Atlas / MCP servers / appreply-co / App Store Scraper

App Store ScraperCAUTION

mcp/appreply-co/app-store-scraper

This is an MCP server that provides tools to LLMs for searching and analyzing apps from both Google Play Store and Apple App Store – perfect for ASO.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
11 11r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
77
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This is an MCP (Model Context Protocol) server that provides tools for searching and analyzing apps from both the Google Play Store and Apple App Store.

Perfect for ASO (App Store Search Optimization).

Built by AppReply.co.

Installation

# Clone the repository
git clone https://github.com/appreply-co/mcp-appstore.git
cd mcp-appstore

# Install dependencies
npm install

Running the Server

npm start

This will start the server in studio mode, which is compatible with MCP clients.

Claude Code: Add to .mcp.json or your MCP config (path must be absolute; on Windows you can use forward slashes):

{
"mcpServers": {
"mcp-appstore": {
"command": "node",
"args": ["/absolute/path/to/mcp-appstore/server.js"]
}
}
}

Or: claude mcp add --transport stdio mcp-appstore -- node /absolute/path/to/mcp-appstore/server.js

Claude Desktop: Same mcpServers entry in claude_desktop_config.json (see Claude’s docs for the file path on your OS).

Available Tools

The server provides the following tools:

1. search_app

Search for apps by name and platform.

Parameters:

  • term: The search term to look up
  • platform: The platform to search on (ios or android)
  • num (optional): Number of results to return (default: 10, max: 250)
  • country (optional): Two-letter country code (default: "us")

Example usage:

const result = await client.callTool({
name: "search_app",
arguments: {
term: "spotify",
platform: "android",
num: 5
}
});

Response:

{
"query": "spotify",
"platform": "android",
"results": [
{
"id": "com.spotify.music",
"appId": "com.spotify.music",
"title": "Spotify: Music and Podcasts",
"developer": "Spotify AB",
"developerId": "Spotify+AB",
"icon": "https://play-lh.googleusercontent.com/...",
"score": 4.3,
"scoreText": "4
Read from source at commit a6300b343731OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-appstore -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-appstore": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (11)

11 read · 0 write · 0 destructive.

ToolRiskDescription
analyze_reviewsread
analyze_top_keywordsread
fetch_reviewsread
get_android_categoriesread
get_app_detailsread
get_developer_inforead
get_keyword_scoresread
get_pricing_detailsread
get_similar_appsread
get_version_historyread
search_appread
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

MEDIUMInventory / provenance · inv.binary · CWE-1104
.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
mcp-appstore-1.0.0.tgz
mcp-appstore-1.0.0.tgz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
server-http.run-test.js:21
const url = `http://127.0.0.1:${port}/mcp`;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
server-http.run-test.js:54
MCP_HTTP_TEST_URL: `http://127.0.0.1:${port}/mcp`,
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
server-http.test.js:15
const baseUrl = process.env.MCP_HTTP_TEST_URL || 'http://127.0.0.1:34567/mcp';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, google-play-scraper, zod, @eslint/js, eslint, globals
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha a6300b343731full audit observations/trust-audit/mcp-server/appreply-co__app-store-scraper.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07a6300b343731CAUTIONB89first audit
06

Questions

What is the App Store Scraper MCP server?

This is an MCP server that provides tools to LLMs for searching and analyzing apps from both Google Play Store and Apple App Store – perfect for ASO.

What tools does App Store Scraper expose?

11 in total: 11 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is App Store Scraper safe to connect to an agent?

With care. The audit graded it B (89/100) and found 7 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does App Store Scraper need?

No credential environment variables were found in its source, so it appears to need none.

How does App Store Scraper run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-appstore at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (a6300b343731), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement