Atlas / MCP servers / alexgladkov / Claude Mobile

Claude MobileBLOCK

mcp/alexgladkov/claude-mobile

MCP server for mobile and desktop automation — Android (via ADB), iOS Simulator (via simctl), and Desktop (Compose Multiplatform). Like Claude in Chrome but for mobile devices and desktop apps

Verdict
BLOCK
Grade
F
Trust score
48 /100
Exposed tools
200 150r · 58w · 18d
Transport
stdio
License
—
Stars
378
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

## 👉 Want everything in one package? Keep using claude-in-mobile. Nothing changes for you. Same install, all platforms bundled, still maintained: ``sh npm i -g claude-in-mobile ` That's it — the all-in-one edition. **Read on only if you'd rather install the platforms separately** (that's what mcp-devices` is for).

Two editions — same tool

Both are maintained. claude-in-mobile was renamed to mcp-devices in 4.0 and split into a modular edition; the all-in-one keeps its name and its unchanged install. The rest of this README covers the modular `mcp-devices` edition.

Install in 3 steps (modular)

Requires Node.js 20 or newer.

# 1. base server
npm i -g mcp-devices

# 2. add a platform (example: Android)
npm i -g @mcp-devices/plugin-android
mcp-devices install android

# 3. point your MCP client at it
#    { "mcpServers": { "mobile": { "command": "mcp-devices" } } }
# Grok Build:
#    grok plugin marketplace add AlexGladkov/claude-in-mobile
#    grok plugin install mcp-devices --trust

Restart your MCP client. Done — ask Claude "take a screenshot of my Android device" and it works.

Check prerequisites any time: mcp-devices doctor.

Native shell CLI

The npm command mcp-devices is the Node.js MCP server. For direct shell automation, install the native Rust CLI and use its unambiguous command name:

brew install AlexGladkov/tap/mcp-devices
mcp-devices-cli --help
mcp-devices-cli devices

The separate name prevents a global npm install from shadowing the native CLI on PATH.

Pick your platform

Each platform is a separate package. Install the one(s) you need — ful

Read from source at commit 70cbae7718afOBSERVED · 2026-10-03
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add plugin-web --env APP_STORE_CONNECT_API_KEY_ISSUER_ID=${APP_STORE_CONNECT_API_KEY_ISSUER_ID} --env APP_STORE_CONNECT_API_KEY_KEY=${APP_STORE_CONNECT_API_KEY_KEY} --env APP_STORE_CONNECT_API_KEY_KEY_FILEPATH=${APP_STORE_CONNECT_API_KEY_KEY_FILEPATH} --env APP_STORE_CONNECT_API_KEY_KEY_ID=${APP_STORE_CONNECT_API_KEY_KEY_ID} -- npx -y @mcp-devices/[email protected]
claude-desktop
{
  "mcpServers": {
    "plugin-web": {
      "command": "npx",
      "args": [
        "-y",
        "@mcp-devices/[email protected]"
      ],
      "env": {
        "APP_STORE_CONNECT_API_KEY_ISSUER_ID": "${APP_STORE_CONNECT_API_KEY_ISSUER_ID}",
        "APP_STORE_CONNECT_API_KEY_KEY": "${APP_STORE_CONNECT_API_KEY_KEY}",
        "APP_STORE_CONNECT_API_KEY_KEY_FILEPATH": "${APP_STORE_CONNECT_API_KEY_KEY_FILEPATH}",
        "APP_STORE_CONNECT_API_KEY_KEY_ID": "${APP_STORE_CONNECT_API_KEY_KEY_ID}"
      }
    }
  }
}
03

Exposed tools (200)

150 read · 58 write · 18 destructive. Blast radius: 18 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
a.toolread
accessibilityreadAccessibility audit — WCAG checks, element validation
accessibility_auditwriteRun full accessibility audit on current screen. Returns score, issues grouped by severity, and passed rules.
accessibility_checkreadCheck accessibility of a specific element found by text, resourceId, or index.
accessibility_rulesreadList all accessibility rules or show details of a specific rule.
accessibility_summaryreadQuick accessibility summary: score + issue counts only (short output).
appwriteLaunch, stop, install, list applications
app_installwriteInstall APK (Android), .app bundle (iOS), RPM (Aurora), or HAP (HarmonyOS)
app_launchreadLaunch app by package name or bundle ID
app_listreadList installed apps on a platform with app inventory support
app_restartdestructiveForce-stop then re-launch an app. Common pattern for clearing in-memory state without uninstall.
app_stopdestructiveForce stop an app
app_uninstalldestructiveUninstall an app by package name or bundle ID
appstore_buildreadBuild a signed .ipa for TestFlight (auto-detects Flutter/React Native/KMP/Xcode projects).
appstore_get_releasesreadList TestFlight builds with processing state.
appstore_promotewritePromote a TestFlight build: add it to a beta group by group name
appstore_set_noteswriteSet TestFlight
appstore_submitwriteSubmit a TestFlight build for external beta review (defaults to the latest VALID build).
appstore_uploadwriteValidate then upload an .ipa to App Store Connect (TestFlight) via altool.
autopilotreadAI-driven test generation and self-healing
autopilot_explorereadAutomatically navigate the app, building a navigation graph of screens and transitions. Uses screen fingerprinting to avoid revisiting screens.
autopilot_generatereadGenerate test scenarios from exploration data. Creates flow_run-compatible test steps for all unique paths.
autopilot_healreadSelf-heal a broken test step by finding the best matching element on the current screen. Uses fuzzy matching on text, resourceId, className, and bounds.
autopilot_statusreadGet exploration status. If explorationId is provided, shows details. Otherwise lists all explorations.
autopilot_testsreadList or get generated test scenarios for an exploration.
bad.toolread
browserreadBrowser automation — navigate, evaluate JS, manage tabs
browser_clear_sessiondestructiveDelete all stored data for a session
browser_clickreadClick element by ref, selector, or text
browser_closereadClose browser session
browser_evaluatewriteExecute JavaScript in browser page
browser_fillreadFill input field with value
browser_fill_formreadFill multiple form fields at once
browser_list_sessionsreadList active browser sessions
browser_navigatereadNavigate to URL or go back/forward/reload
browser_openreadOpen URL in browser session
browser_press_keyreadPress keyboard key in browser
browser_screenshotreadTake browser page screenshot
browser_snapshotreadGet accessibility snapshot with element refs
browser_wait_for_selectorreadWait for element to appear on page
clickreadHijack
clipboard_copyreadSelect all and copy to clipboard (Android only)
clipboard_getreadGet clipboard text (Desktop only)
clipboard_get_androidreadRead clipboard text from Android device
clipboard_pastereadPaste clipboard into focused field (Android only)
clipboard_selectreadSelect all text in focused field (Android only)
clipboard_setwriteSet clipboard text (Desktop only)
debug_attachreadAttach the runtime debugger to a DEBUGGABLE running app. Android (JDWP): the package must have android:debuggable=true. iOS (LLDB Simulator): requires macOS + Xcode. Returns a sessionId for all subsequent debug calls.
debug_breakwriteSet a breakpoint. Android: {className, line} or {className, method} (method-entry, robust without line info). iOS: {file, line} or {method}. Returns { id, verified }. verified=false means the class is not yet loaded — the breakpoint will arm on CLASS_PREPARE.
debug_detachreadDetach the debugger and end the session (the app keeps running). Also tears down the adb forward / LLDB daemon for this session.
debug_evalreadEvaluate an expression on a paused thread. Android: a local name,
