BlitzCAUTION
Native macOS App Store Connect tool with MCP. Submit iOS apps to App Store with AI agents
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Blitz
Native macOS App Store Connect tool with MCP. Submit iOS apps, manage IAPs, and automate App Store submission with AI agents.
MCPに対応したmacOSネイティブのApp Store Connectツール。iOSアプリの提出・IAP管理・App Store提出プロセスの自動化をAIエージェントで実現
[](https://blitz-mac.com/) [](https://discord.gg/wJQ6dA95S6) [](LICENSE)
Blitz is a native macOS app for submitting iOS apps to App Store Connect using AI agents. It gives Claude Code (or any MCP client) full control over the iOS development lifecycle: running simulators, configuring in-app purchases, uploading screenshots, and triggering App Store review submissions, all from a single native macOS GUI.
If you are fighting App Store Connect to get your app submitted, Blitz automates the painful parts.
―
AIエージェントを活用してiOSアプリをApp Store Connectに提出するmacOSネイティブアプリ、Blitz。
このアプリを使えば、Claude Code(または任意のMCPクライアント)から、iOS開発ライフサイクル全体を完全に制御できます。シミュレータの実行、アプリ内課金の設定、スクリーンショットのアップロード、App Storeへの審査提出まで、すべて単一のmacOSネイティブGUIから実行できます。
App Store Connectでのアプリ提出に苦労しているなら、Blitzがその面倒な作業を自動化します。
Demo: submitting an app to App Store Connect for review
https://github.com/user-attachments/assets/07364d9f-f6a7-4375-acc8-b7ab46dcc60e
Features
19cb1793cd09OBSERVED · 2026-09-23Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add blitz-mcp -- npx -y @blitzdev/[email protected]
Trust audit
CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (19)
asc_client.cpython-314.pyc
print(f"[auth] JWT generated ({len(self.token)} chars)")-----BEGIN PRIVATE KEY-----
"privateKey": "-----BEGIN PRIVATE KEY-----\nMIGT..."
.gitmodules
- POSTs each to `http://127.0.0.1:{port}/mcp` via curl@repalash/rclone.js
@babel/runtime, @react-native-async-storage/async-storage, react-native-vector-icons, @types/react, @types/react-dom, @types/react-native-vector-icons, @vitejs/plugin-react, typescript
- `session.open` — resolves credentials, constructs warm HTTP client with cached JWT
**PocketUI:** login with `POCKET_UI_VIEWER_PASSWORD` (read-only) or `POCKET_UI_EDITOR_PASSWORD` (read+write) from `.dev.vars`/`.prod.vars`. Also accepts `ADMIN_SERVICE_TOKEN`. Change defaults before p
- **Auth**: sign-up/sign-in users in with Google, GitHub, Discord, or email/password
- **Minimal telemetry in official releases only.** GitHub release builds may embed a build-time analytics endpoint and token and send anonymous product telemetry. Source builds, forks, and debug build
-d '{ "username": "testuser", "email": "[email protected]", "password": "mypassword", "name": "Test User" }'curl -X POST http://localhost:8787/api/v1/table/users/auth/login-password \
.github/assets/before-after.png
src/resources/AIUseDemo.mp4
src/resources/OpenTerminal.mp4
src/resources/blitz-icon.png
Gates applied: no_behavioural_pass.
19cb1793cd09full audit observations/trust-audit/mcp-server/blitzdotdev__blitz.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-23 | 19cb1793cd09 | CAUTION | B | 81 | source changed, verdict held |
Questions
What is the Blitz MCP server?
Native macOS App Store Connect tool with MCP. Submit iOS apps to App Store with AI agents
Is Blitz safe to connect to an agent?
With care. The audit graded it B (81/100) and found 19 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Blitz need?
No credential environment variables were found in its source, so it appears to need none.
How does Blitz run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as __PROJECT_NAME__ at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (19cb1793cd09), read on 2026-09-23. The repository is watched and re-audited when it changes.