ApplescriptSAFE
A macOS AppleScript MCP server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol server that enables LLM applications to interact with macOS through AppleScript. This server provides a standardized interface for AI applications to control system functions, manage files, handle notifications, and more.
[](https://github.com/joshrutkowski/applescript-mcp/actions/workflows/node.js.yml)
Features
- 🗓️ Calendar management (events, reminders)
- 📋 Clipboard operations
- 🔍 Finder integration
- 🔔 System notifications
- ⚙️ System controls (volume, dark mode, apps)
- 📟 iTerm terminal integration
- 📬 Mail (create new email, list emails, get email)
- 🔄 Shortcuts automation
- 💬 Messages (list chats, get messages, search messages, send a message)
- 🗒️ Notes (create formatted notes, list notes, search notes)
- 📄 Pages (create documents)
Planned Features
- 🧭 Safari (open in Safari, save page content, get selected page/tab)
- ✅ Reminders (create, get)
Prerequisites
- macOS 10.15 or later
- Node.js 18 or later
Available Categories
Calendar
Examples
// Create a new calendar event Create a calendar event titled "Team Meeting" starting tomorrow at 2pm for 1 hour // List today's events What events do I have scheduled for today?
Clipboard
cb6afab31b09OBSERVED · 2026-10-01Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add applescript-mcp -- npx -y [email protected]
{
"mcpServers": {
"applescript-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (43)
31 read · 11 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add | write | Add a new event to Calendar |
calendar | read | Calendar operations |
clear_clipboard | destructive | Clear clipboard content |
clipboard | read | Clipboard management operations |
compose_message | write | Open Messages app with a pre-filled message to a recipient or automatically send a message |
create | write | Create a new note with optional formatting |
createRawHtml | write | Create a new note with direct HTML content |
create_document | write | Create a new Pages document with plain text content (no formatting) |
create_email | write | Create a new email in Mail.app |
finder | read | Finder and file operations |
get | read | Get a specific note by title |
get_battery_status | read | Get battery level and charging status |
get_clipboard | read | Get current clipboard content |
get_email | read | Get a specific email by search criteria from Mail.app |
get_frontmost_app | read | Get the name of the frontmost application |
get_messages | read | Get messages from the Messages app |
get_selected_files | read | Get currently selected files in Finder |
iterm | read | iTerm terminal operations |
launch_app | read | Launch an application |
list | read | List all events for today |
list_chats | read | List available iMessage and SMS chats |
list_emails | read | List emails from a specified mailbox in Mail.app |
list_shortcuts | read | List all available shortcuts with optional limit |
mail | read | Mail operations |
messages | read | iMessage operations |
notes | read | Apple Notes operations |
notifications | read | Notification management |
pages | read | Pages document operations |
paste_clipboard | read | Paste clipboard content into iTerm |
quick_look_file | read | Preview a file using Quick Look |
quit_app | read | Quit an application |
run | write | Run a command in iTerm |
run_shortcut | write | Run a shortcut with optional input. Uses Shortcuts Events to run in background without opening the app. |
search | read | Search for notes containing specific text |
search_files | read | Search for files by name |
search_messages | read | Search for messages containing specific text or from a specific sender |
send_notification | write | Send a system notification |
set_clipboard | write | Set clipboard content |
shortcuts | read | Shortcuts operations |
system | read | System control and information |
toggle_dark_mode | read | Toggle system dark mode |
toggle_do_not_disturb | read | Toggle Do Not Disturb mode using keyboard shortcut |
volume | write | Set system volume |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
clear_clipboard
@modelcontextprotocol/sdk, @types/node, typescript, ts-node
Gates applied: no_behavioural_pass.
cb6afab31b09full audit observations/trust-audit/mcp-server/joshrutkowski__applescript.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-01 | cb6afab31b09 | SAFE | B | 89 | first audit |
Questions
What is the Applescript MCP server?
A macOS AppleScript MCP server
What tools does Applescript expose?
43 in total: 31 read-only, 11 that write, and 1 that can delete or overwrite (clear_clipboard). Every one is listed on this page with its risk.
Is Applescript safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Applescript need?
No credential environment variables were found in its source, so it appears to need none.
How does Applescript run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as applescript-mcp at 1.0.4.
How current is this page?
The grade is for one exact copy of the source (cb6afab31b09), read on 2026-10-01. The repository is watched and re-audited when it changes.