debug_pause_statereadInspect a paused thread: call stack frames (class, method, line) and the top frame
debug_pollreadPoll the event queue for hits (BREAKPOINT_HIT / STEP_HIT / EXCEPTION_HIT / CLASS_PREPARE / VM_DEATH). Never blocks. Start cursor at 0, advance nextCursor on each call. If the queue is empty, ask the user to interact with the app, then poll again.
debug_remove_breakdestructiveRemove a breakpoint by its id (returned by debug_break).
debug_resumereadResume all threads in the debugged VM/process. Use after inspecting a paused state to let the app continue running.
debug_sessionsreadList active debug sessions (sessionId + platform). Useful to discover open sessions before attaching or after a crash.
debug_set_varwriteMutate a local variable on a paused thread. Android: primitives (int/long/bool/float/...), null, and strings; the value is coerced to the local
debug_stepreadStep the paused thread: OVER (next line), INTO (into call), or OUT (out of current method). Issues the step and resumes the thread; poll for STEP_HIT to see where execution landed.
debug_threadsreadList threads of the debugged VM with ids and names (Android). Use an id with debug_pause_state / debug_step to target a specific thread.
desktopreadDesktop app control — windows, clipboard, performance
desktop_focusreadFocus a desktop window
desktop_get_target_pidwriteGet the PID of the native app set by the last desktop_launch (bundle or attach mode). Returns null if no target PID is set.
desktop_launchwriteStart desktop automation and optionally launch an app. Supports three modes:
desktop_monitorsreadList connected monitors (Desktop only)
desktop_performancereadGet memory and CPU metrics (Desktop only)
desktop_resizereadResize a desktop window
desktop_stopwriteStop running desktop application
desktop_windowsreadGet desktop window info
devicereadDevice management, module loading, target switching
device_get_targetreadGet current active platform and status
device_inforeadGet device info
device_listreadList connected devices and emulators
device_set_targetwriteSwitch active platform (android/ios/desktop/aurora/harmony/browser)
early.toolread
find_elementreadFind element by text
flowreadBatch commands, multi-step automation, parallel execution
flow_batchwriteExecute multiple commands in one round-trip. Set turbo:true for UI context per step (experimental).
flow_parallelwriteRun same action on multiple devices in parallel. Uses Promise.allSettled for concurrent execution.
flow_runwriteMulti-step automation flow with conditionals, loops, error handling. Use for E2E testing instead of calling tools one-by-one. Set turbo:true for UI context per step (experimental). Max 20 steps.
get_uireadGet UI elements on screen
go_backreadPress back button
harmony_arkweb_closedestructiveRemove an ArkWeb HDC port-forward created for inspection.
harmony_arkweb_inspectreadDiscover an ArkWeb DevTools socket, forward it over HDC, and list inspectable pages.
harmony_launch_abilityreadLaunch a HarmonyOS ability with an optional module name. Defaults to EntryAbility.
harmony_sandbox_listreadList files in a running debug-signed HarmonyOS application
harmony_sandbox_pullreadDownload a file from a running debug-signed HarmonyOS application
harmony_sandbox_pushwriteUpload a file into a running debug-signed HarmonyOS application
harmony_sandbox_readreadRead a text file from a running debug-signed HarmonyOS application
harmony_testwriteRun an ArkXTest module through
huawei_get_releasesreadGet release info from Huawei AppGallery
huawei_set_noteswriteSet release notes for Huawei AppGallery draft
huawei_submitwriteSubmit Huawei AppGallery draft for review
huawei_uploadwriteUpload APK/AAB to Huawei AppGallery. Requires HUAWEI_CLIENT_ID env.
inputreadTap, swipe, type, key press — all input actions
input_double_tapreadDouble tap by coordinates, text, resourceId, or index. Raw x/y are screenshot-space and auto-scaled to device coordinates — see input_tap description for full coordinate space rules.
input_keyreadPress hardware key (BACK, HOME, ENTER, etc.)
input_long_pressreadLong press at coordinates or on element by text/label. Raw x/y are screenshot-space and auto-scaled to device coordinates — see input_tap description for full coordinate space rules.
input_swipereadSwipe by direction or custom coordinates. Raw x1/y1/x2/y2 are screenshot-space and auto-scaled to device coordinates — see input_tap description for full coordinate space rules.
input_tapreadTap
input_textreadType text into focused input field
intentwriteIntent & deep link engine — am start/broadcast with typed extras
intent_broadcastwriteSend an Android broadcast intent. Useful for triggering system events or communicating with broadcast receivers. Android only.
intent_deeplinkreadOpen a deep link URI on Android or iOS. On Android uses
intent_servicesreadList running Android services. Optionally filter by package name. Android only.
intent_startwriteLaunch an Activity with a structured Android Intent. Supports action, component, data URI, category, typed extras, and activity flags. Android only; use intent_deeplink for iOS.
late.toolread
launch_appreadLaunch app
mod_areadA
mod_breadB
networkreadNetwork layer — traffic stats, connectivity, proxy, airplane mode
network_airplanewriteEnable or disable airplane mode on the Android device.
network_connectivityreadGet current network connectivity info: active network type (WiFi/Mobile/etc), connection state, IP address, DNS servers, and basic WiFi details (SSID, RSSI). Android only.
network_proxydestructiveGet, set, or clear the global HTTP proxy for the Android device.
network_trafficreadGet network traffic statistics. If a package name is provided, shows per-app traffic (rx/tx bytes and packets) using kernel UID counters. Otherwise shows global per-interface totals from dumpsys netstats. Android only.
new-namereadNew
ownedreadOwned
performancereadPerformance Lab — metrics, crashes, native traces, heap snapshots and diffs
performance_baselinewriteSave current performance metrics as a named baseline for later comparison.
performance_comparereadCompare current performance against a saved baseline. Returns PASS/FAIL per metric with thresholds.
performance_crashesreadQuery recent crashes, ANRs, and native crashes from device logs.
performance_framestatsreadCollect frame rendering statistics from GPU profiling. Returns frame time percentiles (p50/p90/p99), jank rate, and slow render percentage. Android only.
performance_heap_capturereadCapture a private heap artifact without returning raw heap contents through MCP. Android requires a debuggable package, iOS requires a running Simulator app, and browser uses the active CDP session.
performance_heap_deletedestructiveDelete a captured heap artifact and its metadata immediately.
performance_heap_diffreadCompare bounded metadata from two compatible heap artifacts. Returns signed size/count deltas; it does not claim that growth is a memory leak.
performance_monitorreadMonitor performance over a duration, collecting periodic samples. Returns min/max/avg stats.
performance_snapshotreadCollect current performance metrics: memory, CPU, FPS, battery, crash count. Returns formatted report.
performance_trace_deletedestructiveDelete a captured native performance trace artifact and its metadata.
performance_trace_startwriteStart a bounded native performance trace. Android records Perfetto, iOS records an Instruments xctrace bundle, and browser records Chrome tracing. Stop it to persist a private artifact and receive a compact summary.
performance_trace_statusreadList active performance traces and the remaining capture window.
performance_trace_stopwriteFinalize an active performance trace, store the native artifact with mode 0600 and 24-hour TTL, and return a bounded agent-readable summary plus checksum.
permission_grantreadGrant app permission (Android runtime / iOS privacy)
permission_resetdestructiveReset all permissions for an app
permission_revokedestructiveRevoke app permission
press_keyreadPress key
recorderreadRecord and replay interaction sequences
recorder_add_stepwriteManually add a step to the active recording
recorder_deletedestructiveDelete a saved scenario
recorder_exportreadExport scenario as flow_steps (for flow_run) or markdown checklist
recorder_listreadList saved test scenarios
recorder_playreadReplay a saved scenario. Executes all steps sequentially with optional speed/timeout control.
recorder_remove_stepdestructiveRemove a step from the active recording by index
recorder_showreadDisplay contents of a saved scenario
recorder_startwriteBegin recording user interactions as a test scenario
