@aarwitz/tapp

MCPcommunity
v0.17.3io.github.aarwitzMITAggiornato 5 g fanpmGitHub

Let coding agents verify UI changes on real iOS, Android, and web surfaces, then enforce reviewed proof in deterministic CI.

Funziona in
ClaudeCursorCopilotGemini

Dedotto dai trasporti dichiarati da questo annuncio (stdio). Un client che non compare qui non è escluso — semplicemente Forge non è in grado di confermarlo.

Indicizzato automaticamente da fonti pubbliche. Non ancora verificato dal suo sviluppatore su Forge.Rivendica questo annuncio →
3kDownload/sett.
5 g faUltimo aggiornamento
Pacchetto
Autoreio.github.aarwitz
LicenzaMIT
Versione0.17.3
Fontenpm+mcp-registry
Stato di fiducia
B
60/100Buono
Presente nell’indice di Forge+10/10
Identità del publisher verificata+0/20
Publisher: esegui `forge publish` dal repo del pacchetto per rivendicarne la proprietà
Firma di pubblicazione Ed25519+0/5
Inclusa automaticamente quando il publisher esegue `forge publish`
Verifica del dominio+0/5
Publisher: ospita /.well-known/forge.json sulla homepage del pacchetto con { "publisher": "<github-login>" }
npm Trusted Publishing (Sigstore)+0/5
Pubblica da GitHub Actions con --provenance perché l’attestation leghi questo pacchetto a questo repo
Corrispondenza del maintainer npm+0/5
Si ottiene quando la tua identità è verificata qui sopra e quel login è maintainer npm di questo pacchetto
Analisi CVE · pulita+30/30
Analisi statica · pulita+20/20
Incollalo in Claude Code, Cursor o qualsiasi assistente di IA per colmare tutte le lacune
StatoIndicizzato dalla community
PublisherNon verificato
FirmaNon firmato
Dominio
Provenienza
Dipendenze✓ 60 risolte+ · nessuna vulnerabile
Superficie di strumenti33 strumenti · 1 privilegiati
Analisi di sicurezza✓ Pulitov0.17.3 · oggiQuanto è efficace questa analisi?
ValutazioniNessuna
Indicizzato20 ago 2026

La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.

Strumenti

33 strumenti · 1 privilegiati
Estratto staticamente dal pacchetto pubblicatov0.17.3 · 2h ago

Letto dal codice che npm distribuisce davvero, al momento dell’analisi. Il pacchetto non è mai stato eseguito. Gli strumenti registrati dinamicamente a runtime, o nascosti in codice impacchettato o minificato, possono sfuggire — quindi questo è un limite inferiore della superficie di strumenti, non un censimento completo.

checkoutCreatesDurableOrderNessuna descrizione pubblicata

Questo strumento non ha pubblicato alcuna descrizione. Forge non se la inventa.

test-appUse Tapp's real app surfaces to inspect, drive, or explore this repository and report evidence honestly.

Use Tapp's real app surfaces to inspect, drive, or explore this repository and report evidence honestly.

Per questo strumento non è stato pubblicato alcuno schema di input.

goalWhat to verify, such as finding bugs or exercising checkout

What to verify, such as finding bugs or exercising checkout

Per questo strumento non è stato pubblicato alcuno schema di input.

targetOptional repo target, bundle/app id, APK path, or owned URL

Optional repo target, bundle/app id, APK path, or owned URL

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_healthCheck Tapp workspace and toolchain availability

Check Tapp workspace and toolchain availability

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_buildBuild the user's iOS app for the simulator from an Xcode project/workspace (auto-detects the

Build the user's iOS app for the simulator from an Xcode project/workspace (auto-detects the

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_captureRun headless capture workflows using scripts/quick-capture.sh

Run headless capture workflows using scripts/quick-capture.sh

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_parse_markersParse OCQA markers from a capture run into structured summary

Parse OCQA markers from a capture run into structured summary

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_list_capturesList recent capture runs from captures/

List recent capture runs from captures/

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_capture_summaryShow summary metadata for a capture run

Show summary metadata for a capture run

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_exploreAutonomously explore iOS (appBundleId), Android (androidAppId), OR a web app

Autonomously explore iOS (appBundleId), Android (androidAppId), OR a web app

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_initNessuna descrizione pubblicata

Questo strumento non ha pubblicato alcuna descrizione. Forge non se la inventa.

tapp_actor_configManage the repository-native .tapp/project.json actor/session contract used by init, release-contract generation, and CI. `read` is inspect-only. `set` writes an explicit actor role, isolation/provisioning policy, and credential-name to environment-variable-name bindings. The tool never accepts, re…

Manage the repository-native .tapp/project.json actor/session contract used by init, release-contract generation, and CI. `read` is inspect-only. `set` writes an explicit actor role, isolation/provisioning policy, and credential-name to environment-variable-name bindings. The tool never accepts, re…

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_release_planNessuna descrizione pubblicata

Questo strumento non ha pubblicato alcuna descrizione. Forge non se la inventa.

tapp_ci_setupComplete the local release-contract onboarding loop from the shared application model. `inspect` renders a target-aware GitHub workflow and machine-readable CI manifest without writing; `install` writes both with collision protection; `baseline` imports an existing successful conclusive portable-ga…

Complete the local release-contract onboarding loop from the shared application model. `inspect` renders a target-aware GitHub workflow and machine-readable CI manifest without writing; `install` writes both with collision protection; `baseline` imports an existing successful conclusive portable-ga…

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_ui_mapUse Tapp's first-class platform-neutral UI Map: evidence-grounded screen states, semantic controls, transitions, platform variants, provenance, and task/contract coverage hooks.

Use Tapp's first-class platform-neutral UI Map: evidence-grounded screen states, semantic controls, transitions, platform variants, provenance, and task/contract coverage hooks.

