Atlas / MCP servers / r-huijts / Xcode

XcodeBLOCK

mcp/r-huijts/xcode-1

MCP Server implementation for Xcode integration

Verdict
BLOCK
Grade
D
Trust score
61 /100
Exposed tools
76 51r · 21w · 4d
Transport
stdio
License
MIT
Stars
384
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/r-huijts-xcode-mcp-server)

An MCP (Model Context Protocol) server providing comprehensive Xcode integration for AI assistants. This server enables AI agents to interact with Xcode projects, manage iOS simulators, and perform various Xcode-related tasks with enhanced error handling and support for multiple project types.

Features

Project Management

  • Set active projects and get detailed project information
  • Create new Xcode projects from templates (iOS, macOS, watchOS, tvOS)
  • Add files to Xcode projects with target and group specification
  • Parse workspace documents to find associated projects
  • List available schemes in projects and workspaces

File Operations

  • Read/write files with support for different encodings
  • Handle binary files with base64 encoding/decoding
  • Search for text content within files using patterns and regex
  • Check file existence and get file metadata
  • Create directory structures automatically

Build & Testing

  • Build projects with customizable options
  • Run tests with detailed failure reporting
  • Analyze code for potential issues
  • Clean build directories
  • Archive projects for distribution

CocoaPods Integration

  • Initialize CocoaPods in projects
  • Install and update pods
  • Add and remove pod dependencies
  • Execute arbitrary pod commands

Swift Package Manager

  • Initialize new Swift packages
  • Add and remove package dependencies with various version requirements
  • Update packages and resolve dependencies
  • Generate documentation for Swift packages using DocC
  • Run tests and build Swift packages

iOS Simulator Tools

  • List available simulators with detailed information
  • Boot and shut down simulators
  • Install and launch apps on simulators
  • Take screenshots and record videos
  • Manage simulator settings and state

Xcode Utilities

  • Execute Xcode commands via xcrun
  • Comp
Read from source at commit 6c022dd495b1OBSERVED · 2026-10-02
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add xcode-mcp-server -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "xcode-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (76)

51 read · 21 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_file_to_projectwriteAdds a file to the active Xcode project.
add_project_to_workspacewriteAdds an existing project to the active workspace.
add_swift_packagewriteAdds a Swift Package dependency to the active project. Note: Your project must already be set up for Swift Package Manager (must have a Package.swift file). If you haven
analyze_filereadAnalyzes a source file for potential issues using Xcode
archive_projectreadArchives the active Xcode project for distribution.
boot_simulatorreadBoot an iOS simulator by UDID or name
build_projectreadBuilds the active Xcode project using the specified configuration and scheme.
build_spm_packagereadBuilds a Swift Package Manager package directly using
build_swift_packagereadBuilds a Swift Package using Swift Package Manager.
change_directoryreadChanges the active directory for relative path operations.
check_cocoapodsreadChecks if the active project uses CocoaPods and returns setup information.
check_file_existsreadChecks if a file or directory exists at the specified path.
clean_projectreadCleans the build directory for the active Xcode project.
clean_swift_packagereadCleans the build artifacts of a Swift Package.
compile_asset_catalogreadCompiles an asset catalog (.xcassets) using actool
copy_filereadCopies a file or directory to a new location within allowed directories.
create_directorywriteCreates a new directory within allowed directories.
create_workspacewriteCreates a new Xcode workspace and optionally adds existing projects to it.
create_xcode_projectwriteCreates a new Xcode project using a template.
delete_filedestructiveDeletes a file or directory within allowed directories.
detect_active_projectreadAttempts to automatically detect the active Xcode project.
dump_swift_packagereadDumps the Package.swift manifest as JSON.
edit_package_swiftwriteDirectly edit the Package.swift file of the active SPM project. This is useful for making changes that aren
export_archivereadExport an Xcode archive for distribution (App Store, Ad Hoc, Enterprise, Development)
find_filesreadSearches for files matching a pattern in a directory.
find_projectsreadFinds Xcode projects in the specified directory.
generate_icon_setwriteGenerate an app icon set from a source image
generate_swift_docsreadGenerates documentation for a Swift Package using DocC.
get_active_projectreadRetrieves detailed information about the currently active Xcode project.
get_current_directoryreadReturns the current active directory.
get_file_inforeadGets detailed information about a file or directory.
get_package_inforeadGets detailed information about a Swift Package Manager package.
get_project_configurationreadRetrieves configuration details for the active project, including schemes and targets.
get_xcode_inforeadGet information about Xcode installations on the system
init_swift_packagereadInitializes a new Swift Package Manager project in the current directory. Use this tool first if your project doesn
install_appwriteInstall an app on a simulator
launch_appreadLaunch an installed app on a simulator
list_available_destinationsreadLists available build destinations for the active Xcode project or workspace.
list_available_schemesreadLists all available schemes in the active Xcode project or workspace.
list_booted_simulatorsreadList all currently booted iOS simulators
list_directoryreadLists the contents of a directory, showing both files and subdirectories.
list_installed_appsreadList all installed applications on a simulator
list_project_filesreadLists all files within an Xcode project.
list_simulatorsreadList all available iOS simulators with filtering options
move_filewriteMoves a file or directory to a new location within allowed directories.
open_urlreadOpen a URL in a simulator
pod_deintegratereadDeintegrate CocoaPods from the active project, removing all traces of CocoaPods.
pod_initreadGenerate a Podfile for the current project directory.
pod_installwriteRuns
pod_outdatedreadShows outdated pods in the current project and their available updates.
pod_repo_updatewriteUpdates the local clone of the CocoaPods spec repositories.
pod_updatewriteRuns
pop_directoryreadPops a directory from the stack and changes to it.
push_directorywritePushes the current directory onto a stack and changes to a new directory.
read_filereadReads the contents of a file within the active project or allowed directories.
remove_swift_packagedestructiveRemoves a Swift Package dependency from the active project.
reset_simulatordestructiveReset a simulator by erasing all content and settings
resolve_pathreadResolves a path, taking into account the active directory and current project.
run_lldbwriteLaunches the LLDB debugger with optional arguments
run_testswriteExecutes tests for the active Xcode project.
run_xcrunwriteExecutes a specified Xcode tool via xcrun
search_in_filesreadSearches for text content within files in a directory.
set_project_pathwriteSets the active Xcode project by specifying the path to its .xcodeproj directory.
set_projects_base_dirwriteSets the base directory where your Xcode projects are stored.
show_swift_dependenciesreadShows the resolved dependencies of a Swift Package.
shutdown_simulatorreadShutdown a simulator by UDID, or shutdown all running simulators
swift_package_commandreadExecutes Swift Package Manager commands in the active project directory.
switch_xcodereadSwitch the active Xcode version
take_screenshotreadTake a screenshot of a simulator
terminate_appdestructiveTerminate a running app on a simulator
test_spm_packagereadRuns tests for a Swift Package Manager package directly using
test_swift_packagereadTests a Swift Package using Swift Package Manager.
trace_appreadCaptures a performance trace of an application using xctrace
update_swift_packagewriteUpdates the dependencies of your Swift project using Swift Package Manager.
validate_appreadValidate an app for App Store submission using altool
write_filewriteWrites or updates the content of a file within the active project or allowed directories.
04

