Android Debug BridgeSAFE
MCP plugin to control Android devices via ADB (Android Debug Bridge) for automation, testing, and agent integration.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Control Android devices and emulators from an AI agent — over MCP or straight from the terminal.
Both surfaces share one engine, so anything you can do as an MCP tool call you can also do as a shell command, and vice versa.
Features
- UI automation that survives layout changes — parse the accessibility tree, find elements by label/description/resource-id, and tap them by name instead of by coordinate
- Occlusion-aware taps — the accessibility tree has no z-order, so an element under a bottom bar still claims those pixels;
ui tapfinds an uncovered point inside the target and refuses (instead of silently hitting the overlay) when there is none - Normalized coordinates —
0.5 0.7means the same point on any screen size; raw pixels still work - Input — tap, double tap, long press, swipe, scroll, type, clear fields, and 40+ hardware/software keys
- Apps — list, launch (with launcher-activity resolution), stop, restart, clear data, install/uninstall, inspect versions, grant/revoke runtime permissions
- Screen — screenshots to disk and base64, screen recording, rotation, wake/sleep, PIN unlock
- Compressed screenshots — the full-resolution PNG goes to disk, the caller gets a downscaled copy: ~90% fewer bytes across the wire, which on an MCP client is the difference between a screenshot costing a few hundred tokens and costing a few hundred thousand
- Marked screenshots — a ring where the tap landed, drawn on the returned image: Android's own touch indicator exists only while the finger is down, so a screenshot taken afterwards never shows it
- Emulator console —
emu finger touchanswers a fingerprint prompt on an AVD, andemu send
665f6080d44fOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add android-debug-bridge-mcp -- npx -y [email protected]
{
"mcpServers": {
"android-debug-bridge-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (62)
41 read · 13 write · 8 destructive. Blast radius: 8 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
adb_shell | write | Escape hatch: run an arbitrary command in the device shell. Use a dedicated tool when one exists. |
app_info | read | Get package details: version name/code, SDK levels, installer, APK path and granted/denied permissions |
capture_screenshot | write | Capture a screenshot, save the full-resolution PNG under the test folder (or out_path) and return a downscaled, compressed copy as image content |
capture_ui_dump | read | Dump the UI hierarchy of the current screen and return the parsed elements (texts, buttons, inputs, switches, scrollables) with tap coordinates |
clear_app_data | destructive | Clear all app data (accounts, databases, caches). Destructive: the app returns to a first-install state. |
clear_logcat | destructive | Clear the logcat buffer, so the next read only shows new output |
connect_device | read | Connect to a device over TCP/IP (host:port) |
create_test_folder | write | Create a folder to collect the artifacts of a test run |
device_info | read | Get the device fingerprint: model, manufacturer, Android version, SDK, ABI, screen size, density, rotation and battery level |
disconnect_device | read | Disconnect a TCP/IP device, or all of them when no address is given |
emu_console | write | Send a raw command to the emulator console (adb emu ...), e.g. |
emu_finger_remove | destructive | Lift the virtual finger off the emulator fingerprint sensor (adb emu finger remove) |
emu_finger_touch | read | Touch the emulator fingerprint sensor with an enrolled finger id (adb emu finger touch <id>) — the way to answer a biometric prompt on an AVD. The finger must already be enrolled in Settings; emulators only. |
get_battery_info | read | Get the battery status report |
get_connectivity_state | read | Read the current Wi-Fi, mobile data and airplane mode state |
get_current_activity | read | Get the activity currently in the foreground |
get_device_props | read | Read system properties, optionally filtered by key substring |
get_focused_window | read | Get the currently focused window |
get_memory_usage | read | Get the memory usage report for an app |
get_setting | read | Read an Android setting value |
grant_permission | read | Grant a runtime permission to an app (e.g., CAMERA, ACCESS_FINE_LOCATION) |
input_clear_text | destructive | Clear the focused text field by moving to the end and sending backspaces |
input_double_tap | read | Double tap at coordinates |
input_keyevent | write | Send a hardware/software key event. Known keys: ${Object.keys(KEY_CODES).join( |
input_long_press | read | Press and hold at coordinates |
input_scroll | read | Scroll the screen. |
input_swipe | read | Swipe from one point to another, for gestures and drag interactions |
input_tap | read | Tap at coordinates. Accepts normalized 0..1 fractions or raw pixels. |
input_text | read | Type text into the focused field. ADB only transmits ASCII reliably; unsupported characters are reported back. |
install_apk | write | Install an APK on the device |
list_apps | read | List installed packages, optionally filtered by a name pattern |
list_artifacts | read | List the files collected in a test folder |
list_devices | read | List connected ADB devices with their state, model and transport id, and show which one the other tools target by default |
list_notifications | read | List the notifications currently posted on the device |
list_processes | read | List running processes, optionally filtered by a substring |
mark_screenshot | read | Draw the tap that just happened onto a screenshot taken before it. A click belongs to the screen it was decided from, not to the one it opened, and a capture cannot know what will be tapped next — so take the screenshot, act, then mark it. Rewrites the file in place unless out_path is given. |
open_app | read | Launch an app by package name. Resolves the launcher activity automatically unless one is given. |
open_deeplink | read | Open a URL or deeplink through the activity manager |
pull_file | read | Pull a file from the device to this machine |
push_file | write | Push a local file to the device |
put_setting | write | Write an Android setting value |
read_logcat | read | Read the logcat buffer, filtered by package, priority or substring — the fastest way to spot crashes and exceptions |
reboot_device | read | Reboot the device, optionally into bootloader or recovery |
record_screen | read | Record the screen for a number of seconds and pull the MP4 to this machine. Blocks for the whole duration (max 180s). |
reinstall_apk | read | Reinstall (replace) an existing APK, keeping app data |
restart_app | destructive | Force-stop an app and launch it again — the usual way to reset to a clean start |
revoke_permission | destructive | Revoke a runtime permission from an app |
rotate_screen | write | Set the screen orientation, or restore automatic rotation |
screen_state | read | Report screen size, rotation, and whether the display is awake and locked |
send_broadcast | write | Broadcast an intent with optional string extras |
sleep_screen | read | Turn the display off |
stop_app | destructive | Force-stop an app |
toggle_airplane_mode | write | Enable or disable airplane mode |
toggle_mobile_data | write | Enable or disable mobile data |
toggle_wifi | write | Enable or disable Wi-Fi |
ui_find | read | Find elements on the current screen by text, content description, resource id, class or type, ranked by relevance |
ui_tap | read | Find an element by text/description/resource id and tap it. Preferred over raw coordinates because it survives layout changes. Refuses to tap when the element is covered by an overlay or bottom bar, instead of silently hitting the thing on top. |
ui_wait_for | read | Poll the screen until an element matching the query appears, or time out |
uninstall_app | destructive | Uninstall an app from the device |
unlock_device | read | Wake the device, swipe up and type a numeric PIN to unlock |
wait_for_device | read | Wait until the device is online and has finished booting |
wake_screen | read | Wake the display and dismiss the keyguard swipe |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
clear_app_data, clear_logcat, emu_finger_remove, input_clear_text, restart_app, revoke_permission, stop_app, uninstall_app
@modelcontextprotocol/sdk, xml2js, @types/node, @types/xml2js, typescript, sharp
Gates applied: no_behavioural_pass.
665f6080d44ffull audit observations/trust-audit/mcp-server/tiagodanin__android-debug-bridge.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 665f6080d44f | SAFE | B | 89 | first audit |
Questions
What is the Android Debug Bridge MCP server?
MCP plugin to control Android devices via ADB (Android Debug Bridge) for automation, testing, and agent integration.
What tools does Android Debug Bridge expose?
62 in total: 41 read-only, 13 that write, and 8 that can delete or overwrite (clear_app_data, clear_logcat, emu_finger_remove, input_clear_text, restart_app). Every one is listed on this page with its risk.
Is Android Debug Bridge safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 8 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Android Debug Bridge need?
No credential environment variables were found in its source, so it appears to need none.
How does Android Debug Bridge run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as android-debug-bridge-mcp at 2.1.0.
How current is this page?
The grade is for one exact copy of the source (665f6080d44f), read on 2026-10-08. The repository is watched and re-audited when it changes.