appstore-api-mcp
npm
v1.12.0
Source verified
Published by fil-technology — publish provenance cryptographically ties this package to that repository. That is proof of origin, not an official vendor package.
MCP server for Apple App Store Connect — edit listings (keywords, descriptions, titles, screenshots), track analytics (downloads, proceeds, subscriptions, retention), run a fleet-wide ASO audit, preview changes with dry-run, and reach the full API. Works
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 6 = 94. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −6 | capability blast radius (high) — client exposure if the model is manipulated |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
In the server's implementation (`src/index.js:12`): Spawning a shell/process is command-execution capability; with unsanitized tool input it is command injection / RCE. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: { execFile } from "node:child_process"; import { Server } from "@modelcontextprotocol/sdk/server/index.js"; import { Std
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server src/index.js
Each tool and what it can reach — statically extracted from the published source.
download_profileingests untrusted inputget_analytics_report_dataingests untrusted inputget_finance_reportingests untrusted inputget_sales_reportingests untrusted inputget_screenshotingests untrusted inputsnapshot_app_metadataingests untrusted inputadd_beta_testerno sensitive capabilityadd_build_to_beta_groupno sensitive capabilityapps_review_statusno sensitive capabilityarchive_appno sensitive capabilityaso_opportunity_reportno sensitive capabilityaudit_appsno sensitive capabilitybulk_update_version_localizationsno sensitive capabilitybump_build_numberno sensitive capabilitycreate_app_info_localizationno sensitive capabilitycreate_app_preview_setno sensitive capabilitycreate_app_store_versionno sensitive capabilitycreate_app_store_version_localizationno sensitive capabilitycreate_certificateno sensitive capabilitycreate_profileno sensitive capabilitycreate_screenshot_setno sensitive capabilitydelete_app_previewno sensitive capabilitydelete_profileno sensitive capabilitydelete_screenshotno sensitive capabilitydiff_app_metadata_snapshotno sensitive capabilitydoctorno sensitive capabilityget_age_ratingno sensitive capabilityget_appno sensitive capabilityget_app_previewno sensitive capabilityget_app_price_scheduleno sensitive capabilityget_app_store_version_localizationno sensitive capabilityget_subscription_reportno sensitive capabilitylist_analytics_report_instancesno sensitive capabilitylist_analytics_reportsno sensitive capabilitylist_app_info_localizationsno sensitive capabilitylist_app_infosno sensitive capabilitylist_app_preview_setsno sensitive capabilitylist_app_previewsno sensitive capabilitylist_app_price_pointsno sensitive capabilitylist_app_store_version_experimentsno sensitive capabilitylist_app_store_version_localizationsno sensitive capabilitylist_app_store_versionsno sensitive capabilitylist_appsno sensitive capabilitylist_available_territoriesno sensitive capabilitylist_beta_groupsno sensitive capabilitylist_beta_testersno sensitive capabilitylist_buildsno sensitive capabilitylist_bundle_idsno sensitive capabilitylist_certificatesno sensitive capabilitylist_customer_reviewsno sensitive capabilitylist_devicesno sensitive capabilitylist_game_center_achievementsno sensitive capabilitylist_game_center_leaderboardsno sensitive capabilitylist_in_app_purchasesno sensitive capabilitylist_profilesno sensitive capabilitylist_screenshot_setsno sensitive capabilitylist_screenshotsno sensitive capabilityportfolio_growth_reportno sensitive capabilityraw_requestno sensitive capabilityregister_bundle_idno sensitive capabilityregister_deviceno sensitive capabilityrelease_readiness_checkno sensitive capabilityrelease_versionno sensitive capabilityreply_to_customer_reviewno sensitive capabilityrequest_analytics_reportno sensitive capabilityrestore_app_metadatano sensitive capabilityrestore_app_previewsno sensitive capabilityrestore_screenshotsno sensitive capabilityrevoke_certificateno sensitive capabilityset_app_priceno sensitive capabilityset_phased_releaseno sensitive capabilitysigning_healthno sensitive capabilitysubmit_beta_reviewno sensitive capabilitysubmit_for_reviewno sensitive capabilityupdate_app_info_localizationno sensitive capabilityupdate_app_store_version_localizationno sensitive capabilityupdate_in_app_purchaseno sensitive capabilityupload_app_previewno sensitive capabilityupload_buildno sensitive capabilityupload_screenshotno sensitive capabilityScan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.12.0 latest |
A 94/100 | 1 | 1.13.0 | 2026-09-09 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan appstore-api-mcp --online
Hotel booking MCP server — 300K+ properties, real confirmation numbers, loyalty programs. Builders monetize every booking via Stripe Connect. The first MCP server that completes real hotel reservations inside AI conversations.
Manage AdGuard Home through AI assistants
Read-only Azure DevOps for MCP clients using only your existing browser session — no PAT, no Azure CLI. Browse work items, pull requests, comments, attachments and Artifacts feeds across every project, repo and feed you can access.
MCP server for Adobe Experience Manager Assets integration development
Servidor MCP para el tiempo oficial de España (API pública OpenData de AEMET). Predicción, observación y avisos como herramientas MCP tipadas.
A standalone MCP stdio bridge for Affinity by Canva's local MCP SSE server.