tapflow — security grade SAFE, quality 70/100

Security audit verdict: SAFE · quality 70/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by jo-duchan · MCP Server · ★ 617

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is tapflow safe to install? View the security audit →

About tapflow

A self-hosted Appetize / BrowserStack alternative for mobile QA teams Run iOS simulators and Android emulators in any browser — no toolchain setup, no device pool, no cloud uploads. Your builds, streams, and recordings stay on infrastructure you control. 📖 Docs &nbsp;·&nbsp; 🚀 Quick Start &nbsp;·&nbsp; 🎥 Demo <video src="https://github.com/user-attachments/ass

androidandroid-emulatorapp-testingappetize-alternativebrowserstack-alternativedeveloper-toolsemulatorfluttergood-first-issueios

Quick Facts

Stars617
Forks79
LanguageTypeScript
CategoryMCP Server
LicenseMIT
Quality Score70.0092458480446/100
Open Issues71
Last Updated2026-09-15
Created2026-05-07
Platformsbrowser, mcp, node
Est. Tokens~17k

Compatible Skills

These tools work well together with tapflow for enhanced workflows:

  • agent-device — semantic(0.62)+rare_topics+same_lang+shared_platform (62%)
  • agent-device — semantic(0.62)+rare_topics+same_lang+shared_platform (62%)
  • Shelly — semantic(0.19)+complementary+rare_topics+same_lang+similar_pop+shared_platform (56%)
  • ai-phone — semantic(0.43)+complementary+rare_topics+similar_pop+shared_platform (55%)

tapflow alternative? Top 6 similar tools

Looking for a tapflow alternative? If you're comparing tapflow with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • agent-device by callstackincubator · ⭐ 2.4k

    CLI to control iOS and Android devices for AI agents

  • flutter-skill by ai-dashboad · ⭐ 362

    AI-powered E2E testing for 10 platforms. 253 MCP tools. Zero config. Works with Claude, Cursor, Windsurf, Copi

  • ios-simulator-skill by conorluddy · ⭐ 1.2k

    An IOS Simulator Skill for ClaudeCode. Use it to optimise Claude's ability to build, run and interact with you

  • RocketSimApp by AvdLee · ⭐ 798

    RocketSim — 30+ tools for Xcode's iOS Simulator. Testing, debugging, network monitoring, captures, accessibili

  • agent-skills-standard by HoangNguyen0403 · ⭐ 565

    A collection of Agent Skills Standard and Best Practice for Programming Languages, Frameworks that help our AI

  • ethora by dappros · ⭐ 542

    Open-source engine for chat 💬, AI assistants 🤖 & wallets 🪪. React, Typescript, Python, XMPP. Build future a

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is tapflow?

tapflow is Self-hosted iOS & Android simulator streaming for the whole team. It is categorized as a MCP Server with 617 GitHub stars.

What programming language is tapflow written in?

tapflow is primarily written in TypeScript. It covers topics such as android, android-emulator, app-testing.

How do I install or use tapflow?

You can find installation instructions and usage details in the tapflow GitHub repository at github.com/jo-duchan/tapflow. The project has 617 stars and 79 forks, indicating an active community.

What license does tapflow use?

tapflow is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to tapflow?

The top alternatives to tapflow on Agent Skills Hub include agent-device, flutter-skill, ios-simulator-skill. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools