BaepsaeSAFE
MCP server with direct iOS simulator implementation
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Baepsae (Vinous-throated Parrotbill) — A tiny Korean bird. Round, chubby, and constantly hopping around chirping. Known for its grit — even when a little bird tries to keep up with a stork, it never gives up. This project is small too, but it pecks away at your simulators tirelessly.
Local MCP server for iOS Simulator and macOS app automation with a TypeScript MCP layer and a Swift native bridge.
한국어 문서는 README-KR.md를 참고하세요.
Table of Contents
- Prerequisites
- Platform Support
- Install
- Permissions
- MCP Setup (Recommended)
- Client Matrix
- For LLM
- Manual Setup (Fallback)
- Project Structure
- Commands
- MCP Tool Status
- Usage Examples
- Troubleshooting
Prerequisites
- macOS 14+
- Xcode + iOS Simulator
- Node.js 18+
- Swift 6+
Platform Support
Why macOS only?
The Swift native bridge (baepsae-native) uses macOS-specific frameworks (AppKit, CoreGraphics, Accessibility) to interact with iOS Simulator and macOS applications. These frameworks are not available on Linux or Windows. The TypeScript MCP layer also relies on xcrun simctl, which is part of Xcode Command Line Tools and only available on macOS.
Requirements summary:
- macOS 14 or later -- required for iOS Simulator automation and Accessibility API access.
- *Xcode or Xcode Command Line Tools
e720af12dc7fOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-baepsae -- npx -y [email protected]
Exposed tools (47)
35 read · 9 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
activate_app | read | Bring the target app to foreground. |
analyze_ui | read | Describe app UI hierarchy. Works with both simulator (udid) and macOS (bundleId/appName) targets. |
baepsae_help | read | Show help. Optionally pass subcommand name for compatibility reference. |
baepsae_version | read | Show server and native binary versions. |
button | read | Press a simulator hardware button. |
clipboard | write | Read or write the system clipboard. |
context_menu_action | read | Select an item from an open context menu. Call after right_click. Supports submenu paths with > separator (e.g. |
detect_dialog | read | Detect if a modal dialog, sheet, or alert is currently presented. Returns JSON with hasDialog, type, title, isModal, and buttons. |
doctor | write | Run readiness self-checks for host process, parent process, native binary, booted simulator availability, and accessibility permission. |
drag_drop | destructive | Drag and drop in the target app. |
enumerate_ui | read | Discover all attributes, actions, and parameterized attributes of a UI element. Shows which attributes are settable. |
focus_window | read | Raise and focus a specific window by index or title. macOS apps only. |
gesture | write | Execute a preset gesture pattern. |
get_focused_app | read | Get information about the currently focused macOS app. |
hit_test | read | Find which UI element is at specific screen coordinates. Uses system-wide accessibility hit testing. No app target needed. |
input_source | read | Get current keyboard input source or switch to a specific one. Call without sourceId to query current; with sourceId to switch. Uses CJKV workaround for Korean/Japanese/Chinese/Vietnamese. |
install_app | write | Install an app (.app, .ipa) on the simulator. |
key | read | Press a single HID keycode in the target app. |
key_combo | read | Press key combo in the target app. |
key_sequence | read | Press multiple HID keycodes in sequence in the target app. |
launch_app | read | Launch an installed app on the simulator. |
list_apps | read | List running macOS applications with their bundle IDs. |
list_input_sources | read | List all available keyboard input sources with their IDs, names, and active status. |
list_simulators | read | List available simulators using simctl. |
list_windows | read | List windows in the target app. |
menu_action | write | Execute a menu bar action in a macOS app. |
open_url | read | Open a URL in the simulator (e.g. Safari or deep link). |
query_ui | read | Search app UI elements by text, identifier, or label. Works with both simulator and macOS targets. |
read_ui_param | read | Read parameterized accessibility attributes like text ranges, line numbers, and bounds. |
read_ui_value | read | Read value, selected text, or insertion point of a UI element via Accessibility API. |
record_video | read | Record simulator display directly with simctl recordVideo. |
right_click | write | Right-click in the target app. Selector lookup defaults to in-app content; set all=true for Simulator chrome UI. |
run_steps | write | Execute ordered workflow steps using existing tap, type_text, key, swipe, and sleep behavior. Defaults to fail-fast; set continueOnError or continue_on_error to keep going after a failure. |
screenshot | read | Capture a screenshot from simulator display using simctl screenshot. |
screenshot_app | read | Take a screenshot of the target app window. |
scroll | write | Send scroll wheel events to the target app. |
set_ui_value | write | Set value, text selection range, or focus on a UI element via Accessibility API. |
stream_video | read | Capture a time-bounded simulator clip through the native stream-video shim. |
swipe | read | Perform swipe gesture in the target app. |
tap | read | Tap coordinates or accessibility element. Selector lookup defaults to in-app content; set all=true to include Simulator chrome UI. |
tap_tab | read | Tap a tab in a tab bar by index. Prefers semantic descendants or top-row semantic proxy buttons when available, and falls back to geometry only when needed. Useful for SwiftUI TabView cases where tab buttons are not cleanly exposed. |
terminate_app | destructive | Terminate a running app on the simulator. |
touch | read | Perform touch events in the target app. |
type_text | read | Type text into the target app. auto resolves to paste for all targets (more reliable for CJK and emoji); simulator paste uses the simulator pasteboard, macOS paste temporarily uses the host clipboard; keyboard types character-by-character. |
uninstall_app | destructive | Uninstall an app from the simulator. |
wait_for_ui | read | Wait for a UI element to appear or disappear. Polls query_ui at interval until condition met or timeout. |
watch_notification | read | Watch for AX notifications from an app. Blocks until a notification fires or timeout. Use presets for common patterns: window (created/destroyed), text (value/selection changed), focus (app/window focus), menu (opened/closed). |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
drag_drop, terminate_app, uninstall_app
@modelcontextprotocol/sdk, zod, @types/node, typescript
Gates applied: no_behavioural_pass.
e720af12dc7ffull audit observations/trust-audit/mcp-server/oozoofrog__baepsae.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | e720af12dc7f | SAFE | B | 89 | first audit |
Questions
What is the Baepsae MCP server?
MCP server with direct iOS simulator implementation
What tools does Baepsae expose?
47 in total: 35 read-only, 9 that write, and 3 that can delete or overwrite (drag_drop, terminate_app, uninstall_app). Every one is listed on this page with its risk.
Is Baepsae safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Baepsae need?
No credential environment variables were found in its source, so it appears to need none.
How does Baepsae run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-baepsae at 6.3.0.
How current is this page?
The grade is for one exact copy of the source (e720af12dc7f), read on 2026-10-09. The repository is watched and re-audited when it changes.