apsa
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| --home | No | Data storage directory. Precedence: --home → APSA_HOME → QUAYGATE_HOME → MOBILE_AUDIT_HOME → ~/.local/share/mobile-audit | |
| --root | Yes | Absolute path to a root directory for audited targets. Required. Can be repeated for multiple roots. | |
| APSA_HOME | No | Data storage directory. Precedence: --home → APSA_HOME → QUAYGATE_HOME → MOBILE_AUDIT_HOME → ~/.local/share/mobile-audit | |
| QUAYGATE_HOME | No | Data storage directory. Precedence: --home → APSA_HOME → QUAYGATE_HOME → MOBILE_AUDIT_HOME → ~/.local/share/mobile-audit | |
| --allow-runtime | No | Registers runtime_execute and runtime_start tools at server startup. Set to 'true' to enable. | |
| --allow-any-root | No | Explicitly removes the root restriction. Set to 'true' to enable. | |
| MOBILE_AUDIT_HOME | No | Data storage directory. Precedence: --home → APSA_HOME → QUAYGATE_HOME → MOBILE_AUDIT_HOME → ~/.local/share/mobile-audit |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| capabilitiesA | Discover input types, evidence states, runtime requirements and available interfaces. |
| audit_scanA | Inspect local source/APK/IPA using cached intelligence and save an evidence report. No network or device mutation. |
| intelligence_syncC | Fetch official public mobile advisories and update local cache. Returns per-source failures and scope. |
| audit_startA | Start a persistent offline audit; use jobs_status for progress and jobs_cancel to stop it. |
| jobs_statusC | Read durable job state and progress. An interrupted worker never becomes a successful audit. |
| jobs_cancelA | Request cancellation of an authorized job; poll jobs_status until terminal. |
| jobs_listC | List background jobs visible inside this server's configured roots. |
| intelligence_searchB | Search cached CVEs and OWASP tests with provenance. Does not contact the network. |
| intelligence_getA | Read an exact CVE; refresh=true fetches its official CNA record into cache. |
| reports_listB | List saved audit IDs for exact follow-up reads. |
| reports_getB | Read grounded report context, or the exact evidence for one finding ID. |
| reports_compareB | Compare exact report IDs, retaining coverage differences and unproven remediation states. |
| audit_reassessB | Re-evaluate a saved inventory against current cached intelligence and save a new report. |
| dependency_checkB | Query OSV for inventoried package versions, refresh cached matches and save a reassessed report. |
| runtime_planC | Generate an editable test scenario. Does not run it or log out the app automatically. |
| policy_evaluateC | Evaluate team thresholds, explicit coverage requirements and expiring waivers without changing reports. |
| runtime_devicesA | List adb devices and available iOS simulators without changing app state. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| audit_mobile_app | A model-neutral workflow for an authorized local mobile app audit. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| rule_catalog | |
| rule_catalog | |
| rule_catalog |
TDQS
Scored across 17 tools
Most tools target clearly distinct resources and actions, and descriptions clarify boundaries well. The main risk is mild overlap among audit_scan, audit_start, and audit_reassess, plus reports_get/list/compare, but each has a defined role.
Tool names consistently use snake_case and domain prefixes such as reports_, jobs_, intelligence_, and audit_. A few names are noun-oriented rather than verb_noun, but the overall convention is predictable.
At 17 tools the server is slightly above the ideal 3-15 range, but the surface covers several legitimate areas: auditing, intelligence, jobs, reports, runtime, and policy. Each tool appears to earn its place without obvious redundancy.
The set covers core audit lifecycle operations, cached intelligence access, report reading/comparison, background job control, dependency checks, and runtime planning. Minor gaps remain, such as policy CRUD or report deletion/export, but these are not fatal for the apparent domain.