ios-mcp-jailbreak-automation

Fail

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The 'run_command' tool enables the execution of arbitrary shell commands on the target iOS device. This allows for full system control and the execution of potentially malicious scripts with elevated privileges facilitated by the 'mcp-root' helper.
  • [COMMAND_EXECUTION]: The 'install_app' tool allows for the installation of arbitrary IPA files from a local device path, which could be used to deploy unauthorized or malicious software onto the iPhone.
  • [DATA_EXFILTRATION]: Multiple tools provide access to sensitive user information. The 'screenshot' tool captures the device screen as Base64 data, and 'get_clipboard' reads the system clipboard, both of which can contain private communications, credentials, or personal data.
  • [EXTERNAL_DOWNLOADS]: The skill's configuration instructions utilize 'npx' to download and execute '@modelcontextprotocol/server-fetch' at runtime to establish the connection between the AI agent and the iOS device.
  • [DATA_EXFILTRATION]: The 'open_url' tool can be used to trigger URL schemes or navigate to external websites, which may be leveraged to leak device information or interact with other applications on the device.
  • [COMMAND_EXECUTION]: The skill provides granular control over device hardware and UI, including simulated touches ('tap_screen', 'swipe_screen') and hardware button presses, which could be used to bypass local UI confirmations or modify device settings.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 15, 2026, 01:04 AM
Security Audit — agent-trust-hub — ios-mcp-jailbreak-automation