Hacker News new | ask | show | jobs
by sherlock-holmes 25 days ago
fair concern, but a few things should help:

- it's open source, so the update itself is auditable, not a black box push. github.com/shellular-org/packages/actions

- it's E2E encrypted end to end, so even if you don't fully trust us, the relay itself never sees your session

- you're running it via npx shellular, so you can pin a version instead of always pulling latest if you want to control exactly when you upgrade