MirroirBLOCK
MCP server for controlling a real iPhone via macOS iPhone Mirroring...and any MacOs app. Screenshot, tap, swipe, type — from any MCP client.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/mirroir-mcp) [](https://github.com/jfarcand/mirroir-mcp/actions/workflows/build.yml) [](https://github.com/jfarcand/mirroir-mcp/actions/workflows/install.yml) [](https://github.com/jfarcand/mirroir-mcp/actions/workflows/installers.yml) [](https://github.com/jfarcand/mirroir-mcp/actions/workflows/mcp-compliance.yml) [](LICENSE) [](https://support.apple.com/en-us/105071) [](https://discord.gg/jVDBbMjPMf)
Give your AI eyes, hands, and a real iPhone. An MCP server that lets any AI agent see the screen, tap what it needs, and figure the rest out — through macOS iPhone Mirroring. Experimental support for macOS windows. 38 tools, any MCP client.
Vision: agents that test — and play
mirroir is growing archetype-aware coverage for games. A game splits into two surfaces. The shell — menu, shop, loadout, settings, win/lose screens — is ordinary text-labelled UI that today's skills already drive. The scene — the playfield — is a vision-driven loop an agent follows one touch at a time. The honest targets are game QA smoke tests, tutorial walkthroughs, and scripted demos, not real-time play: iPhone Mirroring exposes a single pointer, so twin-
137cba822e5cOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mirroir-mcp -- npx -y [email protected]
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (9 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (20)
Yes. The MCP server operates at the screen level through macOS iPhone Mirroring — it taps, swipes, and types as if a human were interacting with the phone. No source code access, no app SDK, and no ja
mirroir-mcp gives AI agents eyes and hands on a real iPhone. Any LLM with MCP support can screenshot the phone, read the screen via OCR, decide what to do, and execute taps, types, and swipes — no jai
bind `[::1]` only, so `http://127.0.0.1:PORT` is refused while
.envrc.example
.gitmodules
.claude/CLAUDE.md
REAL_GATES="$HERE/../../../.registre/limitation-gates.sh"
root=$(cd "$here/../../.." && pwd)
if curl -sf http://127.0.0.1:11434/api/version > /dev/null; then
curl -sf http://127.0.0.1:11434/api/version | tee /tmp/ollama-version.json
curl -sf http://127.0.0.1:11434/api/version > /dev/null && break
url_root: http://127.0.0.1:${PORT}/path/astro
const VALID = { email: '[email protected]', password: 'correct-horse' };website/public/video1-expo-login.mp4
website/public/video2-waze-slack.mp4
- NEVER log: access tokens, refresh tokens, API keys, passwords, client secrets
- Never log access tokens, API keys, passwords, or secrets
curl -fsSL https://ollama.com/install.sh | sh
Gates applied: instruction_override, no_behavioural_pass.
137cba822e5cfull audit observations/trust-audit/mcp-server/jfarcand__mirroir.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 137cba822e5c | BLOCK | D | 69 | first audit |
Questions
What is the Mirroir MCP server?
MCP server for controlling a real iPhone via macOS iPhone Mirroring...and any MacOs app. Screenshot, tap, swipe, type — from any MCP client.
Is Mirroir safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Mirroir need?
It reads GITHUB_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Mirroir run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mirroir-mcp-website at 0.0.1.
How current is this page?
The grade is for one exact copy of the source (137cba822e5c), read on 2026-10-07. The repository is watched and re-audited when it changes.