io.github.chrischall/apple-icloud-mcp
NPM · APPLE-ICLOUD-MCP · SCANNED OCT 2
Unofficial: Apple Music, iCloud Calendar/Contacts/Mail, Apple Maps and WeatherKit, no Mac needed
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security99
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 7 of 35 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency97
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to chrischall/apple-icloud-mcp). View diagnostics → Pass
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 2 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability65
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 16686 tokens (~282/item across 59 items; 59 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management17
- Stability observed for 5 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 7 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 59 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the io.github.chrischall/apple-icloud-mcp server?
io.github.chrischall/apple-icloud-mcp runs locally as an npm package, launched with npx -y apple-icloud-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · apple-icloud-mcp
claude mcp add chrischall-apple-icloud-mcp -- npx -y apple-icloud-mcp
{
"mcpServers": {
"chrischall-apple-icloud-mcp": {
"command": "npx",
"args": [
"-y",
"apple-icloud-mcp"
]
}
}
} {
"servers": {
"chrischall-apple-icloud-mcp": {
"command": "npx",
"args": [
"-y",
"apple-icloud-mcp"
]
}
}
} codex mcp add chrischall-apple-icloud-mcp -- npx -y apple-icloud-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"chrischall-apple-icloud-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"apple-icloud-mcp"
],
"enabled": true
}
}
} openclaw mcp add chrischall-apple-icloud-mcp --command npx --arg -y --arg apple-icloud-mcp
mcp_servers:
chrischall-apple-icloud-mcp:
command: "npx"
args: ["-y", "apple-icloud-mcp"] {
"McpServers": {
"chrischall-apple-icloud-mcp": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"apple-icloud-mcp"
]
}
}
} assistant mcp add chrischall-apple-icloud-mcp -t stdio -c npx -a -y apple-icloud-mcp
{
"mcpServers": {
"chrischall-apple-icloud-mcp": {
"command": "npx",
"args": [
"-y",
"apple-icloud-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 1 Oct 26 +16
- Malware scan: unverified → pass ▲ security
- 30 Sept 26 −15
- Malware scan: pass → unverified ▼ security
- Package version: 0.2.1 → 0.3.0 functional
- 29 Sept 26 +16
- Malware scan: unverified → pass ▲ security
- 28 Sept 26 −15
- Malware scan: pass → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Stability: unverified → 0.03 ▲ functional
- First check of Schema quality: unverified functional
- Package version: 0.1.0 → 0.2.1 functional
- Package version: 0.1.0 → 0.2.0 functional
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 79
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 2 Oct 2026 · Analysed npm/apple-icloud-mcp@0.3.0
Provenance Verified
A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.
| Result | Verified |
|---|---|
| Ecosystem | npm |
| Reason | Verified |
| Discovered via | Registry attestation endpoint |
| Source repo | chrischall/apple-icloud-mcp |
| Certificate issuer | https://token.actions.githubusercontent.com |
| Certificate SAN | https://github.com/chrischall/apple-icloud-mcp/.github/workflows/release-please.yml@refs/heads/main |
| Rekor log index | 3008557783 |
| Predicate type | SLSA build provenance https://slsa.dev/provenance/v1 |
| Subject digest | sha512:3af786cd6e9fd3e76f9e394faea66083b1d0e588a4ef8ebf6be4479abad8878c6758067abc5ba70eec83069244b60b8e307e87ec97806a5f0d0b0c340 |
Background: How many MCP packages publish verified provenance →
Dependencies 35 packages
| Packages resolved | 35 |
|---|---|
| Stale | 7 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
apple_music_move_playlist Move an Apple Music playlist into a folder ~103
Move one of your library playlists into a playlist folder, or back to the top level ("root"). Checks the folder exists and verifies the playlist appears in it. Uses Apple's web-player API (unofficial; needs APPLE_MUSIC_WEB_USER_TOKEN).
| Name | Type | Req | Description |
|---|---|---|---|
| folderId | string | yes | Destination folder id (p.… from apple_music_list_folders), or "root" for the top level. |
| playlistId | string | yes | Library playlist id (p.…). |
No output schema declared.
