New App: io.github.munzzyy.sweep
I did not find another stalkerware checker in F-Droid. Sweep matches installed apps against Echap's public stalkerware indicators by package name and signing certificate, so a renamed copy still matches. It also checks device admins, accessibility services, hidden apps and sideloads. It is written for people who may be at risk. It never says "you are safe". A match leads with do-not-confront advice and hotlines. No INTERNET permission. More in the listing.
App inclusion checklist
Required
- The app complies with the inclusion criteria
- The original app author has been notified and does not oppose the inclusion (I am the author)
- All related fdroiddata and RFP issues referenced (no RFP or fdroiddata issue exists for this app)
- Builds with
fdroid buildand all pipelines pass - There is an issue tracker and author contact info so bugs can be reported
Strongly recommended
- The upstream source repo carries the metadata in a Fastlane folder
- Releases are tagged and auto update is enabled
Suggested
- External repos added as git submodules instead of srclibs (there are none)
- Reproducible builds enabled
- Multiple apks for native code (single universal apk, no native code)
Build notes
Sweep is a stalkerware checkup app, the fourth of the set alongside Starling (!47404 (merged)), Sepia (!48332) and Magpie (!48333 (merged)). It reads the device surfaces an unprivileged app can see, matches installed apps against a bundled snapshot of Echap's stalkerware-indicators dataset (CC BY 4.0, pinned to an upstream commit, attribution in app/data/NOTICE.md), and never touches the network: the only manifest permission is QUERY_ALL_PACKAGES, which the scan needs for full package visibility on current Android. Same build shape as the siblings, plain gradle with the web assets copied by a Sync task, release apk unsigned for apksigcopier, signing key read from the actual v0.5.0 release apk with keytool. scandelete covers the test-tooling package.json, same as the other two.