AppleSAFE
Collection of apple-native tools for the model context protocol.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Plot twist: Your Mac can do more than just look pretty. Turn your Apple apps into AI superpowers!
Love this MCP? Check out supermemory MCP too - https://mcp.supermemory.ai
Click below for one click install with .dxt
[](https://smithery.ai/server/@Dhravya/apple-mcp)
🤯 What Can This Thing Do?
Basically everything you wish your Mac could do automatically (but never bothered to set up):
💬 Messages - Because who has time to text manually?
- Send messages to anyone in your contacts (even that person you've been avoiding)
- Read your messages (finally catch up on those group chats)
- Schedule messages for later (be that organized person you pretend to be)
📝 Notes - Your brain's external hard drive
- Create notes faster than you can forget why you needed them
- Search through that digital mess you call "organized notes"
- Actually find that brilliant idea you wrote down 3 months ago
👥 Contacts - Your personal network, digitized
- Find anyone in your contacts without scrolling forever
- Get phone numbers instantly (no more "hey, what's your number again?")
- Actually use that contact database you've been building for years
📧 Mail - Email like a pro (or at least pretend to)
- Send emails with attachments, CC, BCC - the whole professional shebang
- Search through your email chaos with surgical precision
- Schedule emails for later (because 3 AM ideas shouldn't be sent at 3 AM)
- Check unread counts (p
cfd13b212f85OBSERVED · 2026-09-22Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add apple-mcp -- npx -y [email protected]
{
"mcpServers": {
"apple-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (7)
1 read · 6 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
calendar | write | Search, create, and open calendar events in Apple Calendar app |
contacts | read | Search and retrieve contacts from Apple Contacts app |
mail | write | Interact with Apple Mail app - read unread emails, search emails, and send emails |
maps | write | Search locations, manage guides, save favorites, and get directions using Apple Maps |
messages | write | Interact with Apple Messages app - send, read, schedule messages and check unread messages |
notes | write | Search, retrieve and create notes in Apple Notes app |
reminders | write | Search, create, and open reminders in Apple Reminders app |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
bun.lockb
import calendarModule from "../../utils/calendar.js";
import contactsModule from "../../utils/contacts.js";
import contactsModule from "../../utils/contacts.js";
import mailModule from "../../utils/mail.js";
import mapsModule from "../../utils/maps.js";
@hono/node-server, @jxa/global-type, @jxa/run, @modelcontextprotocol/sdk, @types/express, mcp-proxy, run-applescript, zod
apple-mcp.dxt
Gates applied: no_behavioural_pass.
cfd13b212f85full audit observations/trust-audit/mcp-server/supermemoryai__apple-5.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-22 | cfd13b212f85 | SAFE | B | 89 | source changed, verdict held |
Questions
What is the Apple MCP server?
Collection of apple-native tools for the model context protocol.
What tools does Apple expose?
7 in total: 1 read-only, 6 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Apple safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Apple need?
No credential environment variables were found in its source, so it appears to need none.
How does Apple run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as apple-mcp at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (cfd13b212f85), read on 2026-09-22. The repository is watched and re-audited when it changes.