Atlas / MCP servers / martingeidobler / Android

AndroidSAFE

mcp/martingeidobler/android-3

MCP server for controlling Android emulators via ADB — screenshots, UI interaction, logcat, and bug documentation for Claude Code

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
25 20r · 4w · 1d
Transport
stdio
License
MIT
Stars
70
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/android-mcp-server) [](https://www.npmjs.com/package/android-mcp-server) [](https://opensource.org/licenses/MIT) [](https://glama.ai/mcp/servers/martingeidobler/android-mcp-server) [](https://github.com/punkpeye/awesome-mcp-servers) [](https://socket.dev/npm/package/android-mcp-server)

MCP server for controlling Android emulators and devices via ADB. Gives AI assistants the ability to see, interact with, and debug Android apps — taking screenshots, tapping elements, reading logs, and documenting bugs.

npm Package | GitHub | Issues

^ Sped up for better viewing. More demos and test cases.

Features

  • 25 tools for complete Android device control
  • Screenshot capture with intelligent compression (Sharp-based, max 1280px)
  • UI tree inspection — read element hierarchy with bounds, text, resource IDs, and state
  • Touch automation — tap, swipe, scroll, type text, press hardware keys
  • Element targeting — find and tap elements by resource-id, text, or content-desc
  • App lifecycle — install APKs, launch apps, inspect current activity
Read from source at commit 08fc9c89f790OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add android-mcp-server -- npx -y [email protected]
03

Exposed tools (25)

20 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
adb_shellwriteRun an arbitrary ADB shell command
clear_logsdestructiveClear the logcat buffer. Call this before reproducing a bug to get clean logs.
double_tapreadDouble tap at screen coordinates. Useful for zoom-in gestures and double-tap interactions.
get_current_activityreadGet the currently displayed app and activity
get_device_inforeadGet device details: model, manufacturer, Android version, API level, screen size, and DPI.
get_logsreadGet device logcat output. Use to find crashes, exceptions, and errors after reproducing a bug.
get_ui_treereadGet the UI element hierarchy of the current screen. Returns interactive elements with their bounds, text, resource IDs, and state. Use this to find elements before tapping.
install_apkwriteInstall an APK file on the device
launch_appreadLaunch an Android app by package name
list_avdsreadList available Android Virtual Devices
list_devicesreadList connected Android devices and emulators
long_pressreadLong press at screen coordinates. Useful for context menus, drag handles, and press-and-hold interactions.
multi_tapreadTap at the same coordinates multiple times with a fixed interval. Use for spam-tapping, incrementing counters, or testing rapid repeat actions.
press_keyreadPress a hardware/software key
pull_filereadPull a file from the Android device to the local filesystem.
screenshotreadTake a screenshot of the Android device. Returns the image for visual analysis. Optionally saves to a file path.
scroll_to_elementreadScroll down repeatedly until an element matching the given criteria is visible
start_emulatorwriteStart an Android emulator. Waits up to 60s for it to come online.
swipereadPerform a swipe gesture on the screen
tapreadTap at specific screen coordinates
tap_and_waitreadTap element then wait for UI to settle and return the new UI tree. Combines tap + wait + get_ui_tree into a single fast operation.
tap_elementreadTap a UI element by its resource-id, text, or content-desc. Finds the element in the UI tree and taps its center.
tap_sequencewriteExecute a multi-step action sequence. Supports taps, waits, text input, key presses, and swipes in any order.
type_textreadType text into the currently focused input field
wait_for_elementreadWait for a UI element to appear on screen. Polls every 500ms.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_logs
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, sharp, zod, @types/node, eslint, typescript, typescript-eslint, vitest
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 08fc9c89f790full audit observations/trust-audit/mcp-server/martingeidobler__android-3.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0808fc9c89f790SAFEB89first audit
06

Questions

What is the Android MCP server?

MCP server for controlling Android emulators via ADB — screenshots, UI interaction, logcat, and bug documentation for Claude Code

What tools does Android expose?

25 in total: 20 read-only, 4 that write, and 1 that can delete or overwrite (clear_logs). Every one is listed on this page with its risk.

Is Android safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Android need?

No credential environment variables were found in its source, so it appears to need none.

How does Android run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as android-mcp-server at 1.3.0.

How current is this page?

The grade is for one exact copy of the source (08fc9c89f790), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement