Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.gbatistuta0/appfactory

PYPI · APPFACTORY · SCANNED OCT 4

Lets your coding agent ship a SwiftUI iOS subscription app from idea to TestFlight.

Available components

75 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security100
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • Runs hatchling.build at install time, a recognised build step with no custom scripting around it. View diagnostics → Pass
  • 1 of 22 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency100
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to gbatistuta0/appfactory). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 4 days ago).Pass
  • Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability48
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • Instruction-quality not yet verified: the AI judgement didn't run.Unverified
  • Context-footprint check failed: tool/resource definitions use about 19176 tokens (~152/item across 126 items; 125 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
  • Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety75
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 4 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • Manipulation not yet verified: only 2 of 127 captured unit(s) of tool text has been judged so far, so we will not certify text no model has read as clean.Unverified
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass

Unverified: 1 category

A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

Install

How do I install the io.github.gbatistuta0/appfactory MCP server?

io.github.gbatistuta0/appfactory runs locally as a PyPI package, launched with uvx appfactory. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

pypi · appfactory

# add to Claude Code
claude mcp add gbatistuta0-appfactory -- uvx appfactory
// .cursor/mcp.json
{
  "mcpServers": {
    "gbatistuta0-appfactory": {
      "command": "uvx",
      "args": [
        "appfactory"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "gbatistuta0-appfactory": {
      "command": "uvx",
      "args": [
        "appfactory"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add gbatistuta0-appfactory -- uvx appfactory
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "gbatistuta0-appfactory": {
      "type": "local",
      "command": [
        "uvx",
        "appfactory"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add gbatistuta0-appfactory --command uvx --arg appfactory
# ~/.hermes/config.yaml
mcp_servers:
  gbatistuta0-appfactory:
    command: "uvx"
    args: ["appfactory"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "gbatistuta0-appfactory": {
      "Transport": "stdio",
      "Command": "uvx",
      "Arguments": [
        "appfactory"
      ]
    }
  }
}
# add to Vellum
assistant mcp add gbatistuta0-appfactory -t stdio -c uvx -a appfactory
// mcp.json
{
  "mcpServers": {
    "gbatistuta0-appfactory": {
      "command": "uvx",
      "args": [
        "appfactory"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 30 Sept 26 +15
    • Malware scan: unverified → pass ▲ security
  • 29 Sept 26 60

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 7 Oct 2026 · Analysed pypi/appfactory@0.1.5

Provenance Verified

A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.

Result Verified
Ecosystem pypi
Reason Verified
Discovered via Registry attestation endpoint
Source repo gbatistuta0/appfactory
Certificate issuer https://token.actions.githubusercontent.com
Certificate SAN https://github.com/gbatistuta0/appfactory/.github/workflows/release.yml@refs/tags/v0.1.5
Rekor log index 3004333188
Predicate type PyPI publish attestation https://docs.pypi.org/attestations/publish/v1
Subject digest sha256:19e11c989976e965a51efa3cbc68c13783dfdc12d467cef474242976ecf7de2f

Background: How many MCP packages publish verified provenance →

Install scripts 1 script
Hook Tier Command
build_backend allowlisted hatchling.build

Background: Why install scripts are a supply-chain risk →

Dependencies 22 packages
Packages resolved 22
Stale 1
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 125 exposed · ~18,907 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
screenshot_apply_layout ~85

Merge the Claude Design store layout (design/project/store_layout.json) into marketing/screenshots/config.json. Use when: before screenshot_brand so every locale renders the approved layout. Returns: {ok, config path, boards}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.

Structured output declared, but exposes no named fields.

No examples provided.

screenshot_brand ~71

Render branded App Store screenshots with the node compositor using the Claude Design store layout. Use when: raw captures exist; run screenshot_apply_layout first (screenshot_build_all does both). Returns: {ok, rendered: count, dir}.

NameTypeReqDescription
marketing_dirstringyesPath to the app's marketing/ directory.

Structured output declared, but exposes no named fields.

No examples provided.

screenshot_build_all ~275

Run the whole turnkey screenshot step: sample image, build and install, captions, capture 32 languages x 6 screens, brand, sync to fastlane/screenshots. Use when: the mandatory screenshots stage. Not for: single captures (use screenshot_capture) or uploading (use deliver_screenshots). Long-running. Returns: {ok, locales, screens, dir} or the first failing step.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
bundle_idstringyesApp bundle identifier in reverse-DNS form, e.g. com.example.app.
locales––List of locale codes, e.g. ['en-US', 'de-DE']; omit for the default set.
projectstringyesPath to the .xcodeproj or .xcworkspace to build, e.g. /path/App/App.xcodeproj.
sample_promptstringyesPrompt describing a sample output of the app (fills Result/Gallery screens).
schemestringyesXcode scheme name to build, e.g. 'MyApp'.
udidstringyesSimulator UDID from build_list_simulators, e.g. 'A1B2C3D4-...'.

Structured output declared, but exposes no named fields.

No examples provided.

screenshot_capture ~148

Capture a raw screenshot from the booted simulator into marketing/raw/<locale>/<name>.png. Use when: capturing a single screen manually. For the full localized set use screenshot_build_all. Returns: {ok, path}.

NameTypeReqDescription
localestringyesApp locale of the capture, e.g. 'en-US'; used as the output subfolder.
marketing_dirstringyesPath to the app's marketing/ directory.
namestringyesScreen name, used as the file name, e.g. 'paywall'.
udidstringyesSimulator UDID from build_list_simulators, e.g. 'A1B2C3D4-...'.

Structured output declared, but exposes no named fields.

No examples provided.

screenshot_generate_sample ~103

Generate a sample image with fal.ai into Resources/sample_headshot.jpg to fill the Result/Gallery screens (paid). Use when: screenshots need real-looking app output; screenshot_build_all calls it for you. Returns: {ok, path}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
promptstringyesImage generation prompt for the sample output.

Structured output declared, but exposes no named fields.

No examples provided.

screenshot_onboarding_heroes ~175

LEGACY, opt-in: generate fal hero images per onboarding step (onb_step0..N). Use when: only for a legacy hero-image onboarding. Onboarding visuals normally come from Claude Design boards. Requires allow_external_generator=true. Returns: {ok, images: [paths]} or a refusal.

NameTypeReqDescription
allow_external_generatorboolean–Must be true to allow the paid fal.ai image generator; default false refuses.
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
conceptstringyesShort concept description of the app used to write the image prompt, e.g. 'AI pet portrait maker'.
countinteger–Number of onboarding hero images to generate (default 11).

Structured output declared, but exposes no named fields.

No examples provided.

screenshot_sync ~89

Copy branded screenshots into fastlane/screenshots/<locale>/. Use when: after screenshot_brand, before deliver_screenshots. Local only; nothing is uploaded. Returns: {ok, synced: count}.

NameTypeReqDescription
fastlane_screenshots_dirstringyesPath to fastlane/screenshots/ to sync branded images into.
marketing_dirstringyesPath to the app's marketing/ directory.

Structured output declared, but exposes no named fields.

No examples provided.

setup_approvals ~86

Set human approvals for live writes to 'required' (recommended). Use when: re-enabling approvals. 'off' is refused here; only the human can switch it off on the setup_credentials page. Returns: {ok, approvals}.

NameTypeReqDescription
modestringyesApprovals mode; only 'required' is accepted here ('off' must be set by the human).

Structured output declared, but exposes no named fields.

No examples provided.

setup_credentials ~100

Open a local browser page (127.0.0.1, random port, one-time token) where the USER types credentials for the given services. Use when: setup_status shows missing keys. Secrets never reach the agent; return immediately, tell the user to fill the form and Save, then call setup_status. Returns: {ok, url, services}.

NameTypeReqDescription
services––Service ids to collect credentials for; omit for every enabled service.

Structured output declared, but exposes no named fields.

No examples provided.

setup_services ~122

Turn optional services on or off (research is always on). Use when: the user has said which services they want; ask them first. Not for: entering credentials (use setup_credentials). Returns: the setup_status result after the change.

NameTypeReqDescription
disable––Service ids to turn off (same ids as enable).
enable––Service ids to turn on, e.g. ['apple', 'supabase', 'revenuecat', 'github', 'firebase', 'xcode', 'maestro', 'design', 'ai', 'lottie'].

Structured output declared, but exposes no named fields.

No examples provided.

setup_set ~112

Set ONE non-secret config key such as asc_key_id, team_id or support_email; an empty value clears it. Use when: changing a single key. Secrets are refused; use setup_credentials so they never pass through the chat. For several fields at once use config_set. Returns: {ok, key, error?}.

