io.github.gbatistuta0/appfactory
PYPI · APPFACTORY · SCANNED OCT 4
Lets your coding agent ship a SwiftUI iOS subscription app from idea to TestFlight.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security100
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- Runs hatchling.build at install time, a recognised build step with no custom scripting around it. View diagnostics → Pass
- 1 of 22 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency100
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to gbatistuta0/appfactory). View diagnostics → Pass
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 4 days ago).Pass
- Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability48
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- Instruction-quality not yet verified: the AI judgement didn't run.Unverified
- Context-footprint check failed: tool/resource definitions use about 19176 tokens (~152/item across 126 items; 125 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- Manipulation not yet verified: only 2 of 127 captured unit(s) of tool text has been judged so far, so we will not certify text no model has read as clean.Unverified
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
Unverified: 1 category
A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.
How do I install the io.github.gbatistuta0/appfactory MCP server?
io.github.gbatistuta0/appfactory runs locally as a PyPI package, launched with uvx appfactory. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
pypi · appfactory
claude mcp add gbatistuta0-appfactory -- uvx appfactory
{
"mcpServers": {
"gbatistuta0-appfactory": {
"command": "uvx",
"args": [
"appfactory"
]
}
}
} {
"servers": {
"gbatistuta0-appfactory": {
"command": "uvx",
"args": [
"appfactory"
]
}
}
} codex mcp add gbatistuta0-appfactory -- uvx appfactory
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"gbatistuta0-appfactory": {
"type": "local",
"command": [
"uvx",
"appfactory"
],
"enabled": true
}
}
} openclaw mcp add gbatistuta0-appfactory --command uvx --arg appfactory
mcp_servers:
gbatistuta0-appfactory:
command: "uvx"
args: ["appfactory"] {
"McpServers": {
"gbatistuta0-appfactory": {
"Transport": "stdio",
"Command": "uvx",
"Arguments": [
"appfactory"
]
}
}
} assistant mcp add gbatistuta0-appfactory -t stdio -c uvx -a appfactory
{
"mcpServers": {
"gbatistuta0-appfactory": {
"command": "uvx",
"args": [
"appfactory"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 30 Sept 26 +15
- Malware scan: unverified → pass ▲ security
- 29 Sept 26 60
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 6 Oct 2026 · Analysed pypi/appfactory@0.1.5
Provenance Verified
A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.
| Result | Verified |
|---|---|
| Ecosystem | pypi |
| Reason | Verified |
| Discovered via | Registry attestation endpoint |
| Source repo | gbatistuta0/appfactory |
| Certificate issuer | https://token.actions.githubusercontent.com |
| Certificate SAN | https://github.com/gbatistuta0/appfactory/.github/workflows/release.yml@refs/tags/v0.1.5 |
| Rekor log index | 3004333188 |
| Predicate type | PyPI publish attestation https://docs.pypi.org/attestations/publish/v1 |
| Subject digest | sha256:19e11c989976e965a51efa3cbc68c13783dfdc12d467cef474242976ecf7de2f |
Background: How many MCP packages publish verified provenance →
Install scripts 1 script
| Hook | Tier | Command |
|---|---|---|
| build_backend | allowlisted | hatchling.build |
Background: Why install scripts are a supply-chain risk →
Dependencies 22 packages
| Packages resolved | 22 |
|---|---|
| Stale | 1 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
ai_configure AI Configure ~78
Report the AI provider/model selection (currently fal.ai Flux schnell); does not change anything. Use when: checking which image model the backend will use. Keys are set with ai_deploy_proxy or backend_deploy. Returns: {ok, providers, models, note}.
| Name | Type | Req | Description |
|---|---|---|---|
| providers | – | – | AI provider ids; default ['fal.ai']. |
Structured output declared, but exposes no named fields.
No examples provided.
ai_deploy_proxy AI Deploy Proxy ~201
Deploy the AI backend: the full spec-driven backend in subscription mode, or the legacy ai-proxy in credits mode (live, needs human approval). Use when: the app has an AI feature. AI keys go only to server-side secrets. For explicit dry-run planning use backend_deploy. Returns: {ok, deployed: [...]} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| daily_limit | integer | – | Per-user daily request cap for the legacy ai-proxy (default 20). |
| project_ref | string | yes | Supabase project ref to deploy to. |
Structured output declared, but exposes no named fields.
No examples provided.
animation_fetch_recolor Animation Fetch Recolor ~223
Fetch a cute Lottie animation from the free LottieFiles library and recolor it to the app palette into Resources/Animations/<slot>.json. Use when: once per slot (loading, success, empty, onboarding_hero) for every app; rendered by lottie-spm with .named(slot). Colors are mapped at build time (dominant to primary, others to accent). Returns: {ok, path, source, colors}.
| Name | Type | Req | Description |
|---|---|---|---|
| accent_hex | string | yes | Accent palette color as hex, '#' optional, e.g. 'FFB300'. |
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| keyword | – | – | App-themed search keyword override, e.g. 'happy dog celebration'. |
| primary_hex | string | yes | Primary palette color as hex, '#' optional, e.g. '006A63'. |
| slot | string | yes | Animation slot: 'loading', 'success', 'empty' or 'onboarding_hero'. |
Structured output declared, but exposes no named fields.
No examples provided.
app_inject_config App Inject Config ~377
Fill in the scaffolded app's AppConfig and StoreKit tokens (Supabase, proxy, PostHog, product ids, credits, paywall strategy). Use when: after backend and RevenueCat values exist. Credit fields default to 15/10/10/30/60 and pack amounts must match the server-side PACK_MAP. Not for: spec-driven changes (edit app.spec.json, then app_sync_spec). Returns: {ok, changed: [files]}.
| Name | Type | Req | Description |
|---|---|---|---|
| ai_proxy_url | – | – | URL of the deployed AI proxy/edge function. |
| credit_pack_large | – | – | Credits in the large top-up pack (default 60). |
| credit_pack_medium | – | – | Credits in the medium top-up pack (default 30). |
| credit_pack_small | – | – | Credits in the small top-up pack (default 10). |
| paywall_strategy | – | – | 'hard_only' (hard paywall only) or 'hard_and_offer' (default: plus a discounted offer paywall on dismiss). |
| posthog_key | – | – | PostHog project API key. |
| privacy_url | – | – | Public privacy policy URL. |
| product_weekly | – | – | Weekly subscription product id. |
| product_yearly | – | – | Yearly subscription product id. |
| project_dir | string | yes | Path to the scaffolded app project directory. |
| revenuecat_key | – | – | RevenueCat public SDK key (appl_...). |
| supabase_anon_key | – | – | Supabase anon (public) key. |
| supabase_url | – | – | Supabase project URL, e.g. https://abcd.supabase.co. |
| support_email | – | – | Public support email address. |
| weekly_credits | – | – | Credits granted per week on the weekly plan (default 10). |
| yearly_credits | – | – | Credits granted per month on the yearly plan (default 15). |
Structured output declared, but exposes no named fields.
No examples provided.
app_scaffold App Scaffold ~207
Scaffold a new SwiftUI app from app.spec.json (xcodegen), init the pipeline manifest and a local git repo. Use when: starting a new app after idea validation. The spec drives products, StoreKit file, locales, onboarding length, monetization mode and backend mode. Not for: editing an existing app (use app_sync_spec after changing the spec). Returns: {ok, dir, name, bundle_id, manifest}.
| Name | Type | Req | Description |
|---|---|---|---|
| bundle_id | – | – | App bundle identifier in reverse-DNS form, e.g. com.example.app. |
| dest_dir | – | – | Directory to create the app folder in; omit for the default apps directory. |
| display_name | – | – | Name shown under the app icon; defaults to name. |
| name | – | – | App name, e.g. 'PetPortrait'; used for the folder and target. |
| spec | – | – | Full app.spec.json as a dict, a dict of overrides on the defaults, or a path to an app.spec.json file. |
Structured output declared, but exposes no named fields.
No examples provided.
app_sync_spec App Sync Spec ~85
Regenerate AppSpec.swift, PaywallSource.swift and Configuration.storekit and prune String Catalogs to locales.app. Use when: after editing app.spec.json. Local writes only. Returns: {ok, files}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
Structured output declared, but exposes no named fields.
No examples provided.
asc_add_subscription_group_localization ASC Add Subscription Group Localization ~161
Add one display-name localization to a subscription group (required to clear MISSING_METADATA; live write, needs human approval). Use when: a single locale is needed. For many languages use asc_localize_group. Returns: {ok, data} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| group_id | string | yes | App Store Connect subscription group id. |
| locale | string | – | Locale code, e.g. 'en-US', 'de-DE'. |
| name | string | yes | Subscription group display name shown to users. |
Structured output declared, but exposes no named fields.
No examples provided.
asc_append_subscription_disclosure ASC Append Subscription Disclosure ~236
Append the subscription disclosure, Terms/EULA and Privacy links to the app description in every language (Apple 3.1.2; live write, needs human approval). Use when: preparing a subscription app for review. Idempotent (skips when the marker is present) and truncated to 4000 characters. Not for: uploading other metadata (use deliver_metadata). Returns: {ok, per-locale results} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| bundle_id | string | yes | App bundle identifier in reverse-DNS form, e.g. com.example.app. |
| disclosure_by_locale | – | – | Optional {locale: disclosure text} overriding the default subscription disclosure per language. |
| privacy_url | string | yes | Public privacy policy URL, e.g. https://example.com/privacy. |
| terms_url | – | – | Terms of Use/EULA URL; omit to use Apple's standard EULA. |
Structured output declared, but exposes no named fields.
No examples provided.
asc_create_app ASC Create App ~235
Create an app shell in App Store Connect via fastlane produce (live write, needs human approval). Use when: after aso_check_name confirms a free name; pass candidate_names and the first available is used. Not for: bundle ids (asc_create_bundle_id) or metadata (deliver_metadata). Returns: {ok, app_id, name, ...} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| app_name | – | – | Single app name; prefer candidate_names. Converted to a one-element candidate list. |
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| bundle_id | string | yes | App bundle identifier in reverse-DNS form, e.g. com.example.app. |
| candidate_names | – | – | Ordered candidate App Store names; the first one not already taken is used. |
| primary_language | string | – | Primary App Store language, e.g. 'en-US'. |
| sku | – | – | Unique SKU string for the app record; omit to derive from the bundle id. |
Structured output declared, but exposes no named fields.
No examples provided.
asc_create_bundle_id ASC Create Bundle ID ~252
Register a bundle id in App Store Connect and check or apply its App ID capabilities (live write, needs human approval). Use when: first ASC step for a new app; capabilities (IN_APP_PURCHASE, Sign in with Apple, HEALTHKIT if enabled) must exist before signing. Not for: creating the app record (use asc_create_app). Returns: {bundle_id: <ASC result>, capabilities: <store_setup report>} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | – | – | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| apply_capabilities | boolean | – | If true, also enable the spec's App ID capabilities (needs app_dir); false only checks them. |
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| identifier | string | yes | Bundle identifier to register, e.g. com.example.app. |
| name | string | yes | Human-readable name of the bundle id in the developer portal, e.g. 'My App'. |
Structured output declared, but exposes no named fields.
No examples provided.
asc_create_subscription ASC Create Subscription ~212
Create a subscription product inside a subscription group (live write, needs human approval). Use when: hand-building a single product. Prefer store_setup for the whole spec. Returns: {ok, data: {data: {id, ...}}} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| family_shareable | boolean | – | Whether the subscription can be shared with family members; default false. |
| group_id | string | yes | App Store Connect subscription group id. |
| name | string | yes | Internal reference name of the subscription product. |
| period | string | – | Subscription period enum: ONE_WEEK, ONE_MONTH, TWO_MONTHS, THREE_MONTHS, SIX_MONTHS or ONE_YEAR. |
| product_id | string | yes | Product identifier of the subscription, e.g. com.example.app.yearly. |
Structured output declared, but exposes no named fields.
No examples provided.
asc_create_subscription_group ASC Create Subscription Group ~183
Create a subscription group for an app (live write, needs human approval). Use when: hand-building the subscription tree. Prefer store_setup, which does groups, products, prices and offers idempotently from app.spec.json. Returns: {ok, data: {data: {id, ...}}} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | string | yes | App Store Connect app id (numeric Apple id, e.g. '1234567890'); for aso_competitor_iap the iTunes trackId. |
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| reference_name | string | yes | Internal reference name of the subscription group (not shown to users). |
Structured output declared, but exposes no named fields.
No examples provided.
asc_ensure_subscription_prices ASC Ensure Subscription Prices ~202
Set a price on every subscription of the app that has none, clearing MISSING_METADATA (live write, needs human approval). Use when: subscriptions are stuck in MISSING_METADATA for price. Idempotent: priced subscriptions are skipped. Returns: {ok, priced: [...], skipped: [...]} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| bundle_id | string | yes | App bundle identifier in reverse-DNS form, e.g. com.example.app. |
| default_usd | – | – | USD price string applied to subscriptions not listed in usd_price_by_product. |
| usd_price_by_product | – | – | Map of subscription productId to USD price string, e.g. {'com.example.app.yearly': '49.99'}. |
Structured output declared, but exposes no named fields.
No examples provided.
asc_finalize_submission_requirements ASC Finalize Submission Requirements ~354
Fill the submit-blocking app-level fields in one call: content rights, copyright, age rating (4+), free price, App Review contact and notes (live write, needs human approval). Use when: once per app before asc_submit_for_review. App Privacy is not in Apple's API and must be set in the ASC web UI. Missing copyright falls back to config; missing contact_email to support_email. Returns: {ok, steps...} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| ai_services | – | – | Short description of the AI services the app uses, inserted into the review notes. |
| app_name | – | – | App name used to fill the generic App Review notes template. |
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| bundle_id | string | yes | App bundle identifier in reverse-DNS form, e.g. com.example.app. |
| contact_email | – | – | App Review contact email; defaults to the config support_email. |
| contact_first | string | – | App Review contact first name. |
| contact_last | string | – | App Review contact last name. |
| contact_phone | string | – | App Review contact phone in international format, e.g. '+14155550100'. |
| copyright | – | – | Copyright line for the store listing, e.g. '2026 Example Ltd'; falls back to the config 'copyright' key. |
| free | boolean | – | If true (default) the app price is set to Free. |
| review_notes | – | – | Custom App Review notes; omit to fill the generic 7-item test-flow template. |
Structured output declared, but exposes no named fields.
No examples provided.
asc_finalize_subscription ASC Finalize Subscription ~271
Finalize one subscription in order: localization, availability (all but CHN), price, intro offer (live write, needs human approval). Use when: fixing a single product by hand. Prefer store_setup, which does every product idempotently. Pass the spec product's intro (e.g. {"type": "free", "duration": "P3D"}); offer products get no intro. Returns: {ok, steps...} per step, or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| description | string | yes | Subscription description shown to users (en-US). |
| intro | – | – | Intro offer from the spec product, e.g. {"type": "free", "duration": "P3D"}; omit for offer products (no intro). |
| name | string | yes | Subscription display name shown to users (en-US). |
| period | – | – | Ignored; kept for backward compatibility. |
| sub_id | string | yes | App Store Connect subscription id. |
| usd_price | string | yes | USD base price as a decimal string, e.g. '49.99'. |
Structured output declared, but exposes no named fields.
No examples provided.
asc_get_app ASC Get App ~94
Find one App Store Connect app by bundle id (live, read-only). Use when: you need the numeric app id for a known bundle id. Not for: listing all apps (use asc_list_apps). Returns: {ok, data: {data: [app resources]}} from the ASC API.
| Name | Type | Req | Description |
|---|---|---|---|
| bundle_id | string | yes | App bundle identifier in reverse-DNS form, e.g. com.example.app. |
Structured output declared, but exposes no named fields.
No examples provided.
asc_list_apps ASC List Apps ~69
List the apps in App Store Connect (live, read-only). Use when: you need app ids or want to see what exists. To find one app by bundle id use asc_get_app. Returns: {ok, count, apps: [{id, bundleId, name, sku}]}.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
asc_localize_group ASC Localize Group ~148
Localize a subscription group's display name in many languages at once (live write, needs human approval). Use when: several locales are needed; for one locale use asc_add_subscription_group_localization. Returns: {ok, done: [locales], skipped: [locales]} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| group_id | string | yes | App Store Connect subscription group id. |
| name_by_locale | object | yes | Map {locale: group display name}. |
Structured output declared, but exposes no named fields.
No examples provided.
asc_localize_subscription ASC Localize Subscription ~156
Localize a subscription's name and description in many languages at once (live write, needs human approval). Use when: filling per-locale product copy. Languages the IAP API does not support are skipped. Returns: {ok, done: [locales], skipped: [locales]} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| items | object | yes | Map {locale: {name, description}} of subscription display copy per locale. |
| sub_id | string | yes | App Store Connect subscription id. |
Structured output declared, but exposes no named fields.
No examples provided.
asc_sbp_check ASC SBP Check ~141
Prove Small Business Program status from the latest subscription sales report (US proceeds/price ratio, about 0.85 SBP vs 0.70 standard; live, read-only). Use when: confirming the 15% commission. Needs a Finance-role key (asc_finance_key_id, asc_finance_key_filepath, asc_vendor_number); a 403 gives a clear error. Returns: {ok, ratio, program, report_date}.
| Name | Type | Req | Description |
|---|---|---|---|
| days_back | integer | – | How many days back to search for the latest report (default 7). |
| report_date | – | – | Sales report date YYYY-MM-DD; omit to use the latest available. |
Structured output declared, but exposes no named fields.
No examples provided.
asc_submit_for_review ASC Submit For Review ~184
Submit the app to App Store review (live write, ALWAYS needs out-of-band human approval, even with approvals off). Use when: everything else is ready and the human has approved. Without a valid approval_id nothing is submitted. Not for: uploading a TestFlight build (use testflight_ship). Returns: {ok, review_submission_id, detail} or {ok: false, blockers, next}, or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | string | yes | App Store Connect app id (numeric Apple id, e.g. '1234567890'); for aso_competitor_iap the iTunes trackId. |
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
Structured output declared, but exposes no named fields.
No examples provided.
asc_token_check ASC Token Check ~88
Verify App Store Connect authentication through the asc CLI with one live read-only call. Use when: before any asc_* tool, to confirm key id, issuer and .p8 work. Not for: listing apps (use asc_list_apps). Returns: {ok, asc: {path, version}, auth_source, key_id, p8, keychain_profiles, note, error?}.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
aso_check_name ASO Check Name ~103
Check whether an App Store app name is free, by exact-name collision in iTunes Search. Use when: testing one name before asc_create_app. For several names use aso_find_available_name. Returns: {ok, name, available, conflicts: [...]}.
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | Two-letter App Store storefront code, lowercase, e.g. 'us', 'gb', 'de'. |
| name | string | yes | Candidate App Store app name to check. |
Structured output declared, but exposes no named fields.
No examples provided.
aso_competitor_iap ASO Competitor IAP ~156
Fetch a competitor's subscription/IAP price ladder from its App Store product page. Use when: setting our pricing. app_id is the iTunes trackId from aso_fetch_competitors. Fragile, undocumented source: on failure ok:false and prices null mean unknown, not free. Returns: {ok, prices: [{name, price}] | null} (untrusted_content).
| Name | Type | Req | Description |
|---|---|---|---|
| app_id | string | yes | App Store Connect app id (numeric Apple id, e.g. '1234567890'); for aso_competitor_iap the iTunes trackId. |
| country | string | – | Two-letter App Store storefront code, lowercase, e.g. 'us', 'gb', 'de'. |
Structured output declared, but exposes no named fields.
No examples provided.
aso_complete ASO Complete ~96
Validate the ASO output and mark the 'aso' stage done, opening the metadata/deliver gate. Use when: ASO files are written. Not for: other stages (use pipeline_mark). Returns: {ok, problems?} or a refusal listing what is missing.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
Structured output declared, but exposes no named fields.
No examples provided.
aso_fetch_competitors ASO Fetch Competitors ~150
Fetch competitor apps for a search term through iTunes Search (live, read-only). Use when: sizing up a niche or getting trackIds for aso_competitor_iap. For a scored go/no-go use aso_niche_score. Returns: {ok, count, apps: [{trackId, name, ratings, price, ...}]} (untrusted_content).
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | Two-letter App Store storefront code, lowercase, e.g. 'us', 'gb', 'de'. |
| limit | integer | – | Number of competitor apps to return (default 10). |
| term | string | yes | Search term or seed keyword, e.g. 'habit tracker'. |
Structured output declared, but exposes no named fields.
No examples provided.
aso_find_available_name ASO Find Available Name ~108
Pick the first available App Store name from a candidate list. Use when: you have ordered name options; a taken name gets a submission rejected. For one name use aso_check_name. Returns: {ok, name, checked: [...]} or {ok: false} if none is free.
| Name | Type | Req | Description |
|---|---|---|---|
| candidates | array | yes | Ordered candidate app names. |
| country | string | – | Two-letter App Store storefront code, lowercase, e.g. 'us', 'gb', 'de'. |
Structured output declared, but exposes no named fields.
No examples provided.
aso_niche_score ASO Niche Score ~183
Score an idea 0-100 from demand, competitor weakness, saturation and monetization, with a go/no-go verdict. Use when: ranking one idea quickly. For the full evidence bundle use idea_evaluate. verdict: GO (>=60), MAYBE (>=40), WEAK, REJECT (median competitor >50k ratings or no demand). Returns: {ok, score, verdict, demand, competitors, ...} (untrusted_content).
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | Two-letter App Store storefront code, lowercase, e.g. 'us', 'gb', 'de'. |
| genre | – | – | App Store category name (e.g. 'photo_video', 'productivity', 'health') or numeric genre id; omit for all/inferred. |
| term | string | yes | Search term or seed keyword, e.g. 'habit tracker'. |
Structured output declared, but exposes no named fields.
No examples provided.
aso_run ASO Run ~80
Start the mandatory ASO stage: create the outputs skeleton and return the skill instructions. Use when: the pipeline reaches ASO. Finish with aso_complete. Returns: {ok, outputs_dir, instructions}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
Structured output declared, but exposes no named fields.
No examples provided.
aso_scaffold_outputs ASO Scaffold Outputs ~118
Create the outputs/<App>/ ASO skeleton including apple-metadata.md in 32 languages. Use when: standalone ASO work. Inside the pipeline use aso_run, which also returns the skill instructions. Returns: {ok, dir, files}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_name | string | yes | App name; creates outputs/<app_name>/. |
| base_dir | string | yes | Directory that contains (or will contain) the outputs/<App>/ folder. |
| locales | – | – | Locale codes for the metadata skeleton; omit for the 32 default languages. |
Structured output declared, but exposes no named fields.
No examples provided.
aso_search_hints ASO Search Hints ~157
Query App Store autocomplete for real search demand; the idea-stage hard gate (0 suggestions for a real term = no demand, reject). Use when: validating an idea or expanding keywords (expand=true appends a-z). An endpoint error returns ok:false, never an empty list. Returns: {ok, term, suggestions: [...], count} (untrusted_content).
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | Two-letter App Store storefront code, lowercase, e.g. 'us', 'gb', 'de'. |
| expand | boolean | – | If true, append a-z to the seed to collect the full keyword universe; default false. |
| term | string | yes | Search term or seed keyword, e.g. 'habit tracker'. |
Structured output declared, but exposes no named fields.
No examples provided.
aso_top_grossing ASO Top Grossing ~157
List the top-grossing apps of a storefront and optional category as a revenue proxy. Use when: hunting proven ideas in one category. To sweep all categories and storefronts use idea_harvest. An unknown genre returns ok:false, never the overall chart. Returns: {ok, apps: [...]} (untrusted_content).
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | Two-letter App Store storefront code, lowercase, e.g. 'us', 'gb', 'de'. |
| genre | – | – | App Store category name (e.g. 'photo_video', 'productivity', 'health') or numeric genre id; omit for all/inferred. |
| limit | integer | – | Number of chart entries to return (default 25). |
Structured output declared, but exposes no named fields.
No examples provided.
aso_unit_economics ASO Unit Economics ~228
Compute margin, break-even and warnings from prices, credits and AI cost (pure calculation, no network). Use when: idea/scaffold stage pricing decisions. Not for: measured-cost economics for a built app (use pricing_unit_economics). apple_cut is 0.15 for Small Business, else 0.30. Returns: {ok, weekly, yearly, margins, break_even, warnings}.
| Name | Type | Req | Description |
|---|---|---|---|
| ai_cost_per_credit | number | – | AI provider cost per credit in USD (default 0.003). |
| apple_cut | number | – | Apple's commission as a fraction: 0.15 (Small Business Program, default) or 0.30. |
| weekly_credits | integer | – | Credits per week on the weekly plan (default 10). |
| weekly_price | number | – | Weekly subscription price in USD (default 7.99). |
| yearly_monthly_credits | integer | – | Credits per month on the yearly plan (default 15). |
| yearly_price | number | – | Yearly subscription price in USD (default 49.99). |
Structured output declared, but exposes no named fields.
No examples provided.
aso_validate_metadata ASO Validate Metadata ~116
Validate outputs/<App>/02-metadata/apple-metadata.md (fields and character limits). Use when: checking ASO output by app name and base dir. For an arbitrary file use metadata_check; to mark the stage done use aso_complete. Returns: {ok, problems: [...]}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_name | string | yes | App name whose outputs/<app_name>/02-metadata/apple-metadata.md is validated. |
| base_dir | string | yes | Directory that contains (or will contain) the outputs/<App>/ folder. |
Structured output declared, but exposes no named fields.
No examples provided.
backend_deploy Backend Deploy ~222
Deploy the spec's Supabase backend: migrations, secrets, auth, legal build and edge functions (live unless dry_run; needs human approval). Use when: after backend_render. dry_run=true (default) returns the plan without any call. Not for: single SQL (supabase_run_sql) or one secret (supabase_set_secret). Returns: {ok, plan/steps, dry_run} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| dry_run | boolean | – | If true (default) nothing is changed or sent and the exact plan/command is returned; false performs the live action. |
| project_ref | string | yes | Supabase project ref to deploy to. |
Structured output declared, but exposes no named fields.
No examples provided.
backend_render Backend Render ~107
Render the scaffolded backend from app.spec.json (offline, idempotent): prune supabase/ to the monetization mode, generate shared config, legal sources and listing locales. Use when: after editing the spec, before backend_deploy. Nothing is deployed. Returns: {ok, mode, render, legal, listing?}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
Structured output declared, but exposes no named fields.
No examples provided.
build_archive Build Archive ~152
Run xcodebuild archive (generic iOS device) to produce a .xcarchive. Use when: manual signing pipeline steps. For the whole signed TestFlight flow use testflight_ship. Returns: {ok, exit_code, stdout, stderr} from xcodebuild.
| Name | Type | Req | Description |
|---|---|---|---|
| archive_path | string | yes | Path to the .xcarchive, e.g. build/App.xcarchive. |
| configuration | string | – | Xcode build configuration, default 'Release'. |
| project | string | yes | Path to the .xcodeproj or .xcworkspace to build, e.g. /path/App/App.xcodeproj. |
| scheme | string | yes | Xcode scheme name to build, e.g. 'MyApp'. |
Structured output declared, but exposes no named fields.
No examples provided.
build_boot_sim Build Boot Simulator ~93
Boot an iOS simulator and open Simulator.app. Use when: before capturing screenshots or running maestro_test. Idempotent if already booted. Returns: {ok, exit_code, stdout, stderr}, or {ok, note: 'already booted'}.
| Name | Type | Req | Description |
|---|---|---|---|
| udid | string | yes | Simulator UDID from build_list_simulators, e.g. 'A1B2C3D4-...'. |
Structured output declared, but exposes no named fields.
No examples provided.
build_export_ipa Build Export IPA ~130
Run xcodebuild -exportArchive to turn a .xcarchive into an .ipa. Use when: after build_archive with an ExportOptions.plist. For the whole flow use testflight_ship. Returns: {ok, exit_code, stdout, stderr} from xcodebuild.
| Name | Type | Req | Description |
|---|---|---|---|
| archive_path | string | yes | Path to the .xcarchive, e.g. build/App.xcarchive. |
| export_dir | string | yes | Directory to write the exported .ipa into. |
| export_options_plist | string | yes | Path to the ExportOptions.plist for xcodebuild -exportArchive. |
Structured output declared, but exposes no named fields.
No examples provided.
build_for_sim Build For Simulator ~134
Build the Xcode project for the simulator to verify it compiles. Use when: verifying code changes. Not for: signed/release builds (use build_archive or testflight_ship). Returns: {ok, exit_code, stdout, stderr} from xcodebuild.
| Name | Type | Req | Description |
|---|---|---|---|
| device_name | string | – | Simulator device name, e.g. 'iPhone 16'. |
| project | string | yes | Path to the .xcodeproj or .xcworkspace to build, e.g. /path/App/App.xcodeproj. |
| scheme | string | yes | Xcode scheme name to build, e.g. 'MyApp'. |
Structured output declared, but exposes no named fields.
No examples provided.
build_list_simulators Build List Simulators ~64
List the available iOS simulators, iPhones first. Use when: you need a udid for build_boot_sim, build_screenshot or screenshot_capture. Returns: {ok, count, simulators: [{name, udid, state, runtime}]}.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
build_screenshot Build Screenshot ~101
Capture a PNG screenshot of the booted simulator to out_path. Use when: an ad-hoc check. For localized store screenshots use screenshot_capture / screenshot_build_all. Returns: {ok, exit_code, stdout, stderr, path}.
| Name | Type | Req | Description |
|---|---|---|---|
| out_path | string | yes | Output file path (PNG). |
| udid | string | yes | Simulator UDID from build_list_simulators, e.g. 'A1B2C3D4-...'. |
Structured output declared, but exposes no named fields.
No examples provided.
build_test Build Test ~126
Run xcodebuild test for the scheme on a simulator. Use when: running unit/UI tests. For end-to-end Maestro flows use maestro_test. Returns: {ok, exit_code, stdout, stderr} from xcodebuild.
| Name | Type | Req | Description |
|---|---|---|---|
| device_name | string | – | Simulator device name, e.g. 'iPhone 16'. |
| project | string | yes | Path to the .xcodeproj or .xcworkspace to build, e.g. /path/App/App.xcodeproj. |
| scheme | string | yes | Xcode scheme name to build, e.g. 'MyApp'. |
Structured output declared, but exposes no named fields.
No examples provided.
build_xcode_version Build Xcode Version ~52
Return the installed Xcode version. Use when: a quick check that xcodebuild works before build_* tools. Returns: {ok, exit_code, stdout, stderr} (stdout holds the version lines).
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
config_doctor Config Doctor ~97
Report which config keys in ~/.appfactory/config.toml are present or missing (secrets masked). Use when: diagnosing ASC/Finance key paths, session state or CLI availability. Not for: overall setup guidance (use setup_status) or toolchain checks (use env_doctor). Returns: {ok, config_path, present, missing, locales, asc_p8_resolved, session, asc_cli, maestro, notes}.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
config_set Config Set ~299
Write several NON-secret settings (ASC key id/issuer/path, team id, copyright, support email, ...) to ~/.appfactory/config.toml. Use when: setting multiple ASC/identity fields together; fields left empty are unchanged. Not for: secrets (use setup_credentials) or one key (use setup_set). Returns: the config_doctor result after the update, or {ok: false, error} if a secret key was passed.
| Name | Type | Req | Description |
|---|---|---|---|
| apple_id | – | – | Apple ID email of the developer account (used by fastlane produce only). |
| asc_finance_key_filepath | – | – | Path to the Finance-role .p8 key file. |
| asc_finance_key_id | – | – | Key id of a Finance-role App Store Connect API key (for sales reports). |
| asc_issuer_id | – | – | App Store Connect API issuer id (UUID). |
| asc_key_filepath | – | – | Path to the App Store Connect .p8 private key file. |
| asc_key_id | – | – | App Store Connect API key id (10 characters). |
| asc_vendor_number | – | – | App Store Connect vendor number (sales reports). |
| copyright | – | – | Copyright line for the store listing, e.g. '2026 Example Ltd'; falls back to the config 'copyright' key. |
| legal_controller | – | – | Legal entity name shown as data controller in the privacy policy. |
| support_email | – | – | Public support email address. |
| team_id | – | – | Apple Developer Team id (10 characters). |
Structured output declared, but exposes no named fields.
No examples provided.
cpp_build_all CPP Build All ~177
Create one Custom Product Page per Search Ads theme (page, version, localization) and return the deep-link URLs (live write, needs human approval). Use when: after ASO produced theme clusters; the URLs feed Ad Ops. Returns: {ok, pages: [{theme, ok, id, version_id, localization_id, url}]} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| bundle_id | string | yes | App bundle identifier in reverse-DNS form, e.g. com.example.app. |
| themes | array | yes | List of {name, locale} Search Ads themes, one Custom Product Page each. |
Structured output declared, but exposes no named fields.
No examples provided.
deliver_metadata Deliver Metadata ~182
Upload metadata to the App Store Connect draft version through the API (live write, needs human approval, ASO-gated). Use when: metadata files are exported (metadata_export). Not for: screenshots (deliver_screenshots) or the submit step (asc_submit_for_review). Returns: {ok, uploaded: [...]} or a gate / approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| bundle_id | string | yes | App bundle identifier in reverse-DNS form, e.g. com.example.app. |
Structured output declared, but exposes no named fields.
No examples provided.
deliver_screenshots Deliver Screenshots ~180
Upload screenshots to the App Store Connect draft with checksum-based incremental sync (live write, needs human approval). Use when: screenshot_build_all is done; unchanged files (MD5 match) are skipped. To verify afterwards use deliver_screenshots_audit. Returns: {ok, uploaded, skipped} or a gate / approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| bundle_id | string | yes | App bundle identifier in reverse-DNS form, e.g. com.example.app. |
Structured output declared, but exposes no named fields.
No examples provided.
deliver_screenshots_audit Deliver Screenshots Audit ~128
Read-only audit that App Store Connect screenshot sets exactly match the local fastlane/screenshots files (order, COMPLETE state, MD5). Use when: after deliver_screenshots and before submission. No writes. Returns: {ok, locales: {locale: {display_type: status}}, previews, problems}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| bundle_id | string | yes | App bundle identifier in reverse-DNS form, e.g. com.example.app. |
Structured output declared, but exposes no named fields.
No examples provided.
What is the io.github.gbatistuta0/appfactory MCP server?
io.github.gbatistuta0/appfactory is an MCP server listed in the public MCP registry as io.github.gbatistuta0/appfactory. Lets your coding agent ship a SwiftUI iOS subscription app from idea to TestFlight. This page covers its PyPI package (appfactory).
Is the io.github.gbatistuta0/appfactory MCP server safe to use?
io.github.gbatistuta0/appfactory scores 75 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 4 October 2026. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.gbatistuta0/appfactory MCP server expose?
io.github.gbatistuta0/appfactory exposes 125 tools: setup_status, setup_services, setup_set, setup_approvals, setup_credentials, and 120 more. Their descriptions and schemas cost roughly 18,907 tokens of context every time the server is loaded.
Is the io.github.gbatistuta0/appfactory MCP server still maintained?
io.github.gbatistuta0/appfactory is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the io.github.gbatistuta0/appfactory MCP server under?
io.github.gbatistuta0/appfactory declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.