Trust audit

BLOCKgrade D · trust 61/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)WARN
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (8 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (13)

HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
setup.sh:72
echo -e "    ${YELLOW}sudo gem install cocoapods${NC}"
Why it matters. asks for elevated privileges
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
setup.sh:80
sudo gem install cocoapods || { echo -e "${RED}Failed to install CocoaPods.${NC}"; exit 1; }
Why it matters. asks for elevated privileges
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
setup.sh:93
echo -e "    ${YELLOW}sudo gem pristine ffi --version 1.15.5${NC}"
Why it matters. asks for elevated privileges
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
setup.sh:97
sudo gem pristine ffi --version 1.15.5 || { echo -e "${YELLOW}Failed to fix ffi gem. You may need to run the command manually.${NC}"; }
Why it matters. asks for elevated privileges
HIGHPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
src/tools/cocoapods/index.ts:93
`   sudo gem install cocoapods\n\n` +
Why it matters. asks for elevated privileges
MEDIUMPrompt injection · scope.undeclared_system · CWE-94, CWE-1427
<declared scope>
system use found in code, not declared in the description
Why it matters. the description does not admit a capability the code has
Fix. declare system use in the description, or remove it
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_file, remove_swift_package, reset_simulator, terminate_app
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/build/index.ts:4
import { XcodeServer } from "../../server.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/build/index.ts:5
import { ProjectNotFoundError, XcodeServerError, CommandExecutionError, PathAccessError } from "../../utils/errors.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/build/index.ts:6
import { getProjectInfo, getWorkspaceInfo } from "../../utils/project.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/build/index.ts:7
import { runExecFile } from "../../utils/execFile.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/cocoapods/index.ts:4
import { XcodeServer } from "../../server.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/glob, glob, zod, dotenv, @types/node, typescript
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-02 · audit v0.4.1 · source sha 6c022dd495b1full audit observations/trust-audit/mcp-server/r-huijts__xcode-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-026c022dd495b1BLOCKD61first audit
06

Questions

What is the Xcode MCP server?

MCP Server implementation for Xcode integration

What tools does Xcode expose?

76 in total: 51 read-only, 21 that write, and 4 that can delete or overwrite (delete_file, remove_swift_package, reset_simulator, terminate_app). Every one is listed on this page with its risk.

Is Xcode safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (61/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Xcode need?

No credential environment variables were found in its source, so it appears to need none.

How does Xcode run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as xcode-mcp-server at 1.0.3.

How current is this page?

The grade is for one exact copy of the source (6c022dd495b1), read on 2026-10-02. The repository is watched and re-audited when it changes.

Advertisement