Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.gbatistuta0/appfactory

PYPI · APPFACTORY · SCANNED OCT 4

Lets your coding agent ship a SwiftUI iOS subscription app from idea to TestFlight.

Available components

75 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security100
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • Runs hatchling.build at install time, a recognised build step with no custom scripting around it. View diagnostics → Pass
  • 1 of 22 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency100
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to gbatistuta0/appfactory). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 4 days ago).Pass
  • Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability48
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • Instruction-quality not yet verified: the AI judgement didn't run.Unverified
  • Context-footprint check failed: tool/resource definitions use about 19176 tokens (~152/item across 126 items; 125 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety75
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • Manipulation not yet verified: only 2 of 127 captured unit(s) of tool text has been judged so far, so we will not certify text no model has read as clean.Unverified
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass

Unverified: 1 category

A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

Install

How do I install the io.github.gbatistuta0/appfactory MCP server?

io.github.gbatistuta0/appfactory runs locally as a PyPI package, launched with uvx appfactory. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

pypi · appfactory

# add to Claude Code
claude mcp add gbatistuta0-appfactory -- uvx appfactory
// .cursor/mcp.json
{
  "mcpServers": {
    "gbatistuta0-appfactory": {
      "command": "uvx",
      "args": [
        "appfactory"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "gbatistuta0-appfactory": {
      "command": "uvx",
      "args": [
        "appfactory"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add gbatistuta0-appfactory -- uvx appfactory
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "gbatistuta0-appfactory": {
      "type": "local",
      "command": [
        "uvx",
        "appfactory"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add gbatistuta0-appfactory --command uvx --arg appfactory
# ~/.hermes/config.yaml
mcp_servers:
  gbatistuta0-appfactory:
    command: "uvx"
    args: ["appfactory"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "gbatistuta0-appfactory": {
      "Transport": "stdio",
      "Command": "uvx",
      "Arguments": [
        "appfactory"
      ]
    }
  }
}
# add to Vellum
assistant mcp add gbatistuta0-appfactory -t stdio -c uvx -a appfactory
// mcp.json
{
  "mcpServers": {
    "gbatistuta0-appfactory": {
      "command": "uvx",
      "args": [
        "appfactory"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 30 Sept 26 +15
    • Malware scan: unverified → pass ▲ security
  • 29 Sept 26 60

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 6 Oct 2026 · Analysed pypi/appfactory@0.1.5

Provenance Verified

A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.

Result Verified
Ecosystem pypi
Reason Verified
Discovered via Registry attestation endpoint
Source repo gbatistuta0/appfactory
Certificate issuer https://token.actions.githubusercontent.com
Certificate SAN https://github.com/gbatistuta0/appfactory/.github/workflows/release.yml@refs/tags/v0.1.5
Rekor log index 3004333188
Predicate type PyPI publish attestation https://docs.pypi.org/attestations/publish/v1
Subject digest sha256:19e11c989976e965a51efa3cbc68c13783dfdc12d467cef474242976ecf7de2f

Background: How many MCP packages publish verified provenance →

Install scripts 1 script
Hook Tier Command
build_backend allowlisted hatchling.build

Background: Why install scripts are a supply-chain risk →

Dependencies 22 packages
Packages resolved 22
Stale 1
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 125 exposed · ~18,907 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
deliver_subscription_review_screenshots ~177

Upload the App Review screenshot of every subscription from store/review-screenshots/<product key>.png (live write, needs human approval). Use when: subscriptions sit in MISSING_METADATA for the review screenshot. Idempotent by MD5. Returns: {ok, uploaded, skipped} or an approval_required refusal.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
bundle_idstringyesApp bundle identifier in reverse-DNS form, e.g. com.example.app.

Structured output declared, but exposes no named fields.

No examples provided.

design_export_png ~200

Rasterize a Claude Design board to PNG with local headless Chrome. Use when: icon (B01-AppIcon 1024x1024 to design/icon.png) or store layout boards (440x956, scale 3). serve_url comes from claude-design render_preview and is used once. Returns: {ok, path, width, height}.

NameTypeReqDescription
heightintegeryesViewport height in CSS pixels, e.g. 1024 for the icon board or 956 for a store board.
out_pathstringyesOutput file path (PNG).
scaleinteger–Device scale factor (default 1; use 3 for store boards).
serve_urlstringyesTemporary serve_url from claude-design render_preview; used once, never stored.
widthintegeryesViewport width in CSS pixels, e.g. 1024 for the icon board or 440 for a store board.

