@aarwitz/tapp

MCPcommunity
v0.17.18io.github.aarwitzMITUpdated 10d agonpmGitHub

Let coding agents verify UI changes on real iOS, Android, and web surfaces, then enforce reviewed proof in deterministic CI.

Works in
ClaudeCursorCopilotGemini

Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
1kDownloads/wk
2GitHub stars
10d agoLast update
Package
Authorio.github.aarwitz
LicenseMIT
Version0.17.18
Sourcenpm+mcp-registry
Trust Status
B
60/100Good
✓Listed in Forge index+10/10
—Publisher identity verified+0/20
→ Publisher: run `forge publish` from the package repo to claim ownership
—Ed25519 publish signature+0/5
→ Included automatically when the publisher runs `forge publish`
—Domain verification+0/5
→ Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
—npm Trusted Publishing (Sigstore)+0/5
→ Publish from GitHub Actions with --provenance so the attestation binds this package to this repo
—npm maintainer match+0/5
→ Earned once your identity is verified above and that login is an npm maintainer of this package
✓CVE scan · clean+30/30
✓Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain—
Provenance—
Dependencies✓ 60 resolved+ · none vulnerable
Tool surface33 tools · 1 privileged
Security scan✓ Cleanv0.17.3 · 1mo agoHow well does this scan work?
EvalsNone
IndexedAug 20, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

33 tools · 1 privileged
Statically extracted from the published packagev0.17.3 · 1mo ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

checkoutCreatesDurableOrderNo description published

This tool published no description. Forge does not invent one.

test-appUse Tapp's real app surfaces to inspect, drive, or explore this repository and report evidence honestly.

Use Tapp's real app surfaces to inspect, drive, or explore this repository and report evidence honestly.

No input schema was published for this tool.

goalWhat to verify, such as finding bugs or exercising checkout

What to verify, such as finding bugs or exercising checkout

No input schema was published for this tool.

targetOptional repo target, bundle/app id, APK path, or owned URL

Optional repo target, bundle/app id, APK path, or owned URL

No input schema was published for this tool.

tapp_healthCheck Tapp workspace and toolchain availability

Check Tapp workspace and toolchain availability

No input schema was published for this tool.

tapp_buildBuild the user's iOS app for the simulator from an Xcode project/workspace (auto-detects the

Build the user's iOS app for the simulator from an Xcode project/workspace (auto-detects the

No input schema was published for this tool.

tapp_captureRun headless capture workflows using scripts/quick-capture.sh

Run headless capture workflows using scripts/quick-capture.sh

No input schema was published for this tool.

tapp_parse_markersParse OCQA markers from a capture run into structured summary

Parse OCQA markers from a capture run into structured summary

No input schema was published for this tool.

tapp_list_capturesList recent capture runs from captures/

List recent capture runs from captures/

No input schema was published for this tool.

tapp_capture_summaryShow summary metadata for a capture run

Show summary metadata for a capture run

No input schema was published for this tool.

tapp_exploreAutonomously explore iOS (appBundleId), Android (androidAppId), OR a web app

Autonomously explore iOS (appBundleId), Android (androidAppId), OR a web app

No input schema was published for this tool.

tapp_initNo description published

This tool published no description. Forge does not invent one.

tapp_actor_configManage the repository-native .tapp/project.json actor/session contract used by init, release-contract generation, and CI. `read` is inspect-only. `set` writes an explicit actor role, isolation/provisioning policy, and credential-name to environment-variable-name bindings. The tool never accepts, re…

Manage the repository-native .tapp/project.json actor/session contract used by init, release-contract generation, and CI. `read` is inspect-only. `set` writes an explicit actor role, isolation/provisioning policy, and credential-name to environment-variable-name bindings. The tool never accepts, re…

No input schema was published for this tool.

tapp_release_planNo description published

This tool published no description. Forge does not invent one.

tapp_ci_setupComplete the local release-contract onboarding loop from the shared application model. `inspect` renders a target-aware GitHub workflow and machine-readable CI manifest without writing; `install` writes both with collision protection; `baseline` imports an existing successful conclusive portable-ga…

Complete the local release-contract onboarding loop from the shared application model. `inspect` renders a target-aware GitHub workflow and machine-readable CI manifest without writing; `install` writes both with collision protection; `baseline` imports an existing successful conclusive portable-ga…

No input schema was published for this tool.

tapp_ui_mapUse Tapp's first-class platform-neutral UI Map: evidence-grounded screen states, semantic controls, transitions, platform variants, provenance, and task/contract coverage hooks.

Use Tapp's first-class platform-neutral UI Map: evidence-grounded screen states, semantic controls, transitions, platform variants, provenance, and task/contract coverage hooks.

No input schema was published for this tool.

tapp_taskWork with repository-native compositional Tasks in .tapp/tasks. Tasks define inputs, outputs, pre/postconditions, platform implementations, and the UI Map states/transitions they cover.

