# simframe

Always-warm iOS Simulator and Android emulator frames: agents read the screen in ~20ms instead of waiting on screenshots. MCP server + CLI.

- **Type:** MCP server
- **Trust:** 85/100 (A), scored on the package rubric
- **Verification:** verified (build provenance)
- **Version:** 0.20.1
- **Author:** Sadjad Asadi
- **License:** MIT
- **npm:** simframe
- **Source:** https://github.com/lvlrSajjad/simframe
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

85/100 (A), scored on the package rubric
- Publisher verified: no
- Build provenance: verified attestation
- npm trusted publishing (OIDC): yes
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 25 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-11T21:41:48.441Z
- **Version scanned:** 0.12.1
- **CVEs:** none found by OSV at scan time

## Tools

20 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `sim_ui` — READ THE SCREEN as text: every element numbered, with region, type, label, state, contents and tap point, plus which screen this is and what simframe knows abou
- `sim_do` — THE MAIN TOOL, and the cheapest path. Plan the WHOLE flow and run it in one call — tap, type, scroll, wait, assert — asserting after each step that matters. Eve
- `sim_tap` — Tap one thing. For more than one step, use sim_do — it batches the verification and costs one round trip. Returns the screen map afterwards.
- `sim_type_into` — Focus a field and type into it. Prefer a sim_do step when this is part of a sequence.
- `sim_scroll_to` — Scroll until something is in view. A control that scrolled off the bottom of a list is not missing, and this is the difference.
- `sim_wait_for` — Block until something appears on screen, then return the screen map. Use this instead of pausing and re-reading.
- `sim_assert` — Check one thing about the screen and fail loudly if it is not so. Cheaper inside a sim_do flow, where a failed assert stops the remaining steps.
- `sim_goto` — Walk to a screen simframe already knows, over edges it has already verified, with no model call per step. Names come from sim_recall or a previous map. Refuses 
- `sim_flow_run` — Replay a saved flow by name, verifying each step. Omit `name` to list the saved flows. Save one with sim_do's `saveAs`.
- `sim_launch` — Launch or relaunch an app, optionally with launch arguments and environment variables — the way to put an app into a test mode without touching its UI.
- `sim_open_url` — Open a URL or deep link on the device — the fastest way to reach a screen when the app has a link for it.
- `sim_permission`
- `sim_find` — Resolve one intent to one control: "tap Save", "the Assets tab", "back". Understands verbs, typos, and where on screen you meant. When two things answer equally
- `sim_state` — Cheapest possible check: a stable screen hash, whether anything changed SINCE YOUR LAST LOOK in this session, how long the screen has been still, and an ASCII m
- `sim_wait` — Wait for the screen to change, settle, or both. sim_do already settles after every step, so you rarely need this inside a flow — reach for it when something mov
- `sim_look` — A screenshot: ~1600 tokens, the most expensive call here. Only for what text cannot answer — layout, colour, spacing, a control the map omits. NOT for what a fi
- `sim_strip` — Return the last few buffered frames tiled into ONE image, oldest first — an image, so not cheap. Lets you understand a transition, animation or flicker in a sin
- `sim_recall` — What happened recently, as text: the screens visited, the actions taken, and what each one did. Use it to re-orient after a failure instead of taking a screensh
- `sim_capture` — Inspect or control the background capture loops: action "status" (what is running and how fresh), "start", "stop". Capture starts automatically on first use, so
- `sim_devices` — List the booted devices simframe can drive — iOS simulators and Android emulators.

## Install

**Verdict: install** — No blocking findings and no open coverage gaps — safe to install as configured.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"simframe\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"simframe\"\n      ]\n    }\n  }\n}"
```

## Blast radius

Contained to moderate — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: runs on your machine; read-only tool surface.
- Floor 13, ceiling 31 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/simframe
- Install plan: https://forgeregistry.com/api/v1/packages/simframe/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/simframe
- HTML page: https://forgeregistry.com/registry/simframe
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