Structured output declared, but exposes no named fields.

No examples provided.

design_generate ~111

Prepare the app's Claude Design project from the brief, spec and screens.json: scaffolds, mascot boards, canvas, store layout and upload plan. Use when: after design_research_check passes. Never uploads; it returns the claude-design MCP calls to make. Then record with design_record_upload. Returns: {ok, plan, mcp_calls}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.

Structured output declared, but exposes no named fields.

No examples provided.

design_record_upload ~142

Record a finished Claude Design upload: the SHA-256 of every file in upload_plan.json into design/project/claude_design.json. Use when: after uploading through the claude-design MCP; the design, icon and screenshot gates fail until this receipt matches. Returns: {ok, receipt path, files}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
open_urlstringyesThe claude.ai/design link returned by render_preview (not the serve_url).
project_idstringyesClaude Design project id from create_project.

Structured output declared, but exposes no named fields.

No examples provided.

design_research_brief_template ~90

Return the design/research/brief.json shape pre-filled with the reference ids. Use when: authoring the design brief after design_research_collect. Read-only. Returns: {ok, template, write_to: [paths]}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.

Structured output declared, but exposes no named fields.

No examples provided.

design_research_check ~83

Run the design_research gate: at least 6 reference apps on disk and a valid, cited brief. Use when: before design_generate. Read-only. Returns: {ok, problems: [...]}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.

Structured output declared, but exposes no named fields.

No examples provided.

design_research_collect ~204

Download category-leader App Store screenshots and icons into design/research/apps/ with references.json (study material only). Use when: first design step. Then write the brief (design_research_brief_template) and run design_research_check. Returns: {ok, apps: [{id, name, files}], references} (untrusted_content).

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
countries––List of two-letter storefront codes, e.g. ['us', 'gb', 'de']; omit for the default set.
max_appsinteger–Maximum reference apps to download (default 16).
screenshots_per_appinteger–Screenshots to download per reference app (default 6).
termsarrayyesSearch terms describing the app category, e.g. ['meditation', 'sleep sounds'].

Structured output declared, but exposes no named fields.

No examples provided.

design_screens_skeleton ~158

Produce the structural skeleton for design/screens.json, following the design brief's onboarding flow when one exists. Use when: starting design. Adapt every screen to the app; the look is authored in Claude Design. write=true saves it (refuses to replace an existing file unless overwrite). Returns: {ok, screens|path, onboarding, main}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
overwriteboolean–If true, replace files that already exist; default false refuses to overwrite.
writeboolean–If true, save the skeleton to design/screens.json; default false only returns it.

Structured output declared, but exposes no named fields.

No examples provided.

design_upload_status ~75

Check whether the local Claude Design project is uploaded and unchanged since (read-only). Use when: diagnosing a design gate failure. Returns: {ok, uploaded, changed_files}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.

Structured output declared, but exposes no named fields.

No examples provided.

env_doctor ~89

Check the local toolchain: xcode, swift, node, ruby, git, uv, asc, fastlane, maestro, Java 17+ and maestro- live. Use when: something fails to run locally. Not for: credentials/config (use config_doctor or setup_status). Returns: {ok, available: {tool: bool}, versions: {tool: str}, notes?}.

Input schema present but exposes no named parameters.

Structured output declared, but exposes no named fields.

No examples provided.

firebase_setup ~208

Set up Firebase Analytics: GCP project, iOS app and GoogleService-Info.plist into Resources/ (live write, needs human approval). Use when: once per app (mandatory for every app). Requires gcloud auth and firebase-tools. Returns: {ok, project_id, app_id, google_analytics, console, plist} or an approval_required refusal.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
app_namestringyesApp name as shown on the App Store (globally unique, max 30 characters).
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
bundle_idstringyesApp bundle identifier in reverse-DNS form, e.g. com.example.app.

Structured output declared, but exposes no named fields.

No examples provided.

github_create_repo ~211

Create a PRIVATE GitHub repo under the configured account and push the app (needs human approval unless dry_run). Use when: the app should be tracked on GitHub. dry_run=true (default) only returns the command. For later commits use github_push. Returns: {ok, command/url, dry_run} or an approval_required refusal.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
dry_runboolean–If true (default) nothing is changed or sent and the exact plan/command is returned; false performs the live action.
repo_namestringyesName of the new private repository, e.g. 'my-app'.

Structured output declared, but exposes no named fields.

No examples provided.

github_issue_create ~277

Open a GitHub issue for postponed work (needs human approval unless dry_run). Use when: parking work with a role label plus next or later. dry_run=true (default) returns the exact command. No-op (n/a) when the github_issues run option is off. Returns: {ok, url/command, dry_run} or an approval_required refusal.

NameTypeReqDescription
app_dir––App directory; when given, the github_issues run option is read from its spec.
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
bodystringyesIssue body with what / why / done-when sections.
dry_runboolean–If true (default) nothing is changed or sent and the exact plan/command is returned; false performs the live action.
labelsarrayyesIssue labels: one role label (ios, backend, store, lead, founder) plus next or later.
repostringyesGitHub repository as 'owner/name', e.g. 'octocat/my-app'.
titlestringyesIssue title in imperative form, e.g. 'Add offer paywall analytics'.

Structured output declared, but exposes no named fields.

No examples provided.

github_issues_bootstrap ~226

Create or refresh the GitHub label set (ios, backend, store, lead, founder, next, later, other-project) on a repo (needs human approval unless dry_run). Use when: before github_issue_create. dry_run=true (default) returns the commands. No-op (n/a) when the github_issues run option is off. Returns: {ok, commands/created, dry_run} or an approval_required refusal.

NameTypeReqDescription
app_dir––App directory; when given, the github_issues run option is read from its spec.
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
dry_runboolean–If true (default) nothing is changed or sent and the exact plan/command is returned; false performs the live action.
repostringyesGitHub repository as 'owner/name', e.g. 'octocat/my-app'.

Structured output declared, but exposes no named fields.

No examples provided.

github_push ~148

Commit all changes in the app repo and push (live write, needs human approval). Use when: regular tracking after milestones. For the first push of a new repo use github_create_repo. Returns: {ok, commit, push} or an approval_required refusal.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
messagestringyesGit commit message.

Structured output declared, but exposes no named fields.

No examples provided.

growth_build_slideshows ~162

Render viral TikTok/Reels slideshows (1080x1920 PNGs) to marketing/growth/<name>/NN.png. Use when: post-launch content only, after the app is submitted. You write the hooks and slide text; images come from the app's AI (fal). No scheduling. Returns: {ok, sets: [{name, slides, ok, dir}]}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
slideshowsarrayyesList of {name, slides: [{text, image_prompt or image, cta}]} to render at 1080x1920.

Structured output declared, but exposes no named fields.

No examples provided.

icon_generate ~184

Generate a fal.ai raster icon DRAFT into design/icon_drafts/ as reference for the Claude Design icon board (paid, opt-in only). Use when: the user explicitly allows an external generator. Never installs an icon; the shipped icon comes from Claude Design (icon_install). Returns: {ok, draft, prompt, next} or a refusal unless allow_external_generator is true.

NameTypeReqDescription
allow_external_generatorboolean–Must be true to allow the paid fal.ai image generator; default false refuses.
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
conceptstringyesShort concept description of the app used to write the image prompt, e.g. 'AI pet portrait maker'.
extrastring–Extra prompt text appended to the concept.

Structured output declared, but exposes no named fields.

No examples provided.

icon_install ~148

Install the Claude Design app icon (1024x1024 master) into AppIcon.appiconset and write .appfactory/verify/icon.json. Use when: after design_export_png produced design/icon.png and design_record_upload recorded the upload; the icon gate requires it. Alpha is flattened. Returns: {ok, icon, marker} or an error naming the missing/invalid master.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
sourcestring–Path to the 1024x1024 icon master, relative to the app dir (default 'design/icon.png').

Structured output declared, but exposes no named fields.

No examples provided.

idea_evaluate ~210

Build the evidence bundle to rank one idea in any category. Use when: comparing shortlisted ideas after idea_harvest. Not for: a quick score only (use aso_niche_score). Includes ai_needed and build_complexity heuristics for Claude to judge. Returns: {ok, autocomplete, niche, newcomers, leaders, ai_needed, build_complexity, review_risk, available_name} (untrusted_content).

