{"_id":"@appknox/mcp-server","_rev":"2-e94274932595148918438ebd181ed087","name":"@appknox/mcp-server","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.0":{"name":"@appknox/mcp-server","version":"1.0.0","keywords":["mcp","model-context-protocol","appknox","security","mobile-security","appsec","security-testing","sast","dast","vulnerability-scanning","android","ios","ai","llm","claude"],"author":{"name":"Appknox"},"license":"MIT","_id":"@appknox/mcp-server@1.0.0","maintainers":[{"name":"subho007","email":"sunny@appknox.com"},{"name":"ginilpg","email":"ginil@appknox.com"}],"homepage":"https://github.com/appknox/appknox-mcp#readme","bugs":{"url":"https://github.com/appknox/appknox-mcp/issues"},"bin":{"appknox-mcp":"build/index.js"},"dist":{"shasum":"92ab2840f24cbf8b0a27e29acce76c32156d1195","tarball":"https://registry.npmjs.org/@appknox/mcp-server/-/mcp-server-1.0.0.tgz","fileCount":24,"integrity":"sha512-VesbmGVJ4Qz93EQ1A29OmMeX/wwhANFF+s8DiHp0pX1Pn9b+2H44vlg2sdLo0q/BaIs5l52hjFftuE1ohlH8xw==","signatures":[{"sig":"MEQCIHrH9tr6iPCWODaMeqqSj+aKVoo9aW0Q8zVO/s+qqGnqAiBXfVxp0T12Gx+V8QorDnxu/eobNgBVDXsa5U5gjKwpGA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":92740},"main":"build/index.js","type":"module","types":"./build/index.d.ts","engines":{"node":">=18.0.0"},"gitHead":"ff02ee5fd0b484bb6633657771b03359b99817e4","scripts":{"dev":"tsc --watch","build":"tsc && node scripts/verify-build.js","start":"node build/index.js","verify":"node scripts/verify-build.js","prepare":"npm run build","build:tsc":"tsc","prepublishOnly":"npm run build"},"_npmUser":{"name":"ginilpg","email":"ginil@appknox.com"},"repository":{"url":"git+https://github.com/appknox/appknox-mcp.git","type":"git"},"_npmVersion":"10.8.2","description":"Official Model Context Protocol (MCP) server for Appknox - enables AI assistants to perform mobile application security testing","directories":{},"_nodeVersion":"18.20.5","dependencies":{"zod":"^3.24.1","@modelcontextprotocol/sdk":"^1.0.4"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.2","@types/node":"^22.10.2"},"_npmOperationalInternal":{"tmp":"tmp/mcp-server_1.0.0_1768900627168_0.8534450286465618","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@appknox/mcp-server","version":"1.0.1","description":"Official Model Context Protocol (MCP) server for Appknox - enables AI assistants to perform mobile application security testing","main":"build/index.js","type":"module","bin":{"appknox-mcp":"build/index.js"},"scripts":{"build":"tsc && node scripts/verify-build.js","build:tsc":"tsc","dev":"tsc --watch","start":"node build/index.js","verify":"node scripts/verify-build.js","prepare":"npm run build","prepublishOnly":"npm run build"},"keywords":["mcp","model-context-protocol","appknox","security","mobile-security","appsec","security-testing","sast","dast","vulnerability-scanning","android","ios","ai","llm","claude"],"author":{"name":"Appknox"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/appknox/appknox-mcp.git"},"bugs":{"url":"https://github.com/appknox/appknox-mcp/issues"},"homepage":"https://github.com/appknox/appknox-mcp#readme","engines":{"node":">=18.0.0"},"dependencies":{"@modelcontextprotocol/sdk":"^1.0.4","zod":"^3.24.1"},"devDependencies":{"@types/node":"^22.10.2","typescript":"^5.7.2"},"_id":"@appknox/mcp-server@1.0.1","gitHead":"583ce1752dc35448ea65c0dedbf50cc39fb7053e","types":"./build/index.d.ts","_nodeVersion":"18.20.5","_npmVersion":"10.8.2","dist":{"integrity":"sha512-uFQqge1/SwGSR9kLw2ngAh5oSGq2jlpdY32CWRv8nyWw83XeglUFEZOpx3aBC5kfUGsE4bWPR++V5wKxoHu2bw==","shasum":"bee09c184ce0c129bf7263573cdb17a6402354b4","tarball":"https://registry.npmjs.org/@appknox/mcp-server/-/mcp-server-1.0.1.tgz","fileCount":24,"unpackedSize":101560,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIEPtG+HaO55jFZyQ2S0XmkXKk6W7wNbyuKtZclxIT+SeAiBBW06sztCe2jjp+JuEpGH9HlHI3e6QgrMZ33QoPZoFeA=="}]},"_npmUser":{"name":"ginilpg","email":"ginil@appknox.com"},"directories":{},"maintainers":[{"name":"subho007","email":"sunny@appknox.com"},{"name":"ginilpg","email":"ginil@appknox.