@akoskomuves/appstoreconnect-mcp

MCPattested
v1.0.1Akos KomuvesMITUpdated 3mo agonpmGitHub

Model Context Protocol server for the Apple App Store Connect API.

Works in
ClaudeCursorCopilotGemini

Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Attested build
A verified provenance attestation binds this artifact to the listed repository. Nobody has claimed the listing yet — this proves where the code was built, not who stands behind it.
1kDownloads/wk
3mo agoLast update
Package
AuthorAkos Komuves
LicenseMIT
Version1.0.1
Sourcenpm+mcp-registry
Trust Status
A
85/100Trusted
✓Listed in Forge index+10/10
✓Identity verified · attested build+20/20
—Ed25519 publish signature+0/5
→ Included automatically when the publisher runs `forge publish`
—Domain verification+0/5
→ Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—npm maintainer match+0/5
→ Publisher: add the verified GitHub login to the npm package's maintainers (npm owner add <login>)
✓CVE scan · clean+30/30
✓Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusIdentity verified
PublisherUnverified
SignatureUnsigned
Domain—
Provenance✓ Sigstore-verified · e9b45b8
Dependencies✓ 60 resolved+ · none vulnerable
Tool surface40 tools · 11 privileged
Security scan⚠ Warnings (0)v1.9.0 · 1mo agoHow well does this scan work?
CHANGEtool-addedTool surface grew since v1.0.1: added asc_get_age_rating_declaration, asc_patch_age_rating_declaration (privileged) — review before updating
EvalsNone
IndexedJun 17, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

40 tools · 11 privileged
Statically extracted from the published packagev1.9.0 · 1mo ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

Surface history
CHANGETool surface grew since v1.0.1: added asc_get_age_rating_declaration, asc_patch_age_rating_declaration (privileged) — review before updating
asc_list_accessibility_declarationsNo description published

This tool published no description. Forge does not invent one.

asc_post_accessibility_declarationNo description published

This tool published no description. Forge does not invent one.

asc_patch_accessibility_declarationprivilegedNo description published

This tool published no description. Forge does not invent one.

asc_delete_accessibility_declarationprivilegedNo description published

This tool published no description. Forge does not invent one.

asc_get_age_rating_declarationNo description published

This tool published no description. Forge does not invent one.

asc_patch_age_rating_declarationprivilegedNo description published

This tool published no description. Forge does not invent one.

asc_list_alternative_distribution_domainsNo description published

This tool published no description. Forge does not invent one.

asc_post_alternative_distribution_domainNo description published

This tool published no description. Forge does not invent one.

asc_delete_alternative_distribution_domainprivilegedNo description published

This tool published no description. Forge does not invent one.

asc_list_alternative_distribution_keysNo description published

This tool published no description. Forge does not invent one.

asc_get_app_alternative_distribution_keyNo description published

This tool published no description. Forge does not invent one.

asc_post_alternative_distribution_keyNo description published

This tool published no description. Forge does not invent one.

asc_delete_alternative_distribution_keyprivilegedNo description published

This tool published no description. Forge does not invent one.

asc_post_alternative_distribution_packageNo description published

This tool published no description. Forge does not invent one.

asc_get_version_alternative_distribution_packageNo description published

This tool published no description. Forge does not invent one.

asc_list_alternative_distribution_package_versionsNo description published

This tool published no description. Forge does not invent one.

asc_list_alternative_distribution_package_variantsNo description published

This tool published no description. Forge does not invent one.

asc_list_alternative_distribution_package_deltasNo description published

This tool published no description. Forge does not invent one.

asc_get_marketplace_search_detailNo description published

This tool published no description. Forge does not invent one.

asc_post_marketplace_search_detailNo description published

This tool published no description. Forge does not invent one.

asc_patch_marketplace_search_detailprivilegedNo description published

This tool published no description. Forge does not invent one.

asc_delete_marketplace_search_detailprivilegedNo description published

This tool published no description. Forge does not invent one.

asc_list_marketplace_webhooksNo description published

This tool published no description. Forge does not invent one.

asc_post_marketplace_webhookNo description published

This tool published no description. Forge does not invent one.

asc_patch_marketplace_webhookprivilegedNo description published

This tool published no description. Forge does not invent one.

asc_delete_marketplace_webhookprivilegedNo description published

This tool published no description. Forge does not invent one.

asc_post_analytics_report_requestNo description published

This tool published no description. Forge does not invent one.

asc_list_analytics_report_requestsNo description published

This tool published no description. Forge does not invent one.

asc_delete_analytics_report_requestprivilegedNo description published

This tool published no description. Forge does not invent one.

asc_list_analytics_reportsNo description published

This tool published no description. Forge does not invent one.

asc_list_analytics_report_instancesNo description published

This tool published no description. Forge does not invent one.

asc_list_analytics_report_segmentsNo description published

This tool published no description. Forge does not invent one.

asc_download_analytics_report_segmentNo description published

This tool published no description. Forge does not invent one.

asc_get_app_availability_v2No description published

This tool published no description. Forge does not invent one.

asc_list_territory_availabilitiesNo description published

This tool published no description. Forge does not invent one.

asc_post_app_availability_v2No description published

This tool published no description. Forge does not invent one.

asc_end_app_availability_pre_orderNo description published

This tool published no description. Forge does not invent one.

asc_patch_territory_availabilityprivilegedNo description published

This tool published no description. Forge does not invent one.

asc_list_app_event_screenshotsNo description published

This tool published no description. Forge does not invent one.

asc_get_app_event_screenshotNo description published

This tool published no description. Forge does not invent one.

0 of 40 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

Model Context Protocol server for the Apple App Store Connect API.

Keywords
mcpmodel-context-protocolclaudeanthropicapp-store-connectappstoreconnectappstoreiosascsubscription-pricingppp
Alternatives
Comparing tool surfaces…

No dependency coverage

This package was last scanned before Forge began storing the resolved tree. The next scan will record it.