NameTypeReqDescription
countrystring–Two-letter App Store storefront code, lowercase, e.g. 'us', 'gb', 'de'.
genre––App Store category name (e.g. 'photo_video', 'productivity', 'health') or numeric genre id; omit for all/inferred.
leadersinteger–Number of category leaders to profile with price ladders (default 3).
name_candidates––Candidate app names; the first available one is reported.
termstringyesSearch term or seed keyword, e.g. 'habit tracker'.

Structured output declared, but exposes no named fields.

No examples provided.

idea_harvest ~284

Sweep top-grossing and top-free charts across every App Store category and storefront to find proven and rising ideas. Use when: Phase 0 idea generation (about 1.5 minutes for the default sweep). Not for: evaluating one idea (use idea_evaluate) or a single chart (use aso_top_grossing). Failed feeds are listed, never read as no apps. Returns: {ok, chart_proven, rising_newcomers, clusters: [{genre, open_niche}], failed_feeds} (untrusted_content).

NameTypeReqDescription
countries––List of two-letter storefront codes, e.g. ['us', 'gb', 'de']; omit for the default set.
exclude_terms––Name/seller substrings to drop from results (e.g. your own apps).
feeds––Chart feeds to use, e.g. ['topgrossing', 'topfree']; omit for both.
genres––Category names to sweep, e.g. ['health', 'productivity']; omit for all 24 charted categories.
limitinteger–Chart entries fetched per genre and storefront (default 100).
max_resultsinteger–Maximum entries per result list (default 50).
newcomer_monthsinteger–Apps released within this many months count as rising newcomers (default 12).

Structured output declared, but exposes no named fields.

No examples provided.

legal_check ~86

List what still blocks publishing the legal pages: placeholders, unrendered blocks, missing languages. Use when: after legal_render, offline. For checking the live pages use legal_verify. Returns: {ok, problems: [...]}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.

Structured output declared, but exposes no named fields.

No examples provided.

legal_render ~109

Fill the legal sources (store/privacy/*.md, backend/PRIVACY.md) from the spec and config, keeping or dropping the HealthKit block. Use when: before legal_check. Local writes only. Returns: {ok, files, placeholders_left}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
values––Map of placeholder name to text for product-specific legal placeholders.

Structured output declared, but exposes no named fields.

No examples provided.

legal_verify ~109

Check that every deployed privacy/terms page answers 200 in each app language with the support email and no placeholder (live, read-only). Use when: after backend_deploy. Needs supabase_url in app outputs. For offline checks use legal_check. Returns: {ok, pages: [{locale, url, status, problems}]}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.

Structured output declared, but exposes no named fields.

No examples provided.

localize_apply ~121

Merge translations into the in-app String Catalog for the spec's app locales. Use when: after translating UI strings; locales not in spec locales.app are ignored. Not for: store listing copy (use metadata_render_listing / deliver_metadata). Returns: {ok, locales, keys, missing}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
translationsobjectyesMap {english_key: {locale: translated value}} for the String Catalog.

Structured output declared, but exposes no named fields.

No examples provided.

maestro_test ~186

Run the app's Maestro flows (.maestro/) on the booted simulator with the live Viewer, and write .appfactory/verify/maestro.json. Use when: verifying the app end to end; testflight_ship and the features gate require every smoke flow green. The app must already be installed (build_for_sim + simctl install). Opens the Viewer at http://localhost:7777; there is no headless mode. Returns: {ok, flows: [{name, passed}], report path}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
device––Simulator UDID to run on; omit for the booted simulator.
tags––Comma-separated Maestro tag filter, e.g. 'smoke'; omit to run every flow.

Structured output declared, but exposes no named fields.

No examples provided.

mascot_assets ~131

Import approved mascot poses and blink variants into Resources/Assets.xcassets/Mascot/. Use when: after mascot_blink; states without a pose borrow a fallback. Returns: {ok, imagesets: [names]}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
source_dir––Directory with approved pose PNGs; omit for <app>/design/mascot.
states––Mascot pose/state names, e.g. ['idle', 'happy']; omit for all states.

Structured output declared, but exposes no named fields.

