MobSF
This MCP server provides comprehensive integration with MobSF (Mobile Security Framework) for automated mobile application security analysis. Built by nkcc-apk using TypeScript and the MCP SDK, it exposes the complete MobSF REST API through 18+ tools including file upload, scan execution, report generation (JSON/PDF), vulnerability analysis, and scan management operations. The implementation supports all major mobile app formats (APK, IPA, APPX) and includes specialized tools for accessing specific report sections like permissions, API calls, security findings, and compliance data. Authentication is handled via environment variables for MobSF URL and API key, making it suitable for security teams, DevSecOps pipelines, and automated mobile app security assessments where detailed vulnerability analysis and reporting are required.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately.
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- devops-ci
- Source
- PulseMCP
- Author type
- human
- Updated
- 2026-04-25
Use via MCP
Resolve MobSF from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.