Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
--homeNoData storage directory. Precedence: --home → APSA_HOME → QUAYGATE_HOME → MOBILE_AUDIT_HOME → ~/.local/share/mobile-audit
--rootYesAbsolute path to a root directory for audited targets. Required. Can be repeated for multiple roots.
APSA_HOMENoData storage directory. Precedence: --home → APSA_HOME → QUAYGATE_HOME → MOBILE_AUDIT_HOME → ~/.local/share/mobile-audit
QUAYGATE_HOMENoData storage directory. Precedence: --home → APSA_HOME → QUAYGATE_HOME → MOBILE_AUDIT_HOME → ~/.local/share/mobile-audit
--allow-runtimeNoRegisters runtime_execute and runtime_start tools at server startup. Set to 'true' to enable.
--allow-any-rootNoExplicitly removes the root restriction. Set to 'true' to enable.
MOBILE_AUDIT_HOMENoData storage directory. Precedence: --home → APSA_HOME → QUAYGATE_HOME → MOBILE_AUDIT_HOME → ~/.local/share/mobile-audit

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
capabilitiesA

Discover input types, evidence states, runtime requirements and available interfaces.

audit_scanA

Inspect local source/APK/IPA using cached intelligence and save an evidence report. No network or device mutation.

intelligence_syncC

Fetch official public mobile advisories and update local cache. Returns per-source failures and scope.

audit_startA

Start a persistent offline audit; use jobs_status for progress and jobs_cancel to stop it.

jobs_statusC

Read durable job state and progress. An interrupted worker never becomes a successful audit.

jobs_cancelA

Request cancellation of an authorized job; poll jobs_status until terminal.

jobs_listC

List background jobs visible inside this server's configured roots.

intelligence_searchB

Search cached CVEs and OWASP tests with provenance. Does not contact the network.

intelligence_getA

Read an exact CVE; refresh=true fetches its official CNA record into cache.

reports_listB

List saved audit IDs for exact follow-up reads.

reports_getB

Read grounded report context, or the exact evidence for one finding ID.

reports_compareB

Compare exact report IDs, retaining coverage differences and unproven remediation states.

audit_reassessB

Re-evaluate a saved inventory against current cached intelligence and save a new report.

dependency_checkB

Query OSV for inventoried package versions, refresh cached matches and save a reassessed report.

runtime_planC

Generate an editable test scenario. Does not run it or log out the app automatically.

policy_evaluateC

Evaluate team thresholds, explicit coverage requirements and expiring waivers without changing reports.

runtime_devicesA

List adb devices and available iOS simulators without changing app state.

Prompts

Interactive templates invoked by user choice

NameDescription
audit_mobile_appA model-neutral workflow for an authorized local mobile app audit.

Resources

Contextual data attached and managed by the client

NameDescription
rule_catalog
rule_catalog
rule_catalog

TDQS

B3.2/5.0

Scored across 17 tools

Disambiguation4/5

Most tools target clearly distinct resources and actions, and descriptions clarify boundaries well. The main risk is mild overlap among audit_scan, audit_start, and audit_reassess, plus reports_get/list/compare, but each