No examples provided.

mascot_blink ~136

Create closed-eye blink copies (<state>-blink.png) of the approved mascot pose PNGs. Use when: before mascot_assets. Needs the optional extra `uv sync --extra mascot`. Returns: {ok, written: [paths]}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
paths––Explicit pose PNG paths; overrides the default <app>/design/mascot/<state>.png.
states––Mascot pose/state names, e.g. ['idle', 'happy']; omit for all states.

Structured output declared, but exposes no named fields.

No examples provided.

metadata_check ~81

Validate an apple-metadata.md file: required fields and character limits (no writes). Use when: checking a single metadata file. For the store listing.json use metadata_listing_check; for the ASO outputs folder use aso_validate_metadata. Returns: {ok, problems: [...], locales}.

NameTypeReqDescription
source_mdstringyesPath to apple-metadata.md.

Structured output declared, but exposes no named fields.

No examples provided.

metadata_export ~209

Export apple-metadata.md to fastlane/metadata/<locale>/*.txt after validation. Use when: preparing metadata for deliver_metadata. With app_dir set, refuses until the ASO stage is complete. Not for: uploading to App Store Connect (use deliver_metadata). Returns: {ok, written: [files], locales} or a gate refusal.

NameTypeReqDescription
app_dir––App directory; when given, export is refused until the ASO stage is complete.
dest_dirstringyesOutput directory for the per-locale .txt files, e.g. <app>/fastlane/metadata.
primary_category––Primary App Store category id, e.g. 'PHOTO_AND_VIDEO'.
privacy_url––Public privacy policy URL written to the metadata files.
secondary_category––Secondary App Store category id, e.g. 'PRODUCTIVITY'.
source_mdstringyesPath to apple-metadata.md to export.
support_url––Public support page URL.

Structured output declared, but exposes no named fields.

No examples provided.

metadata_listing_check ~93

Validate store/metadata/listing.json: length limits, keyword rules, no word overlap, subscription disclosure and legal links. Use when: before deliver_metadata. For a bare apple-metadata.md use metadata_check. Returns: {ok, problems: [...]}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.

Structured output declared, but exposes no named fields.

No examples provided.

metadata_render_listing ~94

Sync listing.json to the spec (store locales, IAP copy slots) and fill the legal URLs. Use when: after changing the spec's store locales or products. Local writes only; verify with metadata_listing_check. Returns: {ok, locales, changed}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.

Structured output declared, but exposes no named fields.

No examples provided.

onboarding_plan ~101

Return guidance for choosing the onboarding step count; does not change any file. Use when: deciding onboarding length with the user (quiz-style flow with about 5 personalization questions is the standard). Returns: {ok, step_count, ranges: {"8-10"|"11-13"|"14-15": description}, warning?}.

NameTypeReqDescription
step_countinteger–Desired number of onboarding steps; recommended range 8-15 (default 12).

Structured output declared, but exposes no named fields.

No examples provided.

orchestrator_needs_human ~155

Write NEEDS_HUMAN.md when self-correction is exhausted and return its path. Use when: a stage keeps failing and only the human can unblock it (stop the loop afterwards). Returns: {ok, path}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
how_to_resolvestringyesWhat the human needs to do to unblock the stage.
reasonstringyesWhy self-correction is exhausted (what failed).
stagestringyesPipeline stage id, e.g. 'aso', 'screenshots', 'features' (see pipeline_status for the list).

Structured output declared, but exposes no named fields.

No examples provided.

orchestrator_next_action ~132

Return the next action for the autonomous driver loop: stage, subagent role, retry budget and instructions. Use when: running unattended. done=true means the pipeline is finished (submit still needs human approval). For a manual step use pipeline_next. Returns: {ok, done, stage, role, attempts_left, instructions}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
skip_options_checkboolean–If true, do not require run_options_save to have been called first. Default false.

Structured output declared, but exposes no named fields.

No examples provided.

orchestrator_preflight ~122

Pre-flight for an autonomous run: run options confirmed, config keys present, fastlane session fresh, caffeinate command. Use when: before starting the orchestrator_next_action loop. Ready when blockers is empty. Returns setup_required first if AppFactory is not set up. Returns: {ok, blockers: [...], caffeinate, ...}.

NameTypeReqDescription
app_dir––App directory; omit before the app is scaffolded.
skip_options_checkboolean–If true, do not require run_options_save to have been called first. Default false.