NameTypeReqDescription
keystringyesNon-secret config key, e.g. 'asc_key_id', 'team_id', 'support_email'.
valuestringyesValue to store.

Structured output declared, but exposes no named fields.

No examples provided.

setup_status ~83

Report the AppFactory setup state per service: enabled, keys set or missing (never values), missing tools with install commands, approvals mode. Use when: first call of every session, and after any setup change. Works with no config file. Returns: {ok, services: {name: {enabled, keys, missing}}, approvals, next: [steps]}.

Input schema present but exposes no named parameters.

Structured output declared, but exposes no named fields.

No examples provided.

signing_create_profile ~164

Create an IOS_APP_STORE provisioning profile and write it to the standard locations (live write, needs human approval). Use when: after signing_setup_distribution; testflight_ship does this for you. Returns: {ok, profile_id, name, path}.

NameTypeReqDescription
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
bundle_idstringyesApp bundle identifier in reverse-DNS form, e.g. com.example.app.
cert_idstringyesApp Store Connect certificate id from signing_setup_distribution.
namestring–Provisioning profile name (default 'AppFactory AppStore').

Structured output declared, but exposes no named fields.

No examples provided.

signing_setup_distribution ~109

Create a distribution certificate and install it into a temporary keychain (WWDR included; live write, needs human approval). Use when: hand-running signing steps; testflight_ship does this for you. Returns: {ok, cert_id, identity, keychain}.

NameTypeReqDescription
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.

Structured output declared, but exposes no named fields.

No examples provided.

store_setup ~309

Idempotent App Store Connect and RevenueCat setup from app.spec.json and listing.json (capabilities, subscriptions, prices, offers, age rating, legal URLs, RC entitlement/offerings). Use when: the standard way to set up the store side. mode: plan (offline), check (live reads, simulated writes, reports CONFLICT), apply (live writes, needs human approval). Prefer this over the individual asc_* write tools; asc_create_app is still separate. Returns: {ok, mode, steps: [...], conflicts} or an approval_required refusal.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
modestring–'plan' (offline), 'check' (live reads, simulated writes, reports CONFLICT) or 'apply' (live writes, needs approval).
rc_apple_notification_url––RevenueCat's Apple Server-to-Server notification URL, stored in app outputs.
rc_project_id––RevenueCat project id (proj...) if it already exists.
targetstring–What to set up: 'capabilities', 'asc', 'rc' or 'all' (default).

Structured output declared, but exposes no named fields.

No examples provided.

storekit_generate ~100

Write Resources/Configuration.storekit from app.spec.json (group, levels, free-trial intros, trial-less offer product). Use when: after any product change. Deterministic. app_sync_spec also regenerates it together with Swift sources. Returns: {ok, path, products}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.

Structured output declared, but exposes no named fields.

No examples provided.

storekit_parity ~108

Compare a Configuration.storekit with app.spec.json and list every mismatch (read-only). Use when: verifying products match before store_setup or release. ok=true means in parity. Returns: {ok, mismatches: [...]}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
storekit_path––Path to a Configuration.storekit; omit for Resources/Configuration.storekit.

Structured output declared, but exposes no named fields.

No examples provided.

supabase_create_project ~191

Create a new Supabase project (live write that provisions billable resources, needs human approval). Use when: the app has no backend project yet. Check supabase_list_projects first to avoid duplicates. Returns: {ok, data: {id/ref, name, region, ...}} or an approval_required refusal.

NameTypeReqDescription
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
db_passstringyesDatabase password for the new project.
namestringyesName of the new Supabase project.
org_idstringyesSupabase organization id from supabase_list_orgs.
regionstringyesSupabase region code, e.g. 'us-east-1', 'eu-central-1'.

Structured output declared, but exposes no named fields.

No examples provided.

supabase_get_keys ~105

Get a Supabase project's URL and anon key; the service_role key is saved to ~/.appfactory/supabase/<ref>.json (0600) and never returned. Use when: wiring the app (app_inject_config) or backend. Returns: {ok, project_url, anon_key, service_role_key_file}.

NameTypeReqDescription
refstringyesSupabase project ref (20-char id from supabase_list_projects, e.g. 'abcdefghijklmnopqrst').

Structured output declared, but exposes no named fields.

No examples provided.

supabase_list_orgs ~49

List Supabase organizations (live, read-only). Use when: you need the org_id for supabase_create_project. Returns: {ok, data: [{id, name}]}.

Input schema present but exposes no named parameters.