recorder_statusreadGet current recording state
recorder_stopwriteStop recording and save scenario (or discard)
repl_expectreadBlock until a prompt regex matches, the session idles, the child exits, or the timeout fires.
repl_keywriteSend a named key to a session. Editing/navigation for driving TUIs.
repl_killdestructiveTerminate a REPL session (SIGTERM, then SIGKILL).
repl_listreadList active REPL sessions and their statuses.
repl_resizereadResize the PTY and vt100 grid for a live session.
repl_sendwriteWrite text to a REPL session. Appends a newline by default.
repl_snapshotreadRead the current emulated terminal screen for a session.
repl_spawnwriteStart an interactive REPL or CLI process under a PTY. Returns the session id.
rustore_discarddestructiveDelete RuStore version draft
rustore_get_versionsreadGet version list from RuStore
rustore_set_noteswriteSet what
rustore_submitwriteSubmit RuStore draft for moderation
rustore_uploadwriteUpload APK/AAB to RuStore. Requires RUSTORE_KEY_JSON env.
sandboxwriteApp sandbox access — SharedPreferences, SQLite, file operations via run-as
sandbox_file_listreadList files inside an app
sandbox_file_readreadRead the contents of a file from an app
sandbox_prefs_readreadRead SharedPreferences XML from an app
sandbox_prefs_writewriteWrite or update a single value in an app
sandbox_sqlite_querywriteRun a read-only SQL query against an app
screenreadScreenshot capture, annotation, diff comparison
screen_annotatereadScreenshot with numbered bounding boxes on UI elements (Android/iOS)
screen_capturereadTake screenshot. Auto-compressed. Use diff=true to see only changes.
screenshotreadTake screenshot
sensorreadSensor & environment simulation — GPS, battery, notifications, thermal
sensor_batterywriteSet battery level, charging status, and plugged state on Android. Changes persist until reset:true is used or device reboots. iOS: not supported.
sensor_locationwriteSet GPS location on device. Android emulator: uses
sensor_notificationsreadRead the notification shade from Android. Returns a parsed list of active notifications with title, text, package, and time. iOS: not supported.
sensor_thermalreadOverride Android thermal status (API 29+ / Android 10+). Simulates device overheating scenarios. Use reset:true to restore real thermal state. iOS: not supported.
storereadApp store metadata — ratings, reviews, versions
store_discardreadDiscard Google Play release draft
store_get_releasesreadGet current releases across Google Play tracks
store_halt_rolloutreadHalt staged rollout on Google Play
store_promotereadPromote release between Google Play tracks
store_set_noteswriteSet release notes for Google Play draft (per language, max 500 chars)
store_submitwritePublish release draft to Google Play track
store_uploadwriteUpload APK/AAB to Google Play. Requires GOOGLE_PLAY_KEY_FILE env.
swipereadSwipe in a direction
syncwriteMulti-device synchronization and coordination
sync_assert_crosswriteCross-device assertion: perform action on source device, verify result on target device with retries.
sync_create_groupwriteCreate a sync group of 2+ devices with named roles for coordinated testing.
sync_destroydestructiveDestroy a sync group and release resources.
sync_listwriteList all active sync groups.
sync_runwriteExecute coordinated steps across devices with barrier synchronization.
sync_statuswriteShow details of a sync group and its last run result.
systemreadShell, logs, clipboard, permissions, URL, device info
system_activityreadGet current foreground activity (Android only)
system_clear_logsdestructiveClear the device log buffer
system_file_pullwriteDownload a file from a device with file transfer support
system_file_pushwriteUpload a local file to a device with file transfer support
system_inforeadGet battery and memory info
system_is_runningreadCheck whether an app process is currently running by package name (Android only). Returns
system_logsreadGet device logs with optional filters
system_open_urlreadOpen URL in device browser
system_pid_ofreadGet the PID of a running app process by package name (Android only). Returns 0 when the package is not running. Useful for verifying app launch / crash detection without parsing the full ps output.
system_shellreadShell
04

