io.github.gbatistuta0/appfactory
PYPI · APPFACTORY · SCANNED OCT 4
Lets your coding agent ship a SwiftUI iOS subscription app from idea to TestFlight.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security100
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- Runs hatchling.build at install time, a recognised build step with no custom scripting around it. View diagnostics → Pass
- 1 of 22 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency100
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to gbatistuta0/appfactory). View diagnostics → Pass
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 4 days ago).Pass
- Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability48
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- Instruction-quality not yet verified: the AI judgement didn't run.Unverified
- Context-footprint check failed: tool/resource definitions use about 19176 tokens (~152/item across 126 items; 125 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- Manipulation not yet verified: only 2 of 127 captured unit(s) of tool text has been judged so far, so we will not certify text no model has read as clean.Unverified
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
Unverified: 1 category
A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.
How do I install the io.github.gbatistuta0/appfactory MCP server?
io.github.gbatistuta0/appfactory runs locally as a PyPI package, launched with uvx appfactory. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
pypi · appfactory
claude mcp add gbatistuta0-appfactory -- uvx appfactory
{
"mcpServers": {
"gbatistuta0-appfactory": {
"command": "uvx",
"args": [
"appfactory"
]
}
}
} {
"servers": {
"gbatistuta0-appfactory": {
"command": "uvx",
"args": [
"appfactory"
]
}
}
} codex mcp add gbatistuta0-appfactory -- uvx appfactory
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"gbatistuta0-appfactory": {
"type": "local",
"command": [
"uvx",
"appfactory"
],
"enabled": true
}
}
} openclaw mcp add gbatistuta0-appfactory --command uvx --arg appfactory
mcp_servers:
gbatistuta0-appfactory:
command: "uvx"
args: ["appfactory"] {
"McpServers": {
"gbatistuta0-appfactory": {
"Transport": "stdio",
"Command": "uvx",
"Arguments": [
"appfactory"
]
}
}
} assistant mcp add gbatistuta0-appfactory -t stdio -c uvx -a appfactory
{
"mcpServers": {
"gbatistuta0-appfactory": {
"command": "uvx",
"args": [
"appfactory"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 30 Sept 26 +15
- Malware scan: unverified → pass ▲ security
- 29 Sept 26 60
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 6 Oct 2026 · Analysed pypi/appfactory@0.1.5
Provenance Verified
A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.
| Result | Verified |
|---|---|
| Ecosystem | pypi |
| Reason | Verified |
| Discovered via | Registry attestation endpoint |
| Source repo | gbatistuta0/appfactory |
| Certificate issuer | https://token.actions.githubusercontent.com |
| Certificate SAN | https://github.com/gbatistuta0/appfactory/.github/workflows/release.yml@refs/tags/v0.1.5 |
| Rekor log index | 3004333188 |
| Predicate type | PyPI publish attestation https://docs.pypi.org/attestations/publish/v1 |
| Subject digest | sha256:19e11c989976e965a51efa3cbc68c13783dfdc12d467cef474242976ecf7de2f |
Background: How many MCP packages publish verified provenance →
Install scripts 1 script
| Hook | Tier | Command |
|---|---|---|
| build_backend | allowlisted | hatchling.build |
Background: Why install scripts are a supply-chain risk →
Dependencies 22 packages
| Packages resolved | 22 |
|---|---|
| Stale | 1 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
deliver_subscription_review_screenshots Deliver Subscription Review Screenshots ~177
Upload the App Review screenshot of every subscription from store/review-screenshots/<product key>.png (live write, needs human approval). Use when: subscriptions sit in MISSING_METADATA for the review screenshot. Idempotent by MD5. Returns: {ok, uploaded, skipped} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| bundle_id | string | yes | App bundle identifier in reverse-DNS form, e.g. com.example.app. |
Structured output declared, but exposes no named fields.
No examples provided.
design_export_png Design Export PNG ~200
Rasterize a Claude Design board to PNG with local headless Chrome. Use when: icon (B01-AppIcon 1024x1024 to design/icon.png) or store layout boards (440x956, scale 3). serve_url comes from claude-design render_preview and is used once. Returns: {ok, path, width, height}.
| Name | Type | Req | Description |
|---|---|---|---|
| height | integer | yes | Viewport height in CSS pixels, e.g. 1024 for the icon board or 956 for a store board. |
| out_path | string | yes | Output file path (PNG). |
| scale | integer | – | Device scale factor (default 1; use 3 for store boards). |
| serve_url | string | yes | Temporary serve_url from claude-design render_preview; used once, never stored. |
| width | integer | yes | Viewport width in CSS pixels, e.g. 1024 for the icon board or 440 for a store board. |
Structured output declared, but exposes no named fields.
No examples provided.
design_generate Design Generate ~111
Prepare the app's Claude Design project from the brief, spec and screens.json: scaffolds, mascot boards, canvas, store layout and upload plan. Use when: after design_research_check passes. Never uploads; it returns the claude-design MCP calls to make. Then record with design_record_upload. Returns: {ok, plan, mcp_calls}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
Structured output declared, but exposes no named fields.
No examples provided.
design_record_upload Design Record Upload ~142
Record a finished Claude Design upload: the SHA-256 of every file in upload_plan.json into design/project/claude_design.json. Use when: after uploading through the claude-design MCP; the design, icon and screenshot gates fail until this receipt matches. Returns: {ok, receipt path, files}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| open_url | string | yes | The claude.ai/design link returned by render_preview (not the serve_url). |
| project_id | string | yes | Claude Design project id from create_project. |
Structured output declared, but exposes no named fields.
No examples provided.
design_research_brief_template Design Research Brief Template ~90
Return the design/research/brief.json shape pre-filled with the reference ids. Use when: authoring the design brief after design_research_collect. Read-only. Returns: {ok, template, write_to: [paths]}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
Structured output declared, but exposes no named fields.
No examples provided.
design_research_check Design Research Check ~83
Run the design_research gate: at least 6 reference apps on disk and a valid, cited brief. Use when: before design_generate. Read-only. Returns: {ok, problems: [...]}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
Structured output declared, but exposes no named fields.
No examples provided.
design_research_collect Design Research Collect ~204
Download category-leader App Store screenshots and icons into design/research/apps/ with references.json (study material only). Use when: first design step. Then write the brief (design_research_brief_template) and run design_research_check. Returns: {ok, apps: [{id, name, files}], references} (untrusted_content).
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| countries | – | – | List of two-letter storefront codes, e.g. ['us', 'gb', 'de']; omit for the default set. |
| max_apps | integer | – | Maximum reference apps to download (default 16). |
| screenshots_per_app | integer | – | Screenshots to download per reference app (default 6). |
| terms | array | yes | Search terms describing the app category, e.g. ['meditation', 'sleep sounds']. |
Structured output declared, but exposes no named fields.
No examples provided.
design_screens_skeleton Design Screens Skeleton ~158
Produce the structural skeleton for design/screens.json, following the design brief's onboarding flow when one exists. Use when: starting design. Adapt every screen to the app; the look is authored in Claude Design. write=true saves it (refuses to replace an existing file unless overwrite). Returns: {ok, screens|path, onboarding, main}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| overwrite | boolean | – | If true, replace files that already exist; default false refuses to overwrite. |
| write | boolean | – | If true, save the skeleton to design/screens.json; default false only returns it. |
Structured output declared, but exposes no named fields.
No examples provided.
design_upload_status Design Upload Status ~75
Check whether the local Claude Design project is uploaded and unchanged since (read-only). Use when: diagnosing a design gate failure. Returns: {ok, uploaded, changed_files}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
Structured output declared, but exposes no named fields.
No examples provided.
env_doctor Environment Doctor ~89
Check the local toolchain: xcode, swift, node, ruby, git, uv, asc, fastlane, maestro, Java 17+ and maestro- live. Use when: something fails to run locally. Not for: credentials/config (use config_doctor or setup_status). Returns: {ok, available: {tool: bool}, versions: {tool: str}, notes?}.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
firebase_setup Firebase Setup ~208
Set up Firebase Analytics: GCP project, iOS app and GoogleService-Info.plist into Resources/ (live write, needs human approval). Use when: once per app (mandatory for every app). Requires gcloud auth and firebase-tools. Returns: {ok, project_id, app_id, google_analytics, console, plist} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| app_name | string | yes | App name as shown on the App Store (globally unique, max 30 characters). |
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| bundle_id | string | yes | App bundle identifier in reverse-DNS form, e.g. com.example.app. |
Structured output declared, but exposes no named fields.
No examples provided.
github_create_repo GitHub Create Repo ~211
Create a PRIVATE GitHub repo under the configured account and push the app (needs human approval unless dry_run). Use when: the app should be tracked on GitHub. dry_run=true (default) only returns the command. For later commits use github_push. Returns: {ok, command/url, dry_run} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| dry_run | boolean | – | If true (default) nothing is changed or sent and the exact plan/command is returned; false performs the live action. |
| repo_name | string | yes | Name of the new private repository, e.g. 'my-app'. |
Structured output declared, but exposes no named fields.
No examples provided.
github_issue_create GitHub Issue Create ~277
Open a GitHub issue for postponed work (needs human approval unless dry_run). Use when: parking work with a role label plus next or later. dry_run=true (default) returns the exact command. No-op (n/a) when the github_issues run option is off. Returns: {ok, url/command, dry_run} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | – | – | App directory; when given, the github_issues run option is read from its spec. |
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| body | string | yes | Issue body with what / why / done-when sections. |
| dry_run | boolean | – | If true (default) nothing is changed or sent and the exact plan/command is returned; false performs the live action. |
| labels | array | yes | Issue labels: one role label (ios, backend, store, lead, founder) plus next or later. |
| repo | string | yes | GitHub repository as 'owner/name', e.g. 'octocat/my-app'. |
| title | string | yes | Issue title in imperative form, e.g. 'Add offer paywall analytics'. |
Structured output declared, but exposes no named fields.
No examples provided.
github_issues_bootstrap GitHub Issues Bootstrap ~226
Create or refresh the GitHub label set (ios, backend, store, lead, founder, next, later, other-project) on a repo (needs human approval unless dry_run). Use when: before github_issue_create. dry_run=true (default) returns the commands. No-op (n/a) when the github_issues run option is off. Returns: {ok, commands/created, dry_run} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | – | – | App directory; when given, the github_issues run option is read from its spec. |
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| dry_run | boolean | – | If true (default) nothing is changed or sent and the exact plan/command is returned; false performs the live action. |
| repo | string | yes | GitHub repository as 'owner/name', e.g. 'octocat/my-app'. |
Structured output declared, but exposes no named fields.
No examples provided.
github_push GitHub Push ~148
Commit all changes in the app repo and push (live write, needs human approval). Use when: regular tracking after milestones. For the first push of a new repo use github_create_repo. Returns: {ok, commit, push} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| message | string | yes | Git commit message. |
Structured output declared, but exposes no named fields.
No examples provided.
growth_build_slideshows Growth Build Slideshows ~162
Render viral TikTok/Reels slideshows (1080x1920 PNGs) to marketing/growth/<name>/NN.png. Use when: post-launch content only, after the app is submitted. You write the hooks and slide text; images come from the app's AI (fal). No scheduling. Returns: {ok, sets: [{name, slides, ok, dir}]}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| slideshows | array | yes | List of {name, slides: [{text, image_prompt or image, cta}]} to render at 1080x1920. |
Structured output declared, but exposes no named fields.
