Atlas / MCP servers / minhalvp / Android Control

Android ControlSAFE

mcp/minhalvp/android-control

An MCP server that provides control over Android devices via adb

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
5 4r · 1w · 0d
Transport
stdio
License
Apache-2.0
Stars
811
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP (Model Context Protocol) server that provides programmatic control over Android devices through ADB (Android Debug Bridge). This server exposes various Android device management capabilities that can be accessed by MCP clients like Claude desktop and Code editors (e.g. Cursor)

Features

  • 🔧 ADB Command Execution
  • 📸 Device Screenshot Capture
  • 🎯 UI Layout Analysis
  • 📱 Device Package Management

Prerequisites

  • Python 3.x
  • ADB (Android Debug Bridge) installed and configured
  • Android device or emulator (not tested)

Installation

  1. Clone the repository:
git clone https://github.com/minhalvp/android-mcp-server.git
cd android-mcp-server
  1. Install dependencies:

This project uses uv for project management via various methods of installation.

uv python install 3.11
uv sync

Configuration

The server supports flexible device configuration with multiple usage scenarios.

Device Selection Modes

1. Automatic Selection (Recommended for single device)

  • No configuration file needed
  • Automatically connects to the only connected device
  • Perfect for development with a single test device

2. Manual Device Selection

  • Use when you have multiple devices connected
  • Specify exact device in configuration file

Configuration File (Optional)

The configuration file (config.yaml) is optional. If not present, the server will automatically select the device if only one is connected.

For Automatic Selection

Simply ensure only one device is connected and run the server - no configuration needed!

For Manual Selection

  1. Create a configuration file:
cp config.yaml.example config.yaml
  1. Edit config.yaml and specify your device:
device:
name: "your-device-se
Read from source at commit 548a27bd4123OBSERVED · 2026-09-27
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add android-mcp -- uvx android-mcp
claude-desktop
{
  "mcpServers": {
    "android-mcp": {
      "command": "uvx",
      "args": [
        "android-mcp"
      ]
    }
  }
}
03

Exposed tools (5)

4 read · 1 write · 0 destructive.

ToolRiskDescription
execute_adb_shell_commandwriteExecutes an ADB command and returns the output or an error.
get_package_action_intentsread
get_packagesread
get_screenshotreadTakes a screenshot of the device and returns it.
get_uilayoutread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-09-27 · audit v0.4.1 · source sha 548a27bd4123full audit observations/trust-audit/mcp-server/minhalvp__android-control.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-27548a27bd4123SAFEB89first audit
06

Questions

What is the Android Control MCP server?

An MCP server that provides control over Android devices via adb

What tools does Android Control expose?

5 in total: 4 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Android Control safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Android Control need?

No credential environment variables were found in its source, so it appears to need none.

How does Android Control run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as android-mcp.

How current is this page?

The grade is for one exact copy of the source (548a27bd4123), read on 2026-09-27. The repository is watched and re-audited when it changes.

Advertisement