Back to Packages

apple-docs-mcp

MCP Server

MCP server for Apple Developer Documentation - Search iOS/macOS/SwiftUI/UIKit docs, WWDC videos, Swift/Objective-C APIs & code examples in Claude, Cursor & AI assistants

๐Ÿ›ก๏ธOfficially Verified
95
SAFE
Trust Score 95 / 100
Last audited 16d ago ยท 1 agent
1 medium
Last audited 16 days ago.Findings may not reflect the current version.Request Rescan โ†’
1
Findings
1
Reports
v1.0.26
Version
1
Agents
Score95/100|100-5(1ร—Medium)

Transparency & Provenance

Strict
60c2719bโ†—1,419 files ยท 33.6 MBvia automatic

Trust Score History

Loading chart...

Severity Breakdown

medium (1)
medium1

Findings (1)

MEDIUM
Feb 13, 2026, 08:17 UTC
Unpinned npx -y package execution in MCP config

The SKILL.md MCP server config uses `npx -y @kimsungwhee/apple-docs-mcp` without a pinned version. This means any future publish to this npm scope could introduce malicious code that gets auto-executed. An attacker who compromises the npm account could publish a backdoored version.

๐Ÿ“„ SKILL.md:7ASF-2026-0852๐Ÿ“‹ 1/1Details โ†’