@aarwitz/tapp

MCPcommunauté
v0.17.3io.github.aarwitzMITMis à jour il y a 5 jnpmGitHub

Let coding agents verify UI changes on real iOS, Android, and web surfaces, then enforce reviewed proof in deterministic CI.

Fonctionne dans
ClaudeCursorCopilotGemini

Déduit des transports déclarés par cette annonce (stdio). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.

Indexé automatiquement depuis des sources publiques. Pas encore vérifié par son développeur sur Forge.Revendiquer cette annonce →
3kTéléch./sem.
il y a 5 jDernière mise à jour
Paquet
Auteurio.github.aarwitz
LicenceMIT
Version0.17.3
Sourcenpm+mcp-registry
Statut de confiance
B
60/100Bon
Listé dans l’index Forge+10/10
Identité de l’éditeur vérifiée+0/20
Éditeur : exécutez `forge publish` depuis le dépôt du paquet pour revendiquer la propriété
Signature de publication Ed25519+0/5
Incluse automatiquement quand l’éditeur exécute `forge publish`
Vérification de domaine+0/5
Éditeur : hébergez /.well-known/forge.json sur la page d’accueil du paquet avec { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+0/5
Publiez depuis GitHub Actions avec --provenance pour que l’attestation lie ce paquet à ce dépôt
Correspondance de mainteneur npm+0/5
Acquis dès que votre identité est vérifiée ci-dessus et que ce login est mainteneur npm de ce paquet
Analyse CVE · propre+30/30
Analyse statique · propre+20/20
Collez-le dans Claude Code, Cursor ou tout assistant d’IA pour combler toutes les lacunes
StatutIndexé par la communauté
ÉditeurNon vérifié
SignatureNon signé
Domaine
Provenance
Dépendances✓ 60 résolues+ · aucune vulnérable
Surface d’outils33 outils · 1 privilégiés
Analyse de sécurité✓ Proprev0.17.3 · aujourd’huiQuelle est l’efficacité de cette analyse ?
ÉvaluationsAucune
Indexé20 août 2026

La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.

Outils

33 outils · 1 privilégiés
Extrait statiquement du paquet publiév0.17.3 · 2h ago

Lu dans le code que npm livre réellement, au moment de l’analyse. Le paquet n’a jamais été exécuté. Les outils enregistrés dynamiquement à l’exécution, ou cachés dans du code empaqueté ou minifié, peuvent passer inaperçus — c’est donc un plancher de la surface d’outils, pas un recensement complet.

checkoutCreatesDurableOrderAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

test-appUse Tapp's real app surfaces to inspect, drive, or explore this repository and report evidence honestly.

Use Tapp's real app surfaces to inspect, drive, or explore this repository and report evidence honestly.

Aucun schéma d’entrée n’a été publié pour cet outil.

goalWhat to verify, such as finding bugs or exercising checkout

What to verify, such as finding bugs or exercising checkout

Aucun schéma d’entrée n’a été publié pour cet outil.

targetOptional repo target, bundle/app id, APK path, or owned URL

Optional repo target, bundle/app id, APK path, or owned URL

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_healthCheck Tapp workspace and toolchain availability

Check Tapp workspace and toolchain availability

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_buildBuild the user's iOS app for the simulator from an Xcode project/workspace (auto-detects the

Build the user's iOS app for the simulator from an Xcode project/workspace (auto-detects the

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_captureRun headless capture workflows using scripts/quick-capture.sh

Run headless capture workflows using scripts/quick-capture.sh

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_parse_markersParse OCQA markers from a capture run into structured summary

Parse OCQA markers from a capture run into structured summary

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_list_capturesList recent capture runs from captures/

List recent capture runs from captures/

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_capture_summaryShow summary metadata for a capture run

Show summary metadata for a capture run

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_exploreAutonomously explore iOS (appBundleId), Android (androidAppId), OR a web app

Autonomously explore iOS (appBundleId), Android (androidAppId), OR a web app

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_initAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

tapp_actor_configManage the repository-native .tapp/project.json actor/session contract used by init, release-contract generation, and CI. `read` is inspect-only. `set` writes an explicit actor role, isolation/provisioning policy, and credential-name to environment-variable-name bindings. The tool never accepts, re…

Manage the repository-native .tapp/project.json actor/session contract used by init, release-contract generation, and CI. `read` is inspect-only. `set` writes an explicit actor role, isolation/provisioning policy, and credential-name to environment-variable-name bindings. The tool never accepts, re…

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_release_planAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

tapp_ci_setupComplete the local release-contract onboarding loop from the shared application model. `inspect` renders a target-aware GitHub workflow and machine-readable CI manifest without writing; `install` writes both with collision protection; `baseline` imports an existing successful conclusive portable-ga…

Complete the local release-contract onboarding loop from the shared application model. `inspect` renders a target-aware GitHub workflow and machine-readable CI manifest without writing; `install` writes both with collision protection; `baseline` imports an existing successful conclusive portable-ga…

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_ui_mapUse Tapp's first-class platform-neutral UI Map: evidence-grounded screen states, semantic controls, transitions, platform variants, provenance, and task/contract coverage hooks.