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-server_1.0.1_1769067592607_0.9168905160780949"},"_hasShrinkwrap":false}},"time":{"created":"2026-01-20T09:17:07.040Z","modified":"2026-01-22T07:39:52.911Z","1.0.0":"2026-01-20T09:17:07.302Z","1.0.1":"2026-01-22T07:39:52.750Z"},"bugs":{"url":"https://github.com/appknox/appknox-mcp/issues"},"author":{"name":"Appknox"},"license":"MIT","homepage":"https://github.com/appknox/appknox-mcp#readme","keywords":["mcp","model-context-protocol","appknox","security","mobile-security","appsec","security-testing","sast","dast","vulnerability-scanning","android","ios","ai","llm","claude"],"repository":{"type":"git","url":"git+https://github.com/appknox/appknox-mcp.git"},"description":"Official Model Context Protocol (MCP) server for Appknox - enables AI assistants to perform mobile application security testing","maintainers":[{"name":"subho007","email":"sunny@appknox.com"},{"name":"ginilpg","email":"ginil@appknox.com"}],"readme":"# Appknox MCP Server\n\nA [Model Context Protocol](https://modelcontextprotocol.io) server that wraps the [Appknox CLI](https://github.com/appknox/appknox-go) for mobile application security testing.\n\n## Prerequisites\n\n- **Node.js** 18 or higher\n- **Appknox CLI** - See [installation instructions](https://github.com/appknox/appknox-go#installation)\n- **Appknox Access Token** - Get from [Appknox Dashboard](https://secure.appknox.com) → Settings → Developer Settings\n\n## Installation\n\n```bash\nnpm install -g @appknox/mcp-server\n```\n\n## Configuration\n\n### Authentication\n\nConfigure your access token using Appknox CLI:\n\n```bash\nappknox init\n```\n\nThis will prompt for your access token and save it to `~/.config/appknox.json`.\n\nAlternatively, set the `APPKNOX_ACCESS_TOKEN` environment variable if you prefer not to use the config file.\n\nFor additional configuration options (API host, region, proxy), see [Appknox CLI documentation](https://github.com/appknox/appknox-go#configuration).\n\n### Claude Desktop Setup\n\nAdd to your Claude Desktop config:\n\n**macOS**: `~/Library/Application Support/Claude/claude_desktop_config.json`\n**Windows**: `%APPDATA%\\Claude\\claude_desktop_config.json`\n\n```json\n{\n  \"mcpServers\": {\n    \"appknox\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@appknox/mcp-server\"]\n    }\n  }\n}\n```\n\nIf you haven't run `appknox init`, you can set the token directly in the config:\n\n```json\n{\n  \"mcpServers\": {\n    \"appknox\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@appknox/mcp-server\"],\n      \"env\": {\n        \"APPKNOX_ACCESS_TOKEN\": \"your-token-here\"\n      }\n    }\n  }\n}\n```\n\n### Environment Variables\n\n| Variable | Description | Default |\n|----------|-------------|---------|\n| `APPKNOX_ACCESS_TOKEN` | Your Appknox API access token | Read from `~/.config/appknox.json` |\n| `APPKNOX_CLI_PATH` | Absolute path to the Appknox CLI binary | `/usr/local/bin/appknox` |\n| `LOG_LEVEL` | Logging level (`debug`, `info`, `warn`, `error`) | `info` |\n\nIf the Appknox CLI is installed in a non-standard location, set `APPKNOX_CLI_PATH`:\n\n```json\n{\n  \"mcpServers\": {\n    \"appknox\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@appknox/mcp-server\"],\n      \"env\": {\n        \"APPKNOX_CLI_PATH\": \"/opt/homebrew/bin/appknox\"\n      }\n    }\n  }\n}\n```\n\nRestart Claude Desktop after updating.