Work with repository-native compositional Tasks in .tapp/tasks. Tasks define inputs, outputs, pre/postconditions, platform implementations, and the UI Map states/transitions they cover.

No input schema was published for this tool.

tapp_release_contractWork with repository-native TypeScript release contracts in .tapp/contracts. Contracts express business guarantees through reusable Tasks, named actors, exact/eventual expectations, criticality, policy, and UI Map coverage.

Work with repository-native TypeScript release contracts in .tapp/contracts. Contracts express business guarantees through reusable Tasks, named actors, exact/eventual expectations, criticality, policy, and UI Map coverage.

No input schema was published for this tool.

tapp_pr_planNo description published

This tool published no description. Forge does not invent one.

tapp_flow_runReplay a deterministic, authored end-to-end test (a Flow) against iOS (XCUITest), Android

Replay a deterministic, authored end-to-end test (a Flow) against iOS (XCUITest), Android

No input schema was published for this tool.

tapp_scenario_runReplay a repository-native system test whose named actors run in isolated browser contexts against shared application state.

Replay a repository-native system test whose named actors run in isolated browser contexts against shared application state.

No input schema was published for this tool.

tapp_flow_generateWrite a deterministic E2E Flow from a natural-language goal (e.g. 'sign in and open Settings'),

Write a deterministic E2E Flow from a natural-language goal (e.g. 'sign in and open Settings'),

No input schema was published for this tool.

tapp_flow_saveSave what you've done in the CURRENT interactive session as a reusable, deterministic Flow

Save what you've done in the CURRENT interactive session as a reusable, deterministic Flow

No input schema was published for this tool.

tapp_ui_treeDump the accessibility (UI) tree of the current screen of an installed iOS or Android app —

Dump the accessibility (UI) tree of the current screen of an installed iOS or Android app —

No input schema was published for this tool.

tapp_screenshotReturn an inline image of whatever is CURRENTLY on the booted simulator. It does NOT launch or

Return an inline image of whatever is CURRENTLY on the booted simulator. It does NOT launch or

No input schema was published for this tool.

tapp_open_appLaunch an installed iOS or Android app and return a SCREENSHOT of the screen it lands on

Launch an installed iOS or Android app and return a SCREENSHOT of the screen it lands on

No input schema was published for this tool.

tapp_list_simulatorsList available iOS simulators (name, udid, state, runtime, booted) so you can pick or boot one before running QA.

List available iOS simulators (name, udid, state, runtime, booted) so you can pick or boot one before running QA.

No input schema was published for this tool.

tapp_boot_simulatorBoot an iOS simulator by udid (preferred) or name so Tapp can run against it. No-op if already booted.

Boot an iOS simulator by udid (preferred) or name so Tapp can run against it. No-op if already booted.

No input schema was published for this tool.

tapp_install_appprivilegedBuild a target iOS app for the booted simulator and install it, so it's ready for tapp_explore or

Build a target iOS app for the booted simulator and install it, so it's ready for tapp_explore or

No input schema was published for this tool.

tapp_session_startStart a PERSISTENT interactive session against an installed iOS/Android app, a web URL, or an

Start a PERSISTENT interactive session against an installed iOS/Android app, a web URL, or an

No input schema was published for this tool.

tapp_focusNo description published

This tool published no description. Forge does not invent one.

tapp_session_actPerform ONE action in the active interactive session and get the resulting screen back (the fresh

Perform ONE action in the active interactive session and get the resulting screen back (the fresh

No input schema was published for this tool.

tapp_session_endEnd the active interactive session (quits the app + harness). Always call this when done.

End the active interactive session (quits the app + harness). Always call this when done.

No input schema was published for this tool.

28 of 33 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Let coding agents verify UI changes on real iOS, Android, and web surfaces, then enforce reviewed proof in deterministic CI.

Keywords
tappcliiosandroidsimulatormcpmcp-serverxcuiteste2etestingqaplaywrightrelease-contractsrelease-gateagentclaudecursorcopilotautomationmobile
Alternatives
Comparing tool surfaces…

Dependency tree

What one Forge scan resolved from npm metadata on 2026-08-29 — observed resolution, not a publisher declaration.

60 packages resolved · 2 direct · none carrying advisories Resolution stops at depth 4 and 60 packages.

The crawl stopped at the depth-4 limit. Anything below that level was never resolved.

The crawl stopped at the 60-package limit. The rest of the tree was never resolved.

36 more resolved packages are not drawn here (display cap: 24). Every dependency carrying an advisory is drawn regardless of the cap. Full inventory (CycloneDX SBOM)

Declared but not resolved

54 declared dependencies never landed in the tree. They are missing from Forge's resolution, not from the package.

+42 more not listed. The counts by reason above cover all of them.

Not followed: peerDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.

Topics

Related in browser automation & scraping