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_taskWork with repository-native compositional Tasks in .tapp/tasks. Tasks define inputs, outputs, pre/postconditions, platform implementations, and the UI Map states/transitions they cover.

Work with repository-native compositional Tasks in .tapp/tasks. Tasks define inputs, outputs, pre/postconditions, platform implementations, and the UI Map states/transitions they cover.

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_release_contractWork with repository-native TypeScript release contracts in .tapp/contracts. Contracts express business guarantees through reusable Tasks, named actors, exact/eventual expectations, criticality, policy, and UI Map coverage.

Work with repository-native TypeScript release contracts in .tapp/contracts. Contracts express business guarantees through reusable Tasks, named actors, exact/eventual expectations, criticality, policy, and UI Map coverage.

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_pr_planNessuna descrizione pubblicata

Questo strumento non ha pubblicato alcuna descrizione. Forge non se la inventa.

tapp_flow_runReplay a deterministic, authored end-to-end test (a Flow) against iOS (XCUITest), Android

Replay a deterministic, authored end-to-end test (a Flow) against iOS (XCUITest), Android

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_scenario_runReplay a repository-native system test whose named actors run in isolated browser contexts against shared application state.

Replay a repository-native system test whose named actors run in isolated browser contexts against shared application state.

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_flow_generateWrite a deterministic E2E Flow from a natural-language goal (e.g. 'sign in and open Settings'),

Write a deterministic E2E Flow from a natural-language goal (e.g. 'sign in and open Settings'),

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_flow_saveSave what you've done in the CURRENT interactive session as a reusable, deterministic Flow

Save what you've done in the CURRENT interactive session as a reusable, deterministic Flow

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_ui_treeDump the accessibility (UI) tree of the current screen of an installed iOS or Android app —

Dump the accessibility (UI) tree of the current screen of an installed iOS or Android app —

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_screenshotReturn an inline image of whatever is CURRENTLY on the booted simulator. It does NOT launch or

Return an inline image of whatever is CURRENTLY on the booted simulator. It does NOT launch or

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_open_appLaunch an installed iOS or Android app and return a SCREENSHOT of the screen it lands on

Launch an installed iOS or Android app and return a SCREENSHOT of the screen it lands on

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_list_simulatorsList available iOS simulators (name, udid, state, runtime, booted) so you can pick or boot one before running QA.

List available iOS simulators (name, udid, state, runtime, booted) so you can pick or boot one before running QA.

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_boot_simulatorBoot an iOS simulator by udid (preferred) or name so Tapp can run against it. No-op if already booted.

Boot an iOS simulator by udid (preferred) or name so Tapp can run against it. No-op if already booted.

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_install_appprivilegiatoBuild a target iOS app for the booted simulator and install it, so it's ready for tapp_explore or

Build a target iOS app for the booted simulator and install it, so it's ready for tapp_explore or

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_session_startStart a PERSISTENT interactive session against an installed iOS/Android app, a web URL, or an

Start a PERSISTENT interactive session against an installed iOS/Android app, a web URL, or an

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_focusNessuna descrizione pubblicata

Questo strumento non ha pubblicato alcuna descrizione. Forge non se la inventa.

tapp_session_actPerform ONE action in the active interactive session and get the resulting screen back (the fresh

Perform ONE action in the active interactive session and get the resulting screen back (the fresh

Per questo strumento non è stato pubblicato alcuno schema di input.

tapp_session_endEnd the active interactive session (quits the app + harness). Always call this when done.

End the active interactive session (quits the app + harness). Always call this when done.

Per questo strumento non è stato pubblicato alcuno schema di input.

28 strumenti su 33 hanno pubblicato una descrizione.

I nomi e le descrizioni degli strumenti sono scritti dal publisher e mostrati alla lettera come testo inerte. Sono le stringhe che un client MCP passa a un modello, quindi Forge vi cerca schemi di prompt injection — ogni rilievo compare insieme all’analisi di sicurezza qui sopra. «Privilegiato» è una corrispondenza di parola chiave sul nome dello strumento, non una verifica di ciò che fa: un nome innocuo può comunque fare qualsiasi cosa.

Descrizione

Let coding agents verify UI changes on real iOS, Android, and web surfaces, then enforce reviewed proof in deterministic CI.

Parole chiave
tappcliiosandroidsimulatormcpmcp-serverxcuiteste2etestingqaplaywrightrelease-contractsrelease-gateagentclaudecursorcopilotautomationmobile
Alternative
Confronto delle superfici di strumenti…

Albero delle dipendenze

Ciò che una scansione di Forge ha risolto dai metadati npm il 2026-08-29: risoluzione osservata, non una dichiarazione dell'editore.

60 pacchetti risolti · 2 diretti · nessuno con avvisi di sicurezza La risoluzione si ferma alla profondità 4 e a 60 pacchetti.

La scansione si è fermata al limite di profondità 4. Tutto ciò che sta sotto quel livello non è mai stato risolto.

La scansione si è fermata al limite di 60 pacchetti. Il resto dell'albero non è mai stato risolto.

Altri 36 pacchetti risolti non vengono disegnati qui (limite di visualizzazione: 24). Ogni dipendenza con un avviso di sicurezza viene disegnata comunque. Inventario completo (SBOM CycloneDX)

Dichiarate ma non risolte

54 dipendenze dichiarate non sono mai arrivate nell'albero. Mancano dalla risoluzione di Forge, non dal pacchetto.

+42 altre non elencate. I conteggi per motivo qui sopra le comprendono tutte.

Non seguite: peerDependencies. Questo albero copre solo le dipendenze di runtime, quindi ciò che queste comportano non è mai stato risolto.

Argomenti

Correlati in browser automation & scraping