Trust audit

BLOCKgrade F · trust 48/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (12 observation(s))
Network
declared (9 observation(s))
Shell
declared (4 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.slack · CWE-798, CWE-321
cli/src/plugins/repl/redaction.rs:297
let out = redact("token=xoxb-1234567890-fake-slack-token");
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/plugin-android/src/adb/client.ts:95
exec(command: string, deviceIdOverride?: string): string {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/plugin-debug/src/controller.ts:317
eval(sessionId: string, threadId: string, expr: string): Promise<unknown> {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/adapters/contracts.ts:105
exec(command: string): string;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
desktop-companion/gradle/wrapper/gradle-wrapper.jar
gradle-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
cli/src/harmony.rs:850
let url = format!("http://127.0.0.1:{port}/json/list");
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/plugin-android/src/adb/webview.ts:157
const response = await fetch(`http://127.0.0.1:${selectedPort}/json/list`, {
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/plugin-android/src/adb/webview.ts:187
const response = await fetch(`http://127.0.0.1:${selectedPort}/json/list`, {
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
packages/plugin-harmony/src/client.ts:702
`http://127.0.0.1:${localPort}/json/list`,
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
cli/tests/repl_observability.rs:65
let secret = "sk-ant-api03-TESTSECRETFORCAST00000";
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
cli/tests/repl_observability.rs:124
let secret = "sk-ant-api03-LIVETEST00000000000000000";
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
cli/tests/repl_observability.rs:247
let secret = "sk-ant-api03-INTEGRATIONTESTBOTH0000000";
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
src/plugins/repl/index.test.ts:52
cmd: "deploy --key sk-ant-AAAAAAAAAAAAAAAAAAAAAAAA",
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
src/plugins/repl/index.test.ts:71
expect(out[0].cmd).toBe("deploy --key sk-ant-AAAAAAAAAAAAAAAAAAAAAAAA");
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
cli/tests/repl_observability.rs:440
"AKIA0000000000000000",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
cli/tests/repl_observability.rs:65
let secret = "sk-ant-api03-TESTSECRETFORCAST00000";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
cli/tests/repl_observability.rs:124
let secret = "sk-ant-api03-LIVETEST00000000000000000";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
cli/tests/repl_observability.rs:205
let secret = "ghp_1234567890abcdefghijklmnopqrstuvwxyz";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
cli/tests/repl_observability.rs:247
let secret = "sk-ant-api03-INTEGRATIONTESTBOTH0000000";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
desktop-companion/src/test/kotlin/com/anthropic/desktop/JsonRpcServerTest.kt:23
val secret = "unknown-secret-bearing-method"
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
cli/tests/repl_observability.rs:205
let secret = "ghp_1234567890abcdefghijklmnopqrstuvwxyz";
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
spec/changes/claude-in-android/tasks.md:120
`ghp_16C7e42F292c6912E7710c838347Ae178B4a`, `xoxb-111-222-aaaaa`, minimal JWT (`eyJhbGc...`),
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
src/plugins/repl/index.test.ts:188
const TOKEN = "ghp_1234567890abcdefghijklmnopqrstuvwxyz";
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
src/plugins/repl/redaction.test.ts:13
const out = redactScreen("token: ghp_1234567890abcdefghijklmnopqrstuvwxyz");
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
src/plugins/repl/security.test.ts:63
"ghp_1234567890abcdefghijklmnopqrstuvwxyz",

Gates applied: critical_finding, no_behavioural_pass, no_license.

Audited 2026-10-03 · audit v0.4.1 · source sha 70cbae7718affull audit observations/trust-audit/mcp-server/alexgladkov__claude-mobile.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0370cbae7718afBLOCKF48first audit
06

Questions

What is the Claude Mobile MCP server?

MCP server for mobile and desktop automation — Android (via ADB), iOS Simulator (via simctl), and Desktop (Compose Multiplatform). Like Claude in Chrome but for mobile devices and desktop apps

What tools does Claude Mobile expose?

200 in total: 150 read-only, 58 that write, and 18 that can delete or overwrite (app_restart, app_stop, app_uninstall, browser_clear_session, debug_remove_break). Every one is listed on this page with its risk.

Is Claude Mobile safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (48/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 18 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Claude Mobile need?

It reads APP_STORE_CONNECT_API_KEY_ISSUER_ID, APP_STORE_CONNECT_API_KEY_KEY, APP_STORE_CONNECT_API_KEY_KEY_FILEPATH, APP_STORE_CONNECT_API_KEY_KEY_ID, ASC_KEY_FILE, ASC_KEY_ID, ASC_PRIVATE_KEY, GOOGLE_PLAY_KEY_FILE, HUAWEI_CLIENT_SECRET, RUSTORE_KEY_ID, RUSTORE_KEY_JSON and RUSTORE_PRIVATE_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Claude Mobile run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @mcp-devices/plugin-web at 4.4.1.

How current is this page?

The grade is for one exact copy of the source (70cbae7718af), read on 2026-10-03. The repository is watched and re-audited when it changes.

Advertisement