Atlas / MCP servers / mobai-app / MobAI

MobAICAUTION

mcp/mobai-app/mobai

AI-powered mobile device automation for Android and iOS devices, emulators, and simulators

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
19 8r · 8w · 3d
Transport
stdio
License
Apache-2.0
Stars
251
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/mobai-mcp) [](https://opensource.org/license/Apache-2.0)

MCP (Model Context Protocol) server for MobAI — AI-powered mobile device automation. Lets AI assistants (Claude Code, Cursor, Windsurf, Cline, and other MCP-compatible tools) control Android and iOS devices, emulators, and simulators via a single DSL-first interface.

How it works

All device interaction is batched through one primary tool: `execute_dsl`. Instead of exposing dozens of fine-grained tools (tap, swipe, type...), the server accepts a JSON script describing a sequence of actions with predicates, assertions, waits, and conditional branches. This keeps round-trips low and encodes retry/failure strategies server-side.

A small set of companion tools handles device discovery, screenshots, app management, and running .mob test files.

Prerequisites

  • Node.js 18+
  • MobAI desktop app running locally (HTTP API on 127.0.0.1:8686)
  • A connected Android or iOS device, emulator, or simulator

Installation

Claude Code

claude mcp add mobai -- npx -y mobai-mcp

Cursor

Add to .cursor/mcp.json:

{
"mcpServers": {
"mobai": {
"command": "npx",
"args": ["-y", "mobai-mcp"]
}
}
}

Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS):

{
"mcpServers": {
"mobai": {
"command": "npx",
"args": ["-y", "mobai-mcp"]
}
}
}

Windsurf / Cline / other MCP clients

The server speaks stdio — use your client's generic MCP configuration:

{
"command": "npx",
"args": ["-y", "mobai-mcp"]
}

Tools

Device management

Read from source at commit 03d11d104ff3OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add mobai-mcp -- npx -y [email protected]
03

Exposed tools (19)

8 read · 8 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
debug_appwriteLaunch an app in debug mode and write logs to a file. Returns the log file path — use Read/Grep to inspect logs. Use kill_app to stop.
debug_attachwriteStart a debug session for an iOS app. Provide either bundle_id (launches and attaches) or pid (attaches to a running process). Optional breakpoints[] are armed before the target resumes. Read mobai://reference/debugging first.
debug_breakpointdestructiveAdd or remove a breakpoint in the active debug session. For action=add provide spec; for action=remove provide id.
debug_detachdestructiveEnd the debug session. Pass kill=true to terminate the debuggee; otherwise it keeps running.
debug_evalreadEvaluate a Swift/ObjC expression at the current pause. Session must be paused. Examples:
debug_statewriteQuery the current debug session. Returns {state, breakpoints} by default. Set include_stack=true to also fetch the stack of the stopped thread; include_vars=true to also fetch frame[0] locals; include_threads=true to enumerate all threads.
debug_stepreadAdvance the target.\n
get_devicereadGet details about a specific device
install_appwriteInstall an app on the device from a local file path (.apk for Android, .ipa for iOS). For cloud devices nothing is installed directly: the build is uploaded to the provider
list_appsreadList installed apps on the device
list_devicesreadList all connected Android and iOS devices. Devices with
release_devicereadRelease device lease(s) held by this session. With device_id, releases that device
save_screenshotwriteSave a full-quality PNG screenshot to disk. Use this when you need a high-quality image for reporting, debugging, or sharing — not for LLM processing (use get_screenshot instead).
start_bridgewriteStart the automation bridge on a device. Required before interacting with the device. For cloud devices this allocates the provider session; pass \
stop_bridgewriteStop the automation bridge on a device
test_get_activereadGet the currently active test project directory and its .mob test cases. Use this to discover the project path and available tests. The agent can then read/write/create/delete .mob files directly in the returned directory.
test_list_projectsreadList all known test project directories with their .mob test cases. Each project is a directory containing .mob script files.
test_runwriteRun a .mob test case on a device. The case_path is relative to the project directory. Pass params to supply values for ${name} substitution in the script.
uninstall_appdestructiveUninstall an app from the device
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/index.ts:23
const API_BASE_URL = "http://127.0.0.1:8686/api/v1";
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
debug_breakpoint, debug_detach, uninstall_app
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:145
**"Connection refused" / "Could not reach the MobAI desktop app"** — Make sure the MobAI desktop app is installed and running, and the API is reachable at `http://127.0.0.1:8686`. If you don't have it
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/node, typescript
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
README.md:145
**"Connection refused" / "Could not reach the MobAI desktop app"** — Make sure the MobAI desktop app is installed and running, and the API is reachable at `http://127.0.0.1:8686`. If you don't have it
Why it matters. remote text is to be obeyed as instructions

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 03d11d104ff3full audit observations/trust-audit/mcp-server/mobai-app__mobai.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0603d11d104ff3CAUTIONB89first audit
06

Questions

What is the MobAI MCP server?

AI-powered mobile device automation for Android and iOS devices, emulators, and simulators

What tools does MobAI expose?

19 in total: 8 read-only, 8 that write, and 3 that can delete or overwrite (debug_breakpoint, debug_detach, uninstall_app). Every one is listed on this page with its risk.

Is MobAI safe to connect to an agent?

With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does MobAI need?

No credential environment variables were found in its source, so it appears to need none.

How does MobAI run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mobai-mcp at 2.8.0.

How current is this page?

The grade is for one exact copy of the source (03d11d104ff3), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement