Hacker News new | ask | show | jobs
by croes 23 days ago
The problem is we never know if the next update doesn’t change the security to non existent and suddenly your computer is controlled by someone else.
1 comments

fair concern, but a few things should help:

- it's open source, so the update itself is auditable, not a black box push. github.com/shellular-org/packages/actions

- it's E2E encrypted end to end, so even if you don't fully trust us, the relay itself never sees your session

- you're running it via npx shellular, so you can pin a version instead of always pulling latest if you want to control exactly when you upgrade