Use Tapp's first-class platform-neutral UI Map: evidence-grounded screen states, semantic controls, transitions, platform variants, provenance, and task/contract coverage hooks.

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_taskWork with repository-native compositional Tasks in .tapp/tasks. Tasks define inputs, outputs, pre/postconditions, platform implementations, and the UI Map states/transitions they cover.

Work with repository-native compositional Tasks in .tapp/tasks. Tasks define inputs, outputs, pre/postconditions, platform implementations, and the UI Map states/transitions they cover.

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_release_contractWork with repository-native TypeScript release contracts in .tapp/contracts. Contracts express business guarantees through reusable Tasks, named actors, exact/eventual expectations, criticality, policy, and UI Map coverage.

Work with repository-native TypeScript release contracts in .tapp/contracts. Contracts express business guarantees through reusable Tasks, named actors, exact/eventual expectations, criticality, policy, and UI Map coverage.

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_pr_planAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

tapp_flow_runReplay a deterministic, authored end-to-end test (a Flow) against iOS (XCUITest), Android

Replay a deterministic, authored end-to-end test (a Flow) against iOS (XCUITest), Android

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_scenario_runReplay a repository-native system test whose named actors run in isolated browser contexts against shared application state.

Replay a repository-native system test whose named actors run in isolated browser contexts against shared application state.

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_flow_generateWrite a deterministic E2E Flow from a natural-language goal (e.g. 'sign in and open Settings'),

Write a deterministic E2E Flow from a natural-language goal (e.g. 'sign in and open Settings'),

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_flow_saveSave what you've done in the CURRENT interactive session as a reusable, deterministic Flow

Save what you've done in the CURRENT interactive session as a reusable, deterministic Flow

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_ui_treeDump the accessibility (UI) tree of the current screen of an installed iOS or Android app —

Dump the accessibility (UI) tree of the current screen of an installed iOS or Android app —

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_screenshotReturn an inline image of whatever is CURRENTLY on the booted simulator. It does NOT launch or

Return an inline image of whatever is CURRENTLY on the booted simulator. It does NOT launch or

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_open_appLaunch an installed iOS or Android app and return a SCREENSHOT of the screen it lands on

Launch an installed iOS or Android app and return a SCREENSHOT of the screen it lands on

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_list_simulatorsList available iOS simulators (name, udid, state, runtime, booted) so you can pick or boot one before running QA.

List available iOS simulators (name, udid, state, runtime, booted) so you can pick or boot one before running QA.

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_boot_simulatorBoot an iOS simulator by udid (preferred) or name so Tapp can run against it. No-op if already booted.

Boot an iOS simulator by udid (preferred) or name so Tapp can run against it. No-op if already booted.

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_install_appprivilégiéBuild a target iOS app for the booted simulator and install it, so it's ready for tapp_explore or

Build a target iOS app for the booted simulator and install it, so it's ready for tapp_explore or

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_session_startStart a PERSISTENT interactive session against an installed iOS/Android app, a web URL, or an

Start a PERSISTENT interactive session against an installed iOS/Android app, a web URL, or an

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_focusAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

tapp_session_actPerform ONE action in the active interactive session and get the resulting screen back (the fresh

Perform ONE action in the active interactive session and get the resulting screen back (the fresh

Aucun schéma d’entrée n’a été publié pour cet outil.

tapp_session_endEnd the active interactive session (quits the app + harness). Always call this when done.

End the active interactive session (quits the app + harness). Always call this when done.

Aucun schéma d’entrée n’a été publié pour cet outil.

28 outils sur 33 ont publié une description.

Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.

À propos

Let coding agents verify UI changes on real iOS, Android, and web surfaces, then enforce reviewed proof in deterministic CI.

Mots-clés
tappcliiosandroidsimulatormcpmcp-serverxcuiteste2etestingqaplaywrightrelease-contractsrelease-gateagentclaudecursorcopilotautomationmobile
Alternatives
Comparaison des surfaces d’outils…

Arbre de dépendances

Ce qu'une analyse Forge a résolu à partir des métadonnées npm le 2026-08-29 — résolution observée, et non une déclaration de l'éditeur.

60 paquets résolus · 2 directs · aucun porteur d'avis de sécurité La résolution s'arrête à la profondeur 4 et à 60 paquets.

L'exploration s'est arrêtée à la limite de profondeur 4. Tout ce qui se trouve en dessous n'a jamais été résolu.

L'exploration s'est arrêtée à la limite de 60 paquets. Le reste de l'arbre n'a jamais été résolu.

36 autres paquets résolus ne sont pas dessinés ici (limite d'affichage : 24). Toute dépendance porteuse d'un avis de sécurité est dessinée quelle que soit la limite. Inventaire complet (SBOM CycloneDX)

Déclarées mais non résolues

54 dépendances déclarées ne sont jamais arrivées dans l'arbre. Elles manquent à la résolution de Forge, pas au paquet.

+42 de plus non listées. Les comptes par motif ci-dessus les couvrent toutes.

Non suivies : peerDependencies. Cet arbre ne couvre que les dépendances d'exécution ; ce qu'elles entraînent n'a jamais été résolu.

Thèmes

Apparentés dans browser automation & scraping