callstackincubator cordierite
COMMUNITYLABSCO SUMMARY
The repository is a small monorepo, not a folder of skill files: cordierite is the CLI and host you run from a terminal, @cordierite/shared is a client library shared between the CLI and the app, and @cordierite/react-native is the TurboModule client an app imports and calls registerTool() from. Security is built around TLS with SPKI pinning to a key the developer generates with cordierite keygen and embeds in the app's config, plus a one-time session bootstrap after a deep link is opened — the README is explicit that the deep link itself proves nothing, and that IP address, DNS, or a crafted link are not enough to impersonate the host.
This is for a team that wants specific, developer-defined actions reachable inside a shipping React Native app — for a QA runner, a CI script, or an agent host — without adding a debug menu or a hidden gesture to the production binary. It needs iOS or Android with React Native's New Architecture and a real rebuild after the native config changes; the README lists web as "a safe stub only," and Expo Go specifically will not work, only a development build or a bare native app.
READ THE FULL ANALYSIS
One limitation is in the README itself, not something we found by testing it. Once a Cordierite host is running, its local control API is unauthenticated — any process on the same machine that can reach the local control port can invoke tools on the connected app. The project calls this "a known limitation today," which is worth weighing against the TLS-pinning story told everywhere else in the same document.
This is an early project. It sits under Callstack's "incubator" GitHub org rather than the main Callstack org, carries 2 stars, and the one skill in our index is the entirety of what's documented for it — there is no second skill covering exploratory or automated testing on top of the base tool-invocation flow.
WHAT'S INSIDE
1 showing · 1 totalcordierite
A live link between a phone app that is already running and the terminal on your machine, so the app can be driven by typing instead of tapping through it.
HOW TO GET IT
npx skills add callstackincubator/cordieritenpx skills add callstackincubator/cordierite --skill <name> --full-depthPick the skill name from the Skills tab — each entry there installs independently.