\n\n## Available Tools\n\nThe MCP server exposes Appknox CLI commands as tools:\n\n| Tool | Description |\n|------|-------------|\n| `appknox_whoami` | Show current authenticated user information |\n| `appknox_organizations` | List all organizations accessible to the user |\n| `appknox_projects` | List projects with optional filtering by platform, package name, or search query |\n| `appknox_files` | List all files (app versions) for a specific project. Requires `project_id` |\n| `appknox_analyses` | List security analysis results (vulnerabilities) for a file. Requires `file_id` |\n| `appknox_vulnerability` | Get detailed information about a specific vulnerability |\n| `appknox_owasp` | Fetch OWASP category details by ID |\n| `appknox_upload` | Upload an APK/IPA file for security scanning. Returns `file_id` |\n| `appknox_cicheck` | Check vulnerabilities against a risk threshold (for CI/CD pipelines) |\n| `appknox_sarif` | Generate a SARIF report for integration with code analysis tools |\n| `appknox_reports_create` | Create a vulnerability report for a file |\n| `appknox_reports_download` | Download vulnerability report as CSV. Returns content directly |\n| `appknox_dastcheck` | Check DAST (dynamic scan) status and results |\n\n### Tool Workflow\n\nMost tools require IDs that come from other tools:\n\n```\nappknox_projects → project_id → appknox_files → file_id → appknox_analyses\n                                                       → appknox_reports_download\n                                                       → appknox_cicheck\n                                                       → appknox_sarif\n```\n\n## Usage Examples\n\n### Basic Queries\n\n```\n\"Who am I logged in as?\"\n\"List all my organizations\"\n\"Show me all my Android projects\"\n\"List iOS projects with package name containing 'com.example'\"\n```\n\n### Working with Projects and Files\n\n```\n\"List all files for project ID 1234\"\n\"Show me the latest scan results for project 'MyApp'\"\n\"What vulnerabilities were found in file ID 56789?\"\n```\n\n### Uploading and Scanning\n\n```\n\"Upload /Users/me/Downloads/myapp.apk for security scanning\"\n\"Upload the app at /Users/me/Desktop/app.ipa and tell me the file ID\"\n```\n\n> **Important**: File paths must be absolute paths on your local machine (e.g., `/Users/username/Downloads/app.apk`). Drag-and-drop uploads or sandbox paths won't work.\n\n### Security Analysis\n\n```\n\"Show all critical and high vulnerabilities for file ID 12345\"\n\"Check if file ID 12345 passes the security threshold for 'high' risk\"\n\"Run a CI check on file 12345 with medium risk threshold\"\n```\n\n### Reports and Documentation\n\n```\n\"Download the vulnerability report for file ID 12345\"\n\"Generate a SARIF report for file 12345 with high risk threshold\"\n\"Get details about vulnerability ID 67890\"\n\"What is OWASP M1_2016?\"\n```\n\n### CI/CD Integration Scenarios\n\n```\n\"Upload /path/to/app.apk and check if it has any critical vulnerabilities\"\n\"Scan the app and fail if there are any high-risk issues\"\n\"Generate a SARIF report I can upload to GitHub Security\"\n```\n\n### Dynamic Analysis (DAST)\n\n```\n\"Check the DAST scan status for file ID 12345\"\n\"What are the dynamic scan results for file 12345 with medium risk threshold?\"\n```\n\n## Troubleshooting\n\n**Appknox CLI not found**: Verify installation with `which appknox`\n**Authentication failed**: Check your token with `echo $APPKNOX_ACCESS_TOKEN`\n**Debug logging**: Set `LOG_LEVEL=debug` in your environment\n\n## Development\n\n```bash\n# Clone and build\ngit clone https://github.com/appknox/appknox-mcp.git\ncd appknox-mcp\nnpm install\nnpm run build\n\n# add to mcp config\n \"appknox\": {\n    \"command\": \"node\",\n    \"args\": [\"/abosolute/path/to/appknox-mcp/build/index.js\"]\n  }\n```\n\nSee [CONTRIBUTING.md](.github/CONTRIBUTING.md) for contribution guidelines.\n\n## Resources\n\n- [Appknox CLI](https://github.com/appknox/appknox-go)\n- [MCP Specification](https://modelcontextprotocol.io)\n- [Appknox Dashboard](https://secure.appknox.com)\n\n## License\n\nMIT\n","readmeFilename":"README.md"}