PhonePiBLOCK
PhonePi MCP enables seamless integration between desktop AI tools and your smartphone, providing 23+ direct actions including SMS messaging, phone calls, contact management, snippet creation and search, clipboard sharing, notifications, battery status checks, and remote device controls.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A powerful MCP server and companion app that allows you to manage and control your phone remotely using natural language commands via your favorite MCP-supported AI apps such as Cursor and Claude Desktop. This project provides a comprehensive set of tools and APIs to interact with your mobile device programmatically.
Overview
Phone MCP enables you to:
- Manage contacts and messages
- Handle snippets and notes
- Control phone settings and notifications
- Prepare SMS messages for confirmation on your phone and make calls
- Share content across apps
- Monitor battery status
- Set timers and reminders
- Find your phone with audio alerts
Security
Security is a high concern. Here are a few aspects taken into account around security:
- You are completely in charge around hosting the MCP server locally. The code is completely open source.
- On the app front, you are in charge of what permissions to give depending on the features you want to use.
- The app and the server are linked over your local network. There's no 3p remote servers involved in linking.
- It is highly recommended you use this app over a secure network. Avoid public networks like airports and restaurants.
- Tailscale is highly recommended for creating a private & secure VPN to connect your phone and desktops
Getting Started
For detailed documentation, features, and setup instructions, please visit: phonepimcp.com
Support & Issues
If you encounter any bugs or have feature requests, please open an issue on our GitHub repository.
Background connections (Android app 1.0.1 and later)
Connect to your desktop server, then enable Background Service while PhonePi MCP is open. Android displays a persistent notification while the service keeps the same connection and tool handlers active. The app retries after network ch
c103624ee685OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add phonepi-mcp --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"phonepi-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}"
}
}
}
}Exposed tools (22)
12 read · 8 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_contact | write | Add a new contact to the phone |
add_snippet | write | Add a new snippet to the phone |
copy_to_clipboard | read | Copy text to the phone clipboard |
delete_contact | destructive | Delete a contact from the phone |
delete_snippet | destructive | Delete a snippet from the phone |
find_phone | read | Make the phone beep to help locate it |
get_all_snippets | read | Get all snippets from the phone |
get_battery_level | read | Get the current battery level of the phone |
get_contact_by_id | read | Get a specific contact by ID |
get_contacts | read | Get all contacts from the phone |
get_message_response | read | Get the response to a previously sent message |
get_snippet_by_id | read | Get a specific snippet by ID |
get_snippets_by_type | read | Get snippets by type |
make_call | read | Make a phone call |
search_snippets | read | Search snippets by query |
send_message | write | Send a message to the phone that requires user attention or response |
send_notification | write | Send a notification to the phone |
send_sms | write | Prepare an SMS message on the phone. Current store apps open the SMS composer and require the user to confirm sending; keep the phone app open. |
set_timer | write | Set a timer for a specific duration |
share_snippet | read | Share a snippet via messaging apps |
update_contact | write | Update an existing contact |
update_snippet | write | Update an existing snippet |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
exec(cmd, (error) => {delete_contact, delete_snippet
@anthropic-ai/sdk, @modelcontextprotocol/sdk, chalk, commander, dotenv, inquirer, @types/inquirer, @types/node
@modelcontextprotocol/sdk, ws, typescript, commander, @types/ws, ts-node, nodemon, @types/node
Gates applied: no_behavioural_pass.
c103624ee685full audit observations/trust-audit/mcp-server/priyankark__phonepi.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | c103624ee685 | BLOCK | D | 69 | first audit |
Questions
What is the PhonePi MCP server?
PhonePi MCP enables seamless integration between desktop AI tools and your smartphone, providing 23+ direct actions including SMS messaging, phone calls, contact management, snippet creation and search, clipboard sharing, notifications, battery status checks, and remote device controls.
What tools does PhonePi expose?
22 in total: 12 read-only, 8 that write, and 2 that can delete or overwrite (delete_contact, delete_snippet). Every one is listed on this page with its risk.
Is PhonePi safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does PhonePi need?
It reads ANTHROPIC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does PhonePi run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as phonepi-mcp at 1.0.30.
How current is this page?
The grade is for one exact copy of the source (c103624ee685), read on 2026-10-08. The repository is watched and re-audited when it changes.