Atlas / MCP servers / joshuarileydev / App Store Connect

App Store ConnectBLOCK

mcp/joshuarileydev/app-store-connect
Verdict
BLOCK
Grade
F
Trust score
29 /100
Exposed tools
27 19r · 7w · 1d
Transport
stdio
License
MIT
Stars
331
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server for interacting with the App Store Connect API. This server provides tools for managing apps, beta testers, bundle IDs, devices, app metadata, and capabilities in App Store Connect.

[](https://cursor.com/install-mcp?name=app-store-connect&config=JTdCJTIyY29tbWFuZCUyMiUzQSUyMm5weCUyMC15JTIwYXBwc3RvcmUtY29ubmVjdC1tY3Atc2VydmVyJTIyJTdE)

Overview

The App Store Connect MCP Server is a comprehensive tool that bridges the gap between AI and Apple's App Store Connect ecosystem. Built on the Model Context Protocol (MCP), this server enables developers to interact with their App Store Connect data directly through conversational AI, making app management, beta testing, and analytics more accessible than ever.

Key Benefits:

  • 🤖 AI-Powered App Management: Use natural language to manage your iOS and macOS apps
  • 📊 Comprehensive Analytics: Access detailed app performance, sales, and user engagement data
  • 👥 Streamlined Beta Testing: Efficiently manage beta groups and testers
  • 🌍 Localization Management: Update app descriptions, keywords, and metadata across all languages
  • 🔧 Developer Tools Integration: List Xcode project schemes and integrate with development workflows
  • 🔐 Secure Authentication: Uses official App Store Connect API with JWT authentication
  • 🚀 Real-time Data: Access up-to-date information directly from Apple's systems

Who This Is For:

  • iOS/macOS developers managing apps in App Store Connect
  • Development teams coordinating beta testing programs
  • Product managers analyzing app performance and user engagement
  • Marketing teams managing app metadata and localizations
  • DevOps engineers automating app store workflows
  • Anyone looking to streamline their Apple developer experience

This server transforms complex App Store Connect operations into simple conversational commands, whether

Read from source at commit 14e830b9eb58OBSERVED · 2026-10-03
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add appstore-connect-mcp-server --env APP_STORE_CONNECT_KEY_ID=${APP_STORE_CONNECT_KEY_ID} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "appstore-connect-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "APP_STORE_CONNECT_KEY_ID": "${APP_STORE_CONNECT_KEY_ID}"
      }
    }
  }
}
03

Exposed tools (27)

19 read · 7 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_tester_to_groupwriteAdd a new tester to a beta group
create_analytics_report_requestwriteCreate a new analytics report request for an app
create_app_store_versionwriteCreate a new app store version for an app
create_bundle_idwriteRegister a new bundle ID for app development
disable_bundle_capabilitywriteDisable a capability for a bundle ID
download_analytics_report_segmentreadDownload data from an analytics report segment URL
download_finance_reportreadDownload finance reports for a specific region
download_sales_reportreadDownload sales and trends reports
enable_bundle_capabilitywriteEnable a capability for a bundle ID
get_app_inforeadGet detailed information about a specific app
get_app_store_version_localizationreadGet detailed information about a specific app store version localization
get_beta_feedback_screenshotreadGet detailed information about a specific beta feedback screenshot submission. By default, downloads and returns the screenshot image.
get_bundle_id_inforeadGet detailed information about a specific bundle ID
list_analytics_report_segmentsreadGet segments for a specific analytics report (contains download URLs)
list_analytics_reportsreadGet available analytics reports for a specific report request
list_app_store_version_localizationsreadGet all localizations for a specific app store version
list_app_store_versionsreadGet all app store versions for a specific app
list_appsreadGet a list of all apps in App Store Connect
list_beta_feedback_screenshotsreadList all beta feedback screenshot submissions for an app. This includes feedback with screenshots, device information, and tester comments. You can identify the app using either appId or bundleId.
list_beta_groupsreadGet a list of all beta groups (internal and external)
list_bundle_idsreadFind and list bundle IDs that are registered to your team
list_devicesreadGet a list of all devices registered to your team
list_group_testersreadGet a list of all testers in a specific beta group
list_schemesreadList all available schemes in an Xcode project or workspace
list_usersreadGet a list of all users registered on your App Store Connect team
remove_tester_from_groupdestructiveRemove a tester from a beta group
update_app_store_version_localizationwriteUpdate a specific field in an app store version localization
04