Structured output declared, but exposes no named fields.

No examples provided.

supabase_list_projects ~57

List Supabase projects (live, read-only). Use when: you need a project ref. For org ids use supabase_list_orgs. Returns: {ok, projects: [{name, ref, region, status}]}.

Input schema present but exposes no named parameters.

Structured output declared, but exposes no named fields.

No examples provided.

supabase_run_sql ~198

Run SQL on a Supabase project (live write, needs human approval). Use when: applying schema or migrations by hand; backend_deploy applies the spec's migrations for you. Destructive statements (DROP, TRUNCATE, ALTER ... DROP, GRANT/REVOKE on auth, DELETE/UPDATE without WHERE) always need approval. Returns: {ok, data} rows/result, or an approval_required refusal.

NameTypeReqDescription
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
refstringyesSupabase project ref (20-char id from supabase_list_projects, e.g. 'abcdefghijklmnopqrst').
sqlstringyesSQL to execute. Destructive statements (DROP, TRUNCATE, DELETE/UPDATE without WHERE) always need approval.

Structured output declared, but exposes no named fields.

No examples provided.

supabase_set_secret ~182

Write one edge-function secret on a Supabase project, server-side only (live write, needs human approval). Use when: adding a single secret such as FAL_KEY. backend_deploy sets the standard set for you. Returns: {ok, name} (value never echoed), or an approval_required refusal.

NameTypeReqDescription
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
namestringyesEdge function secret name, e.g. 'FAL_KEY'.
refstringyesSupabase project ref (20-char id from supabase_list_projects, e.g. 'abcdefghijklmnopqrst').
valuestringyesSecret value; written server-side and never echoed back.

Structured output declared, but exposes no named fields.

No examples provided.

team_brief ~150

Render the team docs (TEAM.md, per-role briefs, onboarding plan, ASO research, CHECKLIST.md) from the spec. Use when: setting up multi-session work. Existing files are kept unless overwrite=true. Returns: {ok, files}.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
overwriteboolean–If true, replace files that already exist; default false refuses to overwrite.
repo––GitHub repo 'owner/name' to reference in the briefs; optional.
sessions––Names of the team sessions as {lead, ios, backend, store}.

Structured output declared, but exposes no named fields.

No examples provided.

testflight_ship ~275

Build, sign and upload a TestFlight build end to end: distribution signing, archive, App Store profiles, manual-signing export, asc builds upload (needs human approval). Use when: shipping a build to TestFlight. Refuses unless the Maestro smoke flows passed (maestro_test) and App ID capabilities exist. Never submits for App Store review (use asc_submit_for_review for that). Not for: single build steps (build_archive, build_export_ipa, signing_*). Returns: {ok, build, ...} or an error / approval_required refusal.

NameTypeReqDescription
app_dirstringyesAbsolute path to the app project directory (contains app.spec.json), e.g. /Users/me/Apps/MyApp.
approval_id––Approval id from a previous approval_required refusal; omit on the first call. The human approves out-of-band with `appfactory approve <id>`, then call again with the same arguments and this id.
bundle_idstringyesApp bundle identifier in reverse-DNS form, e.g. com.example.app.
projectstringyesPath to the .xcodeproj or .xcworkspace to build, e.g. /path/App/App.xcodeproj.
schemestringyesXcode scheme name to build, e.g. 'MyApp'.

Structured output declared, but exposes no named fields.

No examples provided.

Common questions

What is the io.github.gbatistuta0/appfactory MCP server?

io.github.gbatistuta0/appfactory is an MCP server listed in the public MCP registry as io.github.gbatistuta0/appfactory. Lets your coding agent ship a SwiftUI iOS subscription app from idea to TestFlight. This page covers its PyPI package (appfactory).

Is the io.github.gbatistuta0/appfactory MCP server safe to use?

io.github.gbatistuta0/appfactory scores 75 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 4 October 2026. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.github.gbatistuta0/appfactory MCP server expose?

io.github.gbatistuta0/appfactory exposes 125 tools: setup_status, setup_services, setup_set, setup_approvals, setup_credentials, and 120 more. Their descriptions and schemas cost roughly 18,907 tokens of context every time the server is loaded.

Is the io.github.gbatistuta0/appfactory MCP server still maintained?

io.github.gbatistuta0/appfactory is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the io.github.gbatistuta0/appfactory MCP server under?

io.github.gbatistuta0/appfactory declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.