Build, sign, and publish iOS and Android apps through AI agents.
This MCP tool claims to integrate Codemagic CI/CD, App Store Connect, and Google Play to build, sign, and publish mobile apps. While the materials indicate it is open source and does not list explicit environment variables, its function inherently touches sensitive release workflows and local code execution, and the sparse documentation and unknown maintenance status warrant caution.
The material states there are no required keys or environment variables, but integrating Codemagic, App Store Connect, and Google Play typically involves platform credentials, signing assets, or session-based authorization. With no README details, it is unclear how credentials are supplied, stored, or isolated, creating a moderate credential-handling concern.
No remote endpoints are listed, but the stated functionality explicitly includes integration with Codemagic CI/CD, App Store Connect, and Google Play, so outbound communication to those relevant services is expected for build, signing, or publishing workflows. There is no evidence of unrelated or unknown endpoints, but the scope and content of data egress are not transparently documented.
The system flags this tool as executes-code, and its stated purpose is to build and publish iOS/Android apps, so it is reasonable to expect it to trigger local or controlled build/signing commands and processes. This is a standard high-privilege capability for this type of MCP tool, and the provided material does not show any abnormal system permission requests beyond its stated purpose.
To build, sign, and publish mobile apps, the tool will likely need access to project source code, build artifacts, configuration files, and possibly signing-related files. The lack of a README means the exact read/write scope, least-privilege design, and whether it touches data beyond release workflow needs cannot be verified, so the data exposure surface should be treated with caution.
Positive signals include an open-source repository and an MIT license, which make auditing possible in principle. However, it comes from a third-party registry, has 0 stars, unknown maintenance status, and almost no documentation, which reduces verifiability and maturity. There is not enough concrete red-flag evidence to rate it as high risk, but supply-chain trust remains limited.
Copy the install command and let the AI configure it · recommended for beginners
No copy-paste install info for "codemagic-mcp-server" yet — see the docs or source repo.
Use Codemagic MCP to create a release workflow for my Flutter app: pull code from the main branch, build iOS and Android release artifacts, sign them with configured certificates, and publish them to App Store Connect and the Google Play internal testing track.
A runnable workflow for building, signing, and publishing the app to both stores.
Configure Codemagic CI/CD for my React Native project: when code is pushed to the release branch, automatically run dependency installation, tests, Android APK/AAB builds, and iOS IPA builds, and provide an error summary if anything fails.
A project-ready CI/CD configuration plan with failure diagnostics summaries.
Check the integration status of Codemagic, App Store Connect, and Google Play. List available release targets, missing credential configurations, and risk items that could block automated publishing.
A release integration report showing publishing readiness and issues to fix.
Generate app icons with AI, resize assets, and publish apps to stores.
Build, debug, and automate work on iOS and macOS projects.
Manage App Store Connect apps, builds, submissions, and analytics with natural language.
Connect AI to Codinfy APIs for licensing, checkout, analytics, and identity workflows.
Connect IDEs or AI assistants to Codex CLI for safe automation and code analysis.
Build, install, debug, and inspect Android and iOS apps with AI.