No examples provided.
apple_music_remove_favorites Unfavorite songs, albums, playlists or artists in Apple Music ~168
Remove the favorite (star) from catalog songs, albums, playlists, artists or music videos, by catalog id, up to 100 per type. Apple answers only "accepted" and offers no way to read favorites back. Uses Apple's web-player API (unofficial; needs APPLE_MUSIC_WEB_USER_TOKEN).
| Name | Type | Req | Description |
|---|---|---|---|
| albums | array | – | Catalog albums ids (up to 100) — numeric. |
| artists | array | – | Catalog artists ids (up to 100) — numeric. |
| musicVideos | array | – | Catalog music-videos ids (up to 100) — numeric. |
| playlists | array | – | Catalog playlists ids (up to 100) — pl.…. |
| songs | array | – | Catalog songs ids (up to 100) — numeric. |
No output schema declared.
No examples provided.
apple_music_remove_from_library Remove songs, albums or playlists from your Apple Music library ~243
Remove songs, albums, music videos or playlists from your Apple Music library by LIBRARY id (i.…, l.…, p.… from apple_music_list_library / apple_music_search_library), up to 50 at a time; the preview names each item. Uses Apple's web-player API (unofficial; needs APPLE_MUSIC_WEB_USER_TOKEN). Asks the user to confirm first: a confirmation prompt where the client supports one; otherwise the first call performs NO write and returns a preview of exactly what would happen plus a confirmToken, and only a repeat call with that token proceeds (see MCP_CONFIRM_MODE).
| Name | Type | Req | Description |
|---|---|---|---|
| confirmToken | string | – | ONLY for the two-step confirmation fallback (a client without MCP elicitation). The confirmToken from this same tool's phase-1 "confirmation-required" response, passed back ONLY after the user has se… |
| ids | array | yes | Library ids (up to 50). |
| type | string | yes | What the ids are. |
No output schema declared.
No examples provided.
apple_music_remove_playlist_tracks Remove tracks from an Apple Music playlist ~354
Remove tracks from one of your library playlists by library track id and/or 1-based position (from apple_music_get_playlist). Apple removes EVERY copy of a track, so removing one copy of a duplicate is refused (use apple_music_reorder_playlist). Takes expectedRevision, returns the new revision. Uses Apple's web-player API (unofficial; needs APPLE_MUSIC_WEB_USER_TOKEN). Asks the user to confirm first: a confirmation prompt where the client supports one; otherwise the first call performs NO write and returns a preview of exactly what would happen plus a confirmToken, and only a repeat call with that token proceeds (see MCP_CONFIRM_MODE).
| Name | Type | Req | Description |
|---|---|---|---|
| confirmToken | string | – | ONLY for the two-step confirmation fallback (a client without MCP elicitation). The confirmToken from this same tool's phase-1 "confirmation-required" response, passed back ONLY after the user has se… |
| expectedRevision | string | – | The playlist revision you expect: from apple_music_get_playlist (a complete read) or from the previous change's result. Refused if the playlist no longer reads as that revision. (A change is also ref… |
| playlistId | string | yes | Library playlist id (p.…). |
| positions | array | – | 1-based positions of tracks to remove (as listed by apple_music_get_playlist). |
| trackIds | array | – | Library ids of the tracks to remove (every copy of each). |
No output schema declared.
No examples provided.
apple_music_reorder_playlist Reorder, sort, dedupe or rewrite an Apple Music playlist ~472
Reorder one of your library playlists: move tracks, sort (name, artist, album, release date, duration, date added), reverse, dedupe (keep the first copy of each song), or replace with a complete new order of its track ids (can drop tracks). Takes expectedRevision, returns the new revision. Uses Apple's web-player API (unofficial; needs APPLE_MUSIC_WEB_USER_TOKEN). Asks the user to confirm first: a confirmation prompt where the client supports one; otherwise the first call performs NO write and returns a preview of exactly what would happen plus a confirmToken, and only a repeat call with that token proceeds (see MCP_CONFIRM_MODE).
| Name | Type | Req | Description |
|---|---|---|---|
| by | string | – | sort: the key (dateAdded is when the song entered your library; Apple often omits it on playlist tracks, and a key no track has is refused). |
| confirmToken | string | – | ONLY for the two-step confirmation fallback (a client without MCP elicitation). The confirmToken from this same tool's phase-1 "confirmation-required" response, passed back ONLY after the user has se… |
| count | integer | – | move: how many consecutive tracks to move (default 1). |
| descending | boolean | – | sort: largest/latest/Z first (default false). |
| expectedRevision | string | – | The playlist revision you expect: from apple_music_get_playlist (a complete read) or from the previous change's result. Refused if the playlist no longer reads as that revision. (A change is also ref… |
| fromPosition | integer | – | move: 1-based position of the first track to move. |
| operation | string | yes | What to do. |
| playlistId | string | yes | Library playlist id (p.…). |
| toPosition | integer | – | move: 1-based position the first moved track should end up at. |
| trackIds | array | – | replace: the complete new order as library track ids from apple_music_get_playlist; ids left out are removed. |
No output schema declared.
No examples provided.
apple_music_search_catalog Search the Apple Music catalog ~312
Search Apple Music's catalog by text for songs, albums, artists, playlists, music videos or stations. Results are grouped by type, each group with its own returned/hasMore/nextOffset, and carry catalog ids other tools take (e.g. to add songs to a playlist). Up to 25 per type per call. Needs an Apple Developer key (APPLE_TEAM_ID, APPLE_KEY_ID, APPLE_PRIVATE_KEY) or web-player mode (APPLE_MUSIC_WEB_USER_TOKEN).
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Results per type (default 10, max 25). |
| offset | integer | – | Skip this many results per type (use a group's nextOffset). |
| storefront | string | – | Two-letter Apple Music storefront (country catalog), e.g. us, gb, jp. Default: APPLE_MUSIC_STOREFRONT, else your account's storefront, else us. |
| term | string | yes | What to search for, e.g. "bohemian rhapsody queen". Prefer "title artist" over "title - artist". |
| types | array | – | Which kinds of results (default songs, albums, artists, playlists). |
| view | string | – | Response shape: "compact" (default) drops fields the response already carries elsewhere; "full" returns every field this server understands. compact keeps ids (library and catalog), names, artist/alb… |
No output schema declared.
No examples provided.
apple_music_search_library Search your Apple Music library ~219
Search YOUR Apple Music library (not the whole catalog) by text for songs, albums, artists, playlists or music videos. Results are grouped by type with library ids (i.… songs, l.… albums, p.… playlists) and each group's returned/hasMore/nextOffset. Up to 25 per type. Needs APPLE_MUSIC_USER_TOKEN or web-player mode.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Results per type (default 10, max 25). |
| offset | integer | – | Skip this many results per type. |
| term | string | yes | What to search for in your library. |
| types | array | – | Kinds of items (default songs, albums, artists, playlists). |
| view | string | – | Response shape: "compact" (default) drops fields the response already carries elsewhere; "full" returns every field this server understands. compact keeps ids (library and catalog), names, artist/alb… |
No output schema declared.
No examples provided.
apple_music_set_rating Love or dislike an Apple Music item ~133
Set your rating on a song, album, playlist, music video or station (catalog or library id): love, dislike, or none to clear it. Always sends the rating (Apple's reads can lag its writes); returns the previous rating as read and verifies the new one. Needs APPLE_MUSIC_USER_TOKEN or web-player mode.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The item id. |
| rating | string | yes | love, dislike, or none to remove your rating. |
| type | string | yes | What the id is: catalog types (songs, albums, …) or library-* types for library ids. |
No output schema declared.
No examples provided.
apple_music_update_playlist Rename an Apple Music playlist or change its description ~149
Rename one of your Apple Music library playlists, change its description, or make it public/private. Returns the previous values and verifies the change. Refused while Apple does not show your last change to the playlist yet (the update sends every field back, so it would undo it). Uses Apple's web-player API (unofficial; needs APPLE_MUSIC_WEB_USER_TOKEN).
| Name | Type | Req | Description |
|---|---|---|---|
| description | string | – | New description ("" clears it). |
| isPublic | boolean | – | Show it on your Apple Music profile (true) or not (false). |
| name | string | – | New name. |
| playlistId | string | yes | Library playlist id (p.…) from apple_music_list_playlists. |
No output schema declared.
