Atlas / MCP servers / blitzdotdev / Blitz

BlitzCAUTION

mcp/blitzdotdev/blitz

Native macOS App Store Connect tool with MCP. Submit iOS apps to App Store with AI agents

Verdict
CAUTION
Grade
B
Trust score
81 /100
Exposed tools
—
Transport
stdio
License
Apache-2.0
Stars
1,747
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Blitz

Native macOS App Store Connect tool with MCP. Submit iOS apps, manage IAPs, and automate App Store submission with AI agents.

MCPに対応したmacOSネイティブのApp Store Connectツール。iOSアプリの提出・IAP管理・App Store提出プロセスの自動化をAIエージェントで実現

[](https://blitz-mac.com/) [](https://discord.gg/wJQ6dA95S6) [](LICENSE)

Blitz is a native macOS app for submitting iOS apps to App Store Connect using AI agents. It gives Claude Code (or any MCP client) full control over the iOS development lifecycle: running simulators, configuring in-app purchases, uploading screenshots, and triggering App Store review submissions, all from a single native macOS GUI.

If you are fighting App Store Connect to get your app submitted, Blitz automates the painful parts.

―

AIエージェントを活用してiOSアプリをApp Store Connectに提出するmacOSネイティブアプリ、Blitz。

このアプリを使えば、Claude Code(または任意のMCPクライアント)から、iOS開発ライフサイクル全体を完全に制御できます。シミュレータの実行、アプリ内課金の設定、スクリーンショットのアップロード、App Storeへの審査提出まで、すべて単一のmacOSネイティブGUIから実行できます。

App Store Connectでのアプリ提出に苦労しているなら、Blitzがその面倒な作業を自動化します。

Demo: submitting an app to App Store Connect for review

https://github.com/user-attachments/assets/07364d9f-f6a7-4375-acc8-b7ab46dcc60e

Features

Read from source at commit 19cb1793cd09OBSERVED · 2026-09-23
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add blitz-mcp -- npx -y @blitzdev/[email protected]
03

Trust audit

CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (19)

MEDIUMInventory / provenance · inv.binary · CWE-1104
scripts/asc-api-tests/__pycache__/asc_client.cpython-314.pyc
asc_client.cpython-314.pyc
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
scripts/asc-api-tests/asc_client.py:69
print(f"[auth] JWT generated ({len(self.token)} chars)")
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
Tests/blitz_tests/ASCAuthBridgeTests.swift:29
-----BEGIN PRIVATE KEY-----
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
docs/app-store-submission-pipeline.md:32
"privateKey": "-----BEGIN PRIVATE KEY-----\nMIGT..."
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/mcp-tools-approval-flow.md:111
- POSTs each to `http://127.0.0.1:{port}/mcp` via curl
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@repalash/rclone.js
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
src/templates/rn-notes-template/package.json
@babel/runtime, @react-native-async-storage/async-storage, react-native-vector-icons, @types/react, @types/react-dom, @types/react-native-vector-icons, @vitejs/plugin-react, typescript
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/codex-migration-prompt.md:39
- `session.open` — resolves credentials, constructs warm HTTP client with cached JWT
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
src/resources/rules/teenybase-rules.md:324
**PocketUI:** login with `POCKET_UI_VIEWER_PASSWORD` (read-only) or `POCKET_UI_EDITOR_PASSWORD` (read+write) from `.dev.vars`/`.prod.vars`. Also accepts `ADMIN_SERVICE_TOKEN`. Change defaults before p
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:62
- **Auth**: sign-up/sign-in users in with Google, GitHub, Discord, or email/password
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:141
- **Minimal telemetry in official releases only.** GitHub release builds may embed a build-time analytics endpoint and token and send anonymous product telemetry. Source builds, forks, and debug build
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
src/resources/rules/teenybase-rules.md:226
-d '{ "username": "testuser", "email": "[email protected]", "password": "mypassword", "name": "Test User" }'
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
src/resources/rules/teenybase-rules.md:230
curl -X POST http://localhost:8787/api/v1/table/users/auth/login-password \
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOInventory / provenance · inv.oversize · CWE-1104
.github/assets/before-after.png
.github/assets/before-after.png
Why it matters. 1509314 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
src/resources/AIUseDemo.mp4
src/resources/AIUseDemo.mp4
Why it matters. 2958927 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
src/resources/OpenTerminal.mp4
src/resources/OpenTerminal.mp4
Why it matters. 6181644 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
src/resources/blitz-icon.png
src/resources/blitz-icon.png
Why it matters. 2421548 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-23 · audit v0.4.1 · source sha 19cb1793cd09full audit observations/trust-audit/mcp-server/blitzdotdev__blitz.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2319cb1793cd09CAUTIONB81source changed, verdict held
05

Questions

What is the Blitz MCP server?

Native macOS App Store Connect tool with MCP. Submit iOS apps to App Store with AI agents

Is Blitz safe to connect to an agent?

With care. The audit graded it B (81/100) and found 19 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Blitz need?

No credential environment variables were found in its source, so it appears to need none.

How does Blitz run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as __PROJECT_NAME__ at 0.0.0.

How current is this page?

The grade is for one exact copy of the source (19cb1793cd09), read on 2026-09-23. The repository is watched and re-audited when it changes.

Advertisement