Structured output declared, but exposes no named fields.

No examples provided.

orchestrator_record_attempt ~123

Count one failed attempt of a stage after a gate failure. Use when: a stage gate failed in the autonomous loop; escalate with orchestrator_needs_human when should_retry is false. Returns: {ok, stage, attempts, should_retry}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
stagestringyesPipeline stage id, e.g. 'aso', 'screenshots', 'features' (see pipeline_status for the list).

Structured output declared, but exposes no named fields.

No examples provided.

pipeline_mark ~150

Set a pipeline stage's status (done, in_progress, pending) in the app manifest. Use when: recording progress. Marking done runs the stage's enforced gate. To only test the gate use pipeline_validate. Returns: {ok, stage, status} or a gate refusal.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
stagestringyesPipeline stage id, e.g. 'aso', 'screenshots', 'features' (see pipeline_status for the list).
statusstring–New stage status: 'done', 'in_progress' or 'pending'.

Structured output declared, but exposes no named fields.

No examples provided.

pipeline_next ~140

Return the next mandatory pipeline step with its instructions. Use when: driving the pipeline manually. Refuses until run options are confirmed (run_options, run_options_save) unless skip_options_check. Not for: the autonomous loop with retry budgets (use orchestrator_next_action). Returns: {ok, stage, instructions} or setup_required / options-not-confirmed errors.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
skip_options_checkboolean–If true, do not require run_options_save to have been called first. Default false.

Structured output declared, but exposes no named fields.

No examples provided.

pipeline_status ~95

Show which pipeline stages are done or pending and what comes next. Use when: checking progress of one app. To get the next instructions use pipeline_next; for the autonomous loop use orchestrator_next_action. Returns: {ok, stages: {stage: status}, next}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.

Structured output declared, but exposes no named fields.

No examples provided.

pipeline_validate ~107

Run a stage's enforced gate without modifying the manifest. Use when: self-checking before pipeline_mark(done). Read-only. Returns: {ok, stage, problems: [...]}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
stagestringyesPipeline stage id, e.g. 'aso', 'screenshots', 'features' (see pipeline_status for the list).

Structured output declared, but exposes no named fields.

No examples provided.

playbook ~50

Return the AppFactory run playbook as markdown. Use when: before driving the pipeline; the same text is the `run` prompt and the appfactory://playbook resource. Returns: markdown string.

Input schema present but exposes no named parameters.

NameTypeReqDescription
resultstringyes–

No examples provided.

preview_brief ~148

Write marketing/preview/BRIEF.md (the HyperFrames App Preview brief) from app.spec.json and create the recordings folders. Use when: starting the App Preview video. Then record the real app and author the video with the hyperframes skill (real footage only). Check with preview_check. Returns: {ok, brief path, recordings dirs}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
messagestring–Optional extra direction appended to the brief.
overwriteboolean–If true, replace files that already exist; default false refuses to overwrite.

Structured output declared, but exposes no named fields.

No examples provided.

preview_check ~116

Check offline readiness of the App Preview set: brief, recordings, one preview per locale, ffprobe specs, self-review status. Use when: before preview_upload. Files must be 886x1920, <=30 fps, H.264, 15-30 s, <=500 MB, stereo AAC or silent. Returns: {ok, problems: [...], plan}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.

Structured output declared, but exposes no named fields.

No examples provided.

preview_review_log ~194

Log one self-review round (scores 1-10 and worst problems) for a final preview file. Use when: after preview_review_sheets. Every score must reach 8+ on the exact final file (MD5-matched) or preview_upload and the gate refuse. Returns: {ok, passed, scores, problems}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
filestringyesPreview file path relative to the app dir, e.g. 'fastlane/app_previews/en-US/preview.mp4'.
problems––Up to 3 worst problems as [{t: seconds, issue: text}]; required while any score is under 8.
scoresobjectyesScores 1-10 for keys hook, readability, motion, variety, brand, music.

Structured output declared, but exposes no named fields.

No examples provided.

preview_review_sheets ~101

Generate self-review material (contact sheet, phone-size sheet, transition strip) for every final preview with ffmpeg. Use when: reviewing a rendered preview; open the sheets, score them, then call preview_review_log. Returns: {ok, sheets: {locale: [paths]}}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.

Structured output declared, but exposes no named fields.

No examples provided.

preview_upload ~242

Upload fastlane/app_previews/<locale>/ to the editable version's iPhone preview sets via the asc CLI (needs human approval unless dry_run). Use when: preview_check is clean and self-review passed. dry_run=true (default) sends nothing. MD5-idempotent; refuses while preview_check has problems. Returns: {ok, uploaded/planned: [...], dry_run} or an approval_required refusal.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
dry_runboolean–If true (default) nothing is changed or sent and the exact plan/command is returned; false performs the live action.
locales––Locale codes to upload; omit for every locale in fastlane/app_previews/.
replaceboolean–If true, replace preview sets that already exist on App Store Connect.

Structured output declared, but exposes no named fields.

No examples provided.

pricing_unit_economics ~188

Compute unit economics from the measured AI cost per call and usage profiles, and write the generated blocks of store/pricing.md. Use when: pricing a built app with real eval data. For quick what-if numbers at idea stage use aso_unit_economics. Returns: {ok, products: [{margin, ...}], path}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
apple_cutnumber–Apple's commission as a fraction: 0.15 (Small Business Program, default) or 0.30.
cost_photo––Measured AI cost in USD per photo call; omit to read from backend/eval/results.
cost_text––Measured AI cost in USD per text call; omit to read from backend/eval/results.

Structured output declared, but exposes no named fields.

No examples provided.

revenuecat_setup ~269

Idempotently set up the RevenueCat v2 project: premium entitlement, subscription attachments, SDK key and Supabase secret (live write, needs human approval). Use when: after a human created the RC project, linked ASC and supplied the v2 key. Returns NEEDS_HUMAN if no project exists. For ASC plus RC in one pass use store_setup. Returns: {ok, entitlement, sdk_key_set, secrets} or an approval_required refusal.

NameTypeReqDescription
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
bundle_idstringyesApp bundle identifier in reverse-DNS form, e.g. com.example.app.
env_suffixstring–Suffix for secret names when several apps share one Supabase project, e.g. '_MYAPP'.
set_secretsboolean–If true (default) also write the RevenueCat secrets to Supabase.
supabase_refstringyesSupabase project ref that receives the RevenueCat secrets.
v2_keystringyesRevenueCat secret API v2 key (sk_...); used for this call only.

Structured output declared, but exposes no named fields.

No examples provided.

run_options ~107

List every optional part of a run with its question, kind, choices, default and current value. Use when: BEFORE any other work when the user says run. Ask the user each question one at a time (or as a checklist), then call run_options_save. Returns: {ok, options: [{id, question, kind, choices, default, value}], confirmed}.

NameTypeReqDescription
app_dir––App directory to read current values from; omit before the app is scaffolded.

Structured output declared, but exposes no named fields.

No examples provided.

run_options_save ~126

Save the user's answers to the run options and mark options confirmed. Use when: after asking every question from run_options. Validates types, choices and dependencies; services go to config.toml, the rest to app.spec.json (or a pending file that app_scaffold applies). Returns: {ok, saved, errors?}.

NameTypeReqDescription
answersobjectyesMap {option id: value} covering every option id returned by run_options.
app_dir––App directory whose app.spec.json receives the answers; omit to save to the pending file used by app_scaffold.

Structured output declared, but exposes no named fields.

No examples provided.

Common questions

What is the io.github.gbatistuta0/appfactory MCP server?

io.github.gbatistuta0/appfactory is an MCP server listed in the public MCP registry as io.github.gbatistuta0/appfactory. Lets your coding agent ship a SwiftUI iOS subscription app from idea to TestFlight. This page covers its PyPI package (appfactory).

Is the io.github.gbatistuta0/appfactory MCP server safe to use?

io.github.gbatistuta0/appfactory scores 75 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 4 October 2026. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.github.gbatistuta0/appfactory MCP server expose?

io.github.gbatistuta0/appfactory exposes 125 tools: setup_status, setup_services, setup_set, setup_approvals, setup_credentials, and 120 more. Their descriptions and schemas cost roughly 18,907 tokens of context every time the server is loaded.

Is the io.github.gbatistuta0/appfactory MCP server still maintained?

io.github.gbatistuta0/appfactory is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the io.github.gbatistuta0/appfactory MCP server under?

io.github.gbatistuta0/appfactory declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.