.

    6.3k GitHub stars~3.6k tokensUpdated 1 mo ago
    Testing & QAAuto-check passed
  • BrowserStack Live Testing

    handsontable/handsontable

    Opens a live BrowserStack session on a real Android, iOS or desktop browser for a local or public URL, tunneling localhost through Cloudflare when needed.

    22k GitHub stars~950 tokensUpdated today
    Testing & QAAuto-check passed
  • Ha Android E2E Debugging

    home-assistant/android

    Home Assistant Android end-to-end (Maestro) failure triage. An agent skill from home-assistant/android.

    4k GitHub stars~1.5k tokensUpdated today
    Testing & QAAuto-check passed
  • Teswiz Project

    znsio/teswiz

    A skill your agent uses when working in the znsio/teswiz repository to modify framework code, Cucumber/TestNG hooks, Applitools visual testing flows, configs/caps, or related docs/tests.

    105 GitHub stars~977 tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Official

    Builds and runs .NET MAUI device tests locally on iOS simulators, MacCatalyst, Android emulators or Windows, with optional category filtering.

    23k GitHub stars~3.3k tokensUpdated today
    Testing & QAAuto-check passed

More from permissionlesstech/bitchat-android

  • Android UI Visual Review

    permissionlesstech/bitchat-android

    Analyze an Android pull request, branch, commit, or patch for user-visible changes and produce reproducible before/after screenshots from isolated builds.

    7.8k GitHub stars~2.6k tokensUpdated 3 days ago
    Auto-check passed
  • Android Readme Screenshot Studio

    permissionlesstech/bitchat-android

    Create or refresh polished, high-resolution screenshots of the Bitchat Android app for README and repository showcase use.

    7.8k GitHub stars~3k tokensUpdated 3 days ago
    Auto-check passed

Works with

Questions about Mesh Lab

What does Mesh Lab do?

Run, diagnose, and extend bitchat Android Mesh Lab physical-device tests. Mesh Lab is an agent skill from permissionlesstech/bitchat-android. Run, diagnose, and extend bitchat Android Mesh Lab physical-device tests.

When should I use Mesh Lab?

Mesh Lab fits situations like: work capable of changing physical peer behavior touches mesh discovery; wi-Fi transport; noise/crypto/identity; foreground-service.

How do I install Mesh Lab in Claude Code?

Run `npx skills add permissionlesstech/bitchat-android --skill mesh-lab -a claude-code`. Or copy the skill folder (.agents/skills/mesh-lab in permissionlesstech/bitchat-android) into .claude/skills/mesh-lab in your project. Claude Code loads it when a task matches its description.

How do I install Mesh Lab in Codex?

Run `npx skills add permissionlesstech/bitchat-android --skill mesh-lab -a codex`. Or copy the skill folder (.agents/skills/mesh-lab in permissionlesstech/bitchat-android) into .agents/skills/mesh-lab in your project. Codex loads it when a task matches its description.

Can I use Mesh Lab in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add permissionlesstech/bitchat-android --skill mesh-lab -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/mesh-lab, .gemini/skills/mesh-lab, .github/skills/mesh-lab and .opencode/skills/mesh-lab in your project.

What does Mesh Lab need to run?

Going by SKILL.md and its folder, Mesh Lab needs the command-line tools its instructions call (python3 and adb). Our summary lists: Python 3.

Does Mesh Lab access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Mesh Lab safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Mesh Lab use?

Mesh Lab is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Mesh Lab use?

About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Mesh Lab?

Skills that share tags, products or a category with Mesh Lab: Dep Validate (blokadaorg/blokada, 3.3k stars), SoloPi AI Control (alipay/SoloPi, 6.3k stars), BrowserStack Live Testing (handsontable/handsontable, 22k stars) and Ha Android E2E Debugging (home-assistant/android, 4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Mesh Lab?

permissionlesstech (a GitHub organization) maintains it in permissionlesstech/bitchat-android, which has 7,763 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 6, 2026.

Source: permissionlesstech/bitchat-android on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.