No examples provided.
apple_weather_get Get the weather forecast (Apple Weather) ~582
Weather forecast for a place from Apple Weather (WeatherKit): current conditions, hourly (up to 240 h), daily (up to 10 days), next-hour rain, severe-weather alerts (need countryCode). Returns temperature, feels-like, rain/snow chance and amount, wind, humidity, UV, sunrise/sunset. Takes latitude/longitude — use apple_maps_geocode first to turn a place name into coordinates. Days roll over in timeZone: pass the place's own zone when it differs from yours. Needs APPLE_TEAM_ID, APPLE_KEY_ID, APPLE_PRIVATE_KEY and APPLE_WEATHERKIT_SERVICE_ID. Show the returned attribution with the data.
| Name | Type | Req | Description |
|---|---|---|---|
| countryCode | string | – | Two-letter ISO country code of the location (e.g. US, GB). Required for severe-weather alerts; without it alerts are skipped, with a note. |
| dataSets | array | – | What to fetch (default current, hourly, daily, alerts): current = conditions now; hourly = hour by hour; daily = day by day; nextHour = minute-level precipitation for the next hour (some regions only… |
| days | integer | – | Days of daily forecast starting today in timeZone (default 7, max 10). Needs "daily" in dataSets. |
| hours | integer | – | Hours of hourly forecast from the current hour (default 24, max 240). Needs "hourly" in dataSets. |
| lang | string | – | Language of alert descriptions, as a BCP 47 tag such as en, en-GB, fr or ja (default en). Condition words are always English. |
| latitude | number | yes | Latitude in decimal degrees, -90 to 90 (e.g. 40.7128). |
| longitude | number | yes | Longitude in decimal degrees, -180 to 180 (e.g. -74.006). |
| timeZone | string | – | IANA time zone (e.g. America/New_York) that times are shown in and that days roll over in. Default: the server's display zone (DISPLAY_TZ). For a place in another zone pass that place's zone. |
| units | string | – | metric (°C, km/h, mm, hPa, km) or imperial (°F, mph, in, inHg, mi). Default: APPLE_UNITS, else metric. |
| view | string | – | Response shape: "compact" (default) drops fields the response already carries elsewhere; "full" returns every field this server understands. compact converts units, rounds, turns fractions into perce… |
No output schema declared.
No examples provided.
apple_weather_get_alert Get a severe-weather alert (Apple Weather) ~264
Get one severe-weather alert's full official text from Apple Weather (WeatherKit), unmodified, by its id (the alerts[].id from apple_weather_get called with countryCode). Returns the issuing agency (source), severity, effective/expiry times, detailsUrl and the messages verbatim. Apple serves an alert only while it is active; an expired one is NOT_FOUND. Needs APPLE_TEAM_ID, APPLE_KEY_ID, APPLE_PRIVATE_KEY and APPLE_WEATHERKIT_SERVICE_ID.
| Name | Type | Req | Description |
|---|---|---|---|
| alertId | string | yes | The alert id (a UUID), from alerts[].id in an apple_weather_get result. |
| lang | string | – | Language of the alert text, as a BCP 47 tag such as en, en-GB, fr or ja (default en). |
| timeZone | string | – | IANA time zone (e.g. America/New_York) the alert's times are shown in. Default: the server's display zone (DISPLAY_TZ). |
| view | string | – | Response shape: "compact" (default) drops fields the response already carries elsewhere; "full" returns every field this server understands. compact drops the alert area geometry (GeoJSON) and bookke… |
No output schema declared.
No examples provided.
What is the io.github.chrischall/apple-icloud-mcp server?
io.github.chrischall/apple-icloud-mcp is listed in the public MCP registry as io.github.chrischall/apple-icloud-mcp. Unofficial: Apple Music, iCloud Calendar/Contacts/Mail, Apple Maps and WeatherKit, no Mac needed. This page covers its npm package (apple-icloud-mcp).
Is the io.github.chrischall/apple-icloud-mcp server safe to use?
io.github.chrischall/apple-icloud-mcp scores 81 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 2 October 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.chrischall/apple-icloud-mcp server expose?
io.github.chrischall/apple-icloud-mcp exposes 59 tools: apple_healthcheck, apple_music_search_catalog, apple_music_get_catalog_items, apple_music_get_charts, apple_music_list_playlists, and 54 more. Their descriptions and schemas cost roughly 16,686 tokens of context every time the server is loaded.
Is the io.github.chrischall/apple-icloud-mcp server still maintained?
io.github.chrischall/apple-icloud-mcp is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the io.github.chrischall/apple-icloud-mcp server under?
io.github.chrischall/apple-icloud-mcp declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.