Trust audit

BLOCKgrade F · trust 29/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (9 observation(s))
Shell
declared (10 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
node_modules/depd/index.js:425
var deprecatedfn = new Function('fn', 'log', 'deprecate', 'message', 'site',
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
node_modules/depd/index.js:427
'return function (' + args + ') {' +
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
node_modules/function-bind/implementation.js:74
bound = Function('binder', 'return function (' + joiny(boundArgs, ',') + '){ return binder.apply(this,arguments); }')(binder);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
node_modules/shelljs/src/common.js:334
if (options.unix === false) { // this branch is for exec()
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
node_modules/typescript/lib/lib.es5.d.ts:998
exec(string: string): RegExpExecArray | null;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHSupply chain · supply.typosquat · CWE-829, CWE-1357
node_modules/form-data/package.json
request ~ requests
Why it matters. dependency name one edit from a popular package
Fix. verify the package; likely typosquat
HIGHSupply chain · supply.typosquat · CWE-829, CWE-1357
node_modules/iconv-lite/package.json
request ~ requests
Why it matters. dependency name one edit from a popular package
Fix. verify the package; likely typosquat
MEDIUMInventory / provenance · inv.binary · CWE-1104
.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
node_modules/bare-fs/prebuilds/android-arm/bare-fs.bare
bare-fs.bare
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
node_modules/bare-fs/prebuilds/android-arm64/bare-fs.bare
bare-fs.bare
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
node_modules/bare-fs/prebuilds/android-ia32/bare-fs.bare
bare-fs.bare
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
node_modules/bare-fs/prebuilds/android-x64/bare-fs.bare
bare-fs.bare
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.symlink · CWE-1104
node_modules/.bin/prebuild-install
node_modules/.bin/prebuild-install
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
node_modules/.bin/rc
node_modules/.bin/rc
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
node_modules/.bin/resolve
node_modules/.bin/resolve
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
node_modules/.bin/semver
node_modules/.bin/semver
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
node_modules/.bin/shjs
node_modules/.bin/shjs
Why it matters. link not followed
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
node_modules/@types/node/url.d.ts:545
* console.log(myURL.password);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
node_modules/proxy-from-env/test.js:313
testProxyUrl(env, '', 'http://10.0.0.1/');
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
node_modules/proxy-from-env/test.js:314
testProxyUrl(env, '', 'http://10.0.0.1:80/');
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
node_modules/proxy-from-env/test.js:315
testProxyUrl(env, '', 'http://10.0.0.1:1337/');
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
node_modules/proxy-from-env/test.js:317
testProxyUrl(env, '', 'http://10.0.0.2/');
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
node_modules/iconv-lite/encodings/sbcs-data-generated.js:100
"chars": "€پ‚ƒ„...†‡ˆ‰ٹ‹Œچژڈگ‘’“”•–—کTMڑ›œں ،¢£¤¥¦§ ̈©ھ«¬® ̄°±23 ́μ¶· ̧1؛»1⁄41⁄23⁄4؟ہءآأؤإئابةتثجحخدذرزسشصض×طظعغـفقكàلâمنهوçèéêëىيîïًٌٍَôُِ÷ّùْûüے"
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
node_modules/iconv-lite/encodings/sbcs-data-generated.js:373
"chars": "«»...“”�•‘’� กขฃคฅฆงจฉชซฌญฎฏฐฑฒณดตถทธนบปผฝพฟภมยรฤลฦวศษสหฬอฮฯะัาําิีึืฺุู–—฿เแโใไๅๆ็่้๊๋์ํTM๏๐๑๒๓๔๕๖๗๘๙®©����"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
remove_tester_from_group
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius

Gates applied: no_behavioural_pass.

Audited 2026-10-03 · audit v0.4.1 · source sha 14e830b9eb58full audit observations/trust-audit/mcp-server/joshuarileydev__app-store-connect.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0314e830b9eb58BLOCKF29first audit
06

Questions

What tools does App Store Connect expose?

27 in total: 19 read-only, 7 that write, and 1 that can delete or overwrite (remove_tester_from_group). Every one is listed on this page with its risk.

Is App Store Connect safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (29/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does App Store Connect need?

It reads APP_STORE_CONNECT_KEY_ID from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does App Store Connect run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as appstore-connect-mcp-server at 1.1.2.

How current is this page?

The grade is for one exact copy of the source (14e830b9eb58), read on 2026-10-03. The repository is watched and re-audited when it changes.

Advertisement