pcapdroid + termux · sale bundle manifest
device not swept yet · needs sdk 21+
packet capture engine — VPN-mode capture, PCAPNG dumps, Intent API we drive from the watch
Installed as a separate app and controlled over its documented Intent API. Set an api_key in /pcap so control intents are accepted without a prompt.
adb install -r PCAPdroid.apk adb shell appops set com.emanuelef.remote_capture ACTIVATE_VPN allow adb shell am start -n com.emanuelef.remote_capture/.activities.CaptureCtrl
device not swept yet · needs sdk 21+
TLS decryption add-on for PCAPdroid
Optional. Only meaningful on devices you own or are authorised to test; the CA must be trusted manually.
adb install -r PCAPdroid-mitm.apk
device not swept yet · needs sdk 24+
on-device shell that hosts the companion agent, adb, node and the Reticulum stack
Termux and its plugins must come from the same signing source (all GitHub, or all F-Droid) or the plugin refuses to bind.
adb install -r termux-app.apk pkg update -y && pkg install -y nodejs android-tools openssl termux-api git termux-setup-storage node ~/apex/agent/adb-bridge-agent.mjs --port 3001
device not swept yet · needs sdk 24+
sensor, GPS, notification and telephony bridge for scripts running in Termux
Pairs with the termux-api package inside Termux. Same-source signing rule as the main app applies.
adb install -r termux-api.apk pkg install -y termux-api termux-sensor -l termux-location -p gps
device not swept yet · needs sdk 24+
auto-starts the companion agent after a phone reboot so the bridge comes back on its own
Optional but recommended for kiosk / field builds.
adb install -r termux-boot.apk mkdir -p ~/.termux/boot printf '#!/data/data/com.termux/files/usr/bin/sh\ntermux-wake-lock\nnode ~/apex/agent/adb-bridge-agent.mjs --port 3001\n' > ~/.termux/boot/apex-agent chmod +x ~/.termux/boot/apex-agent
device not swept yet
off-grid mesh transport and message delivery used by Sovereign Netchat
The bridge agent deploys the Netchat helper; Termux installs and starts the real Reticulum/LXMF node.
pkg install -y python python -m pip install --upgrade rns lxmf termux-setup-storage mkdir -p /sdcard/apex ~/.termux && cp /sdcard/Download/apex-netchat.py ~/netchat.py && printf 'allow-external-apps=true\n' >> ~/.termux/termux.properties rnsd -d nohup python ~/netchat.py listen >> /sdcard/apex/listen.log 2>&1 &
log empty — run the install to stream agent output here
One button connects the bridge, downloads upstream APKs, installs them, deploys the Reticulum helper, and runs the Termux setup. Android may still show its required VPN, storage, and package-install consent screens.
Published as plain downloads. These are Apex work, not third-party components — each one says where it is used in the product.
Tri-Star Traffic Sanitizer
Non-rooted 3-gate outbound proxy: PE sweet-spot sweep (368–370), randomized bracket (342–396) and hard-boundary scrape, with an 11,000 ms timed escapement release.
USED BY · Sits in front of PCAPdroid's mitm socket so anything leaving the handset is scrubbed of IMEI, IMSI, MAC and precise location before it reaches the mesh or our aggregate endpoints — this is what enforces the fine-in / canonical-out rule the privacy statement and the data agreement promise.
Point PCAPdroid-mitm at 127.0.0.1 on the port the script prints. No root. Drops any field it cannot classify rather than forwarding it.
curl -fsSL https://tinyradr.lovable.app/agent/tristar_proxy.py -o ~/tristar_proxy.py pkg install python -y && python ~/tristar_proxy.py
New Barware — Trusted Cell Lock
Watches raw RIL radio logs for tracking-area changes from rogue base stations and refuses forced relocation by cutting cellular data only — the radio stays up for emergency calls.
USED BY · The IMSI-catcher guard behind the operator field tier: it is what lets a crew keep working on mesh when a rogue tower tries to pull the handset off its trusted cell.
Termux + wireless ADB on 127.0.0.1, no root. --pin learns the current tower; default mode monitors and alerts only. Log at ~/new_barware.log.
curl -fsSL https://tinyradr.lovable.app/agent/new_barware.sh -o ~/new_barware.sh sh ~/new_barware.sh --pin # then: sh ~/new_barware.sh --mode lock
Termux Field Setup
One-shot Termux preparation: packages, wake lock, boot hooks and the ADB pairing the other scripts assume.
USED BY · Run first on any new handset before the bridge agent or the two guards above.
Safe to re-run; it skips anything already in place.
curl -fsSL https://tinyradr.lovable.app/agent/termux-setup.sh -o ~/termux-setup.sh sh ~/termux-setup.sh
ADB Bridge Agent
Local listener on port 3001 that the console's install and sweep buttons drive over the bridge.
USED BY · Every live device read in this app — installed-package sweep, compatibility profile, one-tap installs.
Bind it to localhost only. Nothing on it is reachable from off the handset.
curl -fsSL https://tinyradr.lovable.app/agent/adb-bridge-agent.mjs -o ~/apex/agent/adb-bridge-agent.mjs node ~/apex/agent/adb-bridge-agent.mjs --port 3001