No examples provided.
icon_generate Icon Generate ~184
Generate a fal.ai raster icon DRAFT into design/icon_drafts/ as reference for the Claude Design icon board (paid, opt-in only). Use when: the user explicitly allows an external generator. Never installs an icon; the shipped icon comes from Claude Design (icon_install). Returns: {ok, draft, prompt, next} or a refusal unless allow_external_generator is true.
| Name | Type | Req | Description |
|---|---|---|---|
| allow_external_generator | boolean | – | Must be true to allow the paid fal.ai image generator; default false refuses. |
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| concept | string | yes | Short concept description of the app used to write the image prompt, e.g. 'AI pet portrait maker'. |
| extra | string | – | Extra prompt text appended to the concept. |
Structured output declared, but exposes no named fields.
No examples provided.
icon_install Icon Install ~148
Install the Claude Design app icon (1024x1024 master) into AppIcon.appiconset and write .appfactory/verify/icon.json. Use when: after design_export_png produced design/icon.png and design_record_upload recorded the upload; the icon gate requires it. Alpha is flattened. Returns: {ok, icon, marker} or an error naming the missing/invalid master.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| source | string | – | Path to the 1024x1024 icon master, relative to the app dir (default 'design/icon.png'). |
Structured output declared, but exposes no named fields.
No examples provided.
idea_evaluate Idea Evaluate ~210
Build the evidence bundle to rank one idea in any category. Use when: comparing shortlisted ideas after idea_harvest. Not for: a quick score only (use aso_niche_score). Includes ai_needed and build_complexity heuristics for Claude to judge. Returns: {ok, autocomplete, niche, newcomers, leaders, ai_needed, build_complexity, review_risk, available_name} (untrusted_content).
| Name | Type | Req | Description |
|---|---|---|---|
| country | string | – | Two-letter App Store storefront code, lowercase, e.g. 'us', 'gb', 'de'. |
| genre | – | – | App Store category name (e.g. 'photo_video', 'productivity', 'health') or numeric genre id; omit for all/inferred. |
| leaders | integer | – | Number of category leaders to profile with price ladders (default 3). |
| name_candidates | – | – | Candidate app names; the first available one is reported. |
| term | string | yes | Search term or seed keyword, e.g. 'habit tracker'. |
Structured output declared, but exposes no named fields.
No examples provided.
idea_harvest Idea Harvest ~284
Sweep top-grossing and top-free charts across every App Store category and storefront to find proven and rising ideas. Use when: Phase 0 idea generation (about 1.5 minutes for the default sweep). Not for: evaluating one idea (use idea_evaluate) or a single chart (use aso_top_grossing). Failed feeds are listed, never read as no apps. Returns: {ok, chart_proven, rising_newcomers, clusters: [{genre, open_niche}], failed_feeds} (untrusted_content).
| Name | Type | Req | Description |
|---|---|---|---|
| countries | – | – | List of two-letter storefront codes, e.g. ['us', 'gb', 'de']; omit for the default set. |
| exclude_terms | – | – | Name/seller substrings to drop from results (e.g. your own apps). |
| feeds | – | – | Chart feeds to use, e.g. ['topgrossing', 'topfree']; omit for both. |
| genres | – | – | Category names to sweep, e.g. ['health', 'productivity']; omit for all 24 charted categories. |
| limit | integer | – | Chart entries fetched per genre and storefront (default 100). |
| max_results | integer | – | Maximum entries per result list (default 50). |
| newcomer_months | integer | – | Apps released within this many months count as rising newcomers (default 12). |
Structured output declared, but exposes no named fields.
No examples provided.
legal_check Legal Check ~86
List what still blocks publishing the legal pages: placeholders, unrendered blocks, missing languages. Use when: after legal_render, offline. For checking the live pages use legal_verify. Returns: {ok, problems: [...]}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
Structured output declared, but exposes no named fields.
No examples provided.
legal_render Legal Render ~109
Fill the legal sources (store/privacy/*.md, backend/PRIVACY.md) from the spec and config, keeping or dropping the HealthKit block. Use when: before legal_check. Local writes only. Returns: {ok, files, placeholders_left}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| values | – | – | Map of placeholder name to text for product-specific legal placeholders. |
Structured output declared, but exposes no named fields.
No examples provided.
legal_verify Legal Verify ~109
Check that every deployed privacy/terms page answers 200 in each app language with the support email and no placeholder (live, read-only). Use when: after backend_deploy. Needs supabase_url in app outputs. For offline checks use legal_check. Returns: {ok, pages: [{locale, url, status, problems}]}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
Structured output declared, but exposes no named fields.
No examples provided.
localize_apply Localize Apply ~121
Merge translations into the in-app String Catalog for the spec's app locales. Use when: after translating UI strings; locales not in spec locales.app are ignored. Not for: store listing copy (use metadata_render_listing / deliver_metadata). Returns: {ok, locales, keys, missing}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| translations | object | yes | Map {english_key: {locale: translated value}} for the String Catalog. |
Structured output declared, but exposes no named fields.
No examples provided.
maestro_test Maestro Test ~186
Run the app's Maestro flows (.maestro/) on the booted simulator with the live Viewer, and write .appfactory/verify/maestro.json. Use when: verifying the app end to end; testflight_ship and the features gate require every smoke flow green. The app must already be installed (build_for_sim + simctl install). Opens the Viewer at http://localhost:7777; there is no headless mode. Returns: {ok, flows: [{name, passed}], report path}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| device | – | – | Simulator UDID to run on; omit for the booted simulator. |
| tags | – | – | Comma-separated Maestro tag filter, e.g. 'smoke'; omit to run every flow. |
Structured output declared, but exposes no named fields.
No examples provided.
mascot_assets Mascot Assets ~131
Import approved mascot poses and blink variants into Resources/Assets.xcassets/Mascot/. Use when: after mascot_blink; states without a pose borrow a fallback. Returns: {ok, imagesets: [names]}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| source_dir | – | – | Directory with approved pose PNGs; omit for <app>/design/mascot. |
| states | – | – | Mascot pose/state names, e.g. ['idle', 'happy']; omit for all states. |
Structured output declared, but exposes no named fields.
No examples provided.
mascot_blink Mascot Blink ~136
Create closed-eye blink copies (<state>-blink.png) of the approved mascot pose PNGs. Use when: before mascot_assets. Needs the optional extra `uv sync --extra mascot`. Returns: {ok, written: [paths]}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| paths | – | – | Explicit pose PNG paths; overrides the default <app>/design/mascot/<state>.png. |
| states | – | – | Mascot pose/state names, e.g. ['idle', 'happy']; omit for all states. |
Structured output declared, but exposes no named fields.
No examples provided.
metadata_check Metadata Check ~81
Validate an apple-metadata.md file: required fields and character limits (no writes). Use when: checking a single metadata file. For the store listing.json use metadata_listing_check; for the ASO outputs folder use aso_validate_metadata. Returns: {ok, problems: [...], locales}.
| Name | Type | Req | Description |
|---|---|---|---|
| source_md | string | yes | Path to apple-metadata.md. |
Structured output declared, but exposes no named fields.
No examples provided.
metadata_export Metadata Export ~209
Export apple-metadata.md to fastlane/metadata/<locale>/*.txt after validation. Use when: preparing metadata for deliver_metadata. With app_dir set, refuses until the ASO stage is complete. Not for: uploading to App Store Connect (use deliver_metadata). Returns: {ok, written: [files], locales} or a gate refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | – | – | App directory; when given, export is refused until the ASO stage is complete. |
| dest_dir | string | yes | Output directory for the per-locale .txt files, e.g. <app>/fastlane/metadata. |
| primary_category | – | – | Primary App Store category id, e.g. 'PHOTO_AND_VIDEO'. |
| privacy_url | – | – | Public privacy policy URL written to the metadata files. |
| secondary_category | – | – | Secondary App Store category id, e.g. 'PRODUCTIVITY'. |
| source_md | string | yes | Path to apple-metadata.md to export. |
| support_url | – | – | Public support page URL. |
Structured output declared, but exposes no named fields.
No examples provided.
metadata_listing_check Metadata Listing Check ~93
Validate store/metadata/listing.json: length limits, keyword rules, no word overlap, subscription disclosure and legal links. Use when: before deliver_metadata. For a bare apple-metadata.md use metadata_check. Returns: {ok, problems: [...]}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
Structured output declared, but exposes no named fields.
No examples provided.
metadata_render_listing Metadata Render Listing ~94
Sync listing.json to the spec (store locales, IAP copy slots) and fill the legal URLs. Use when: after changing the spec's store locales or products. Local writes only; verify with metadata_listing_check. Returns: {ok, locales, changed}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
Structured output declared, but exposes no named fields.
No examples provided.
onboarding_plan Onboarding Plan ~101
Return guidance for choosing the onboarding step count; does not change any file. Use when: deciding onboarding length with the user (quiz-style flow with about 5 personalization questions is the standard). Returns: {ok, step_count, ranges: {"8-10"|"11-13"|"14-15": description}, warning?}.
| Name | Type | Req | Description |
|---|---|---|---|
| step_count | integer | – | Desired number of onboarding steps; recommended range 8-15 (default 12). |
Structured output declared, but exposes no named fields.
No examples provided.
orchestrator_needs_human Orchestrator Needs Human ~155
Write NEEDS_HUMAN.md when self-correction is exhausted and return its path. Use when: a stage keeps failing and only the human can unblock it (stop the loop afterwards). Returns: {ok, path}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| how_to_resolve | string | yes | What the human needs to do to unblock the stage. |
| reason | string | yes | Why self-correction is exhausted (what failed). |
| stage | string | yes | Pipeline stage id, e.g. 'aso', 'screenshots', 'features' (see pipeline_status for the list). |
Structured output declared, but exposes no named fields.
No examples provided.
orchestrator_next_action Orchestrator Next Action ~132
Return the next action for the autonomous driver loop: stage, subagent role, retry budget and instructions. Use when: running unattended. done=true means the pipeline is finished (submit still needs human approval). For a manual step use pipeline_next. Returns: {ok, done, stage, role, attempts_left, instructions}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| skip_options_check | boolean | – | If true, do not require run_options_save to have been called first. Default false. |
Structured output declared, but exposes no named fields.
No examples provided.
orchestrator_preflight Orchestrator Preflight ~122
Pre-flight for an autonomous run: run options confirmed, config keys present, fastlane session fresh, caffeinate command. Use when: before starting the orchestrator_next_action loop. Ready when blockers is empty. Returns setup_required first if AppFactory is not set up. Returns: {ok, blockers: [...], caffeinate, ...}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | – | – | App directory; omit before the app is scaffolded. |
| skip_options_check | boolean | – | If true, do not require run_options_save to have been called first. Default false. |
Structured output declared, but exposes no named fields.
No examples provided.
orchestrator_record_attempt Orchestrator Record Attempt ~123
Count one failed attempt of a stage after a gate failure. Use when: a stage gate failed in the autonomous loop; escalate with orchestrator_needs_human when should_retry is false. Returns: {ok, stage, attempts, should_retry}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| stage | string | yes | Pipeline stage id, e.g. 'aso', 'screenshots', 'features' (see pipeline_status for the list). |
Structured output declared, but exposes no named fields.
No examples provided.
pipeline_mark Pipeline Mark ~150
Set a pipeline stage's status (done, in_progress, pending) in the app manifest. Use when: recording progress. Marking done runs the stage's enforced gate. To only test the gate use pipeline_validate. Returns: {ok, stage, status} or a gate refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| stage | string | yes | Pipeline stage id, e.g. 'aso', 'screenshots', 'features' (see pipeline_status for the list). |
| status | string | – | New stage status: 'done', 'in_progress' or 'pending'. |
Structured output declared, but exposes no named fields.
No examples provided.
pipeline_next Pipeline Next ~140
Return the next mandatory pipeline step with its instructions. Use when: driving the pipeline manually. Refuses until run options are confirmed (run_options, run_options_save) unless skip_options_check. Not for: the autonomous loop with retry budgets (use orchestrator_next_action). Returns: {ok, stage, instructions} or setup_required / options-not-confirmed errors.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| skip_options_check | boolean | – | If true, do not require run_options_save to have been called first. Default false. |
Structured output declared, but exposes no named fields.
No examples provided.
pipeline_status Pipeline Status ~95
Show which pipeline stages are done or pending and what comes next. Use when: checking progress of one app. To get the next instructions use pipeline_next; for the autonomous loop use orchestrator_next_action. Returns: {ok, stages: {stage: status}, next}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
Structured output declared, but exposes no named fields.
No examples provided.
pipeline_validate Pipeline Validate ~107
Run a stage's enforced gate without modifying the manifest. Use when: self-checking before pipeline_mark(done). Read-only. Returns: {ok, stage, problems: [...]}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| stage | string | yes | Pipeline stage id, e.g. 'aso', 'screenshots', 'features' (see pipeline_status for the list). |
Structured output declared, but exposes no named fields.
No examples provided.
playbook Playbook ~50
Return the AppFactory run playbook as markdown. Use when: before driving the pipeline; the same text is the `run` prompt and the appfactory://playbook resource. Returns: markdown string.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| result | string | yes | – |
No examples provided.
preview_brief Preview Brief ~148
Write marketing/preview/BRIEF.md (the HyperFrames App Preview brief) from app.spec.json and create the recordings folders. Use when: starting the App Preview video. Then record the real app and author the video with the hyperframes skill (real footage only). Check with preview_check. Returns: {ok, brief path, recordings dirs}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| message | string | – | Optional extra direction appended to the brief. |
| overwrite | boolean | – | If true, replace files that already exist; default false refuses to overwrite. |
Structured output declared, but exposes no named fields.
No examples provided.
preview_check Preview Check ~116
Check offline readiness of the App Preview set: brief, recordings, one preview per locale, ffprobe specs, self-review status. Use when: before preview_upload. Files must be 886x1920, <=30 fps, H.264, 15-30 s, <=500 MB, stereo AAC or silent. Returns: {ok, problems: [...], plan}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
Structured output declared, but exposes no named fields.
No examples provided.
preview_review_log Preview Review Log ~194
Log one self-review round (scores 1-10 and worst problems) for a final preview file. Use when: after preview_review_sheets. Every score must reach 8+ on the exact final file (MD5-matched) or preview_upload and the gate refuse. Returns: {ok, passed, scores, problems}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| file | string | yes | Preview file path relative to the app dir, e.g. 'fastlane/app_previews/en-US/preview.mp4'. |
| problems | – | – | Up to 3 worst problems as [{t: seconds, issue: text}]; required while any score is under 8. |
| scores | object | yes | Scores 1-10 for keys hook, readability, motion, variety, brand, music. |
Structured output declared, but exposes no named fields.
No examples provided.
preview_review_sheets Preview Review Sheets ~101
Generate self-review material (contact sheet, phone-size sheet, transition strip) for every final preview with ffmpeg. Use when: reviewing a rendered preview; open the sheets, score them, then call preview_review_log. Returns: {ok, sheets: {locale: [paths]}}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
Structured output declared, but exposes no named fields.
No examples provided.
preview_upload Preview Upload ~242
Upload fastlane/app_previews/<locale>/ to the editable version's iPhone preview sets via the asc CLI (needs human approval unless dry_run). Use when: preview_check is clean and self-review passed. dry_run=true (default) sends nothing. MD5-idempotent; refuses while preview_check has problems. Returns: {ok, uploaded/planned: [...], dry_run} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| dry_run | boolean | – | If true (default) nothing is changed or sent and the exact plan/command is returned; false performs the live action. |
| locales | – | – | Locale codes to upload; omit for every locale in fastlane/app_previews/. |
| replace | boolean | – | If true, replace preview sets that already exist on App Store Connect. |
Structured output declared, but exposes no named fields.
No examples provided.
pricing_unit_economics Pricing Unit Economics ~188
Compute unit economics from the measured AI cost per call and usage profiles, and write the generated blocks of store/pricing.md. Use when: pricing a built app with real eval data. For quick what-if numbers at idea stage use aso_unit_economics. Returns: {ok, products: [{margin, ...}], path}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | string | yes | Absolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp. |
| apple_cut | number | – | Apple's commission as a fraction: 0.15 (Small Business Program, default) or 0.30. |
| cost_photo | – | – | Measured AI cost in USD per photo call; omit to read from backend/eval/results. |
| cost_text | – | – | Measured AI cost in USD per text call; omit to read from backend/eval/results. |
Structured output declared, but exposes no named fields.
No examples provided.
revenuecat_setup RevenueCat Setup ~269
Idempotently set up the RevenueCat v2 project: premium entitlement, subscription attachments, SDK key and Supabase secret (live write, needs human approval). Use when: after a human created the RC project, linked ASC and supplied the v2 key. Returns NEEDS_HUMAN if no project exists. For ASC plus RC in one pass use store_setup. Returns: {ok, entitlement, sdk_key_set, secrets} or an approval_required refusal.
| Name | Type | Req | Description |
|---|---|---|---|
| approval_id | – | – | Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id. |
| bundle_id | string | yes | App bundle identifier in reverse-DNS form, e.g. com.example.app. |
| env_suffix | string | – | Suffix for secret names when several apps share one Supabase project, e.g. '_MYAPP'. |
| set_secrets | boolean | – | If true (default) also write the RevenueCat secrets to Supabase. |
| supabase_ref | string | yes | Supabase project ref that receives the RevenueCat secrets. |
| v2_key | string | yes | RevenueCat secret API v2 key (sk_...); used for this call only. |
Structured output declared, but exposes no named fields.
No examples provided.
run_options Run Options ~107
List every optional part of a run with its question, kind, choices, default and current value. Use when: BEFORE any other work when the user says run. Ask the user each question one at a time (or as a checklist), then call run_options_save. Returns: {ok, options: [{id, question, kind, choices, default, value}], confirmed}.
| Name | Type | Req | Description |
|---|---|---|---|
| app_dir | – | – | App directory to read current values from; omit before the app is scaffolded. |
Structured output declared, but exposes no named fields.
No examples provided.
run_options_save Run Options Save ~126
Save the user's answers to the run options and mark options confirmed. Use when: after asking every question from run_options. Validates types, choices and dependencies; services go to config.toml, the rest to app.spec.json (or a pending file that app_scaffold applies). Returns: {ok, saved, errors?}.
| Name | Type | Req | Description |
|---|---|---|---|
| answers | object | yes | Map {option id: value} covering every option id returned by run_options. |
| app_dir | – | – | App directory whose app.spec.json receives the answers; omit to save to the pending file used by app_scaffold. |
Structured output declared, but exposes no named fields.
No examples provided.
What is the io.github.gbatistuta0/appfactory MCP server?
io.github.gbatistuta0/appfactory is an MCP server listed in the public MCP registry as io.github.gbatistuta0/appfactory. Lets your coding agent ship a SwiftUI iOS subscription app from idea to TestFlight. This page covers its PyPI package (appfactory).
Is the io.github.gbatistuta0/appfactory MCP server safe to use?
io.github.gbatistuta0/appfactory scores 75 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 4 October 2026. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.gbatistuta0/appfactory MCP server expose?
io.github.gbatistuta0/appfactory exposes 125 tools: setup_status, setup_services, setup_set, setup_approvals, setup_credentials, and 120 more. Their descriptions and schemas cost roughly 18,907 tokens of context every time the server is loaded.
Is the io.github.gbatistuta0/appfactory MCP server still maintained?
io.github.gbatistuta0/appfactory is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the io.github.gbatistuta0/appfactory MCP server under?
io.github.gbatistuta0/appfactory declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.