Atlas / MCP servers / oozoofrog / Baepsae

BaepsaeSAFE

mcp/oozoofrog/baepsae

MCP server with direct iOS simulator implementation

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
47 35r · 9w · 3d
Transport
stdio
License
MIT
Stars
26
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Baepsae (Vinous-throated Parrotbill) — A tiny Korean bird. Round, chubby, and constantly hopping around chirping. Known for its grit — even when a little bird tries to keep up with a stork, it never gives up. This project is small too, but it pecks away at your simulators tirelessly.

Local MCP server for iOS Simulator and macOS app automation with a TypeScript MCP layer and a Swift native bridge.

한국어 문서는 README-KR.md를 참고하세요.

Table of Contents

  • Prerequisites
  • Platform Support
  • Install
  • Permissions
  • MCP Setup (Recommended)
  • Client Matrix
  • For LLM
  • Manual Setup (Fallback)
  • Project Structure
  • Commands
  • MCP Tool Status
  • Usage Examples
  • Troubleshooting

Prerequisites

  • macOS 14+
  • Xcode + iOS Simulator
  • Node.js 18+
  • Swift 6+

Platform Support

Why macOS only?

The Swift native bridge (baepsae-native) uses macOS-specific frameworks (AppKit, CoreGraphics, Accessibility) to interact with iOS Simulator and macOS applications. These frameworks are not available on Linux or Windows. The TypeScript MCP layer also relies on xcrun simctl, which is part of Xcode Command Line Tools and only available on macOS.

Requirements summary:

  • macOS 14 or later -- required for iOS Simulator automation and Accessibility API access.
  • *Xcode or Xcode Command Line Tools
Read from source at commit e720af12dc7fOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add mcp-baepsae -- npx -y [email protected]
03

Exposed tools (47)

35 read · 9 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
activate_appreadBring the target app to foreground.
analyze_uireadDescribe app UI hierarchy. Works with both simulator (udid) and macOS (bundleId/appName) targets.
baepsae_helpreadShow help. Optionally pass subcommand name for compatibility reference.
baepsae_versionreadShow server and native binary versions.
buttonreadPress a simulator hardware button.
clipboardwriteRead or write the system clipboard.
context_menu_actionreadSelect an item from an open context menu. Call after right_click. Supports submenu paths with > separator (e.g.
detect_dialogreadDetect if a modal dialog, sheet, or alert is currently presented. Returns JSON with hasDialog, type, title, isModal, and buttons.
doctorwriteRun readiness self-checks for host process, parent process, native binary, booted simulator availability, and accessibility permission.
drag_dropdestructiveDrag and drop in the target app.
enumerate_uireadDiscover all attributes, actions, and parameterized attributes of a UI element. Shows which attributes are settable.
focus_windowreadRaise and focus a specific window by index or title. macOS apps only.
gesturewriteExecute a preset gesture pattern.
get_focused_appreadGet information about the currently focused macOS app.
hit_testreadFind which UI element is at specific screen coordinates. Uses system-wide accessibility hit testing. No app target needed.
input_sourcereadGet current keyboard input source or switch to a specific one. Call without sourceId to query current; with sourceId to switch. Uses CJKV workaround for Korean/Japanese/Chinese/Vietnamese.
install_appwriteInstall an app (.app, .ipa) on the simulator.
keyreadPress a single HID keycode in the target app.
key_comboreadPress key combo in the target app.
key_sequencereadPress multiple HID keycodes in sequence in the target app.
launch_appreadLaunch an installed app on the simulator.
list_appsreadList running macOS applications with their bundle IDs.
list_input_sourcesreadList all available keyboard input sources with their IDs, names, and active status.
list_simulatorsreadList available simulators using simctl.
list_windowsreadList windows in the target app.
menu_actionwriteExecute a menu bar action in a macOS app.
open_urlreadOpen a URL in the simulator (e.g. Safari or deep link).
query_uireadSearch app UI elements by text, identifier, or label. Works with both simulator and macOS targets.
read_ui_paramreadRead parameterized accessibility attributes like text ranges, line numbers, and bounds.
read_ui_valuereadRead value, selected text, or insertion point of a UI element via Accessibility API.
record_videoreadRecord simulator display directly with simctl recordVideo.
right_clickwriteRight-click in the target app. Selector lookup defaults to in-app content; set all=true for Simulator chrome UI.
run_stepswriteExecute ordered workflow steps using existing tap, type_text, key, swipe, and sleep behavior. Defaults to fail-fast; set continueOnError or continue_on_error to keep going after a failure.
screenshotreadCapture a screenshot from simulator display using simctl screenshot.
screenshot_appreadTake a screenshot of the target app window.
scrollwriteSend scroll wheel events to the target app.
set_ui_valuewriteSet value, text selection range, or focus on a UI element via Accessibility API.
stream_videoreadCapture a time-bounded simulator clip through the native stream-video shim.
swipereadPerform swipe gesture in the target app.
tapreadTap coordinates or accessibility element. Selector lookup defaults to in-app content; set all=true to include Simulator chrome UI.
tap_tabreadTap a tab in a tab bar by index. Prefers semantic descendants or top-row semantic proxy buttons when available, and falls back to geometry only when needed. Useful for SwiftUI TabView cases where tab buttons are not cleanly exposed.
terminate_appdestructiveTerminate a running app on the simulator.
touchreadPerform touch events in the target app.
type_textreadType text into the target app. auto resolves to paste for all targets (more reliable for CJK and emoji); simulator paste uses the simulator pasteboard, macOS paste temporarily uses the host clipboard; keyboard types character-by-character.
uninstall_appdestructiveUninstall an app from the simulator.
wait_for_uireadWait for a UI element to appear or disappear. Polls query_ui at interval until condition met or timeout.
watch_notificationreadWatch for AX notifications from an app. Blocks until a notification fires or timeout. Use presets for common patterns: window (created/destroyed), text (value/selection changed), focus (app/window focus), menu (opened/closed).
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
drag_drop, terminate_app, uninstall_app
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod, @types/node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha e720af12dc7ffull audit observations/trust-audit/mcp-server/oozoofrog__baepsae.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09e720af12dc7fSAFEB89first audit
06

Questions

What is the Baepsae MCP server?

MCP server with direct iOS simulator implementation

What tools does Baepsae expose?

47 in total: 35 read-only, 9 that write, and 3 that can delete or overwrite (drag_drop, terminate_app, uninstall_app). Every one is listed on this page with its risk.

Is Baepsae safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Baepsae need?

No credential environment variables were found in its source, so it appears to need none.

How does Baepsae run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-baepsae at 6.3.0.

How current is this page?

The grade is for one exact copy of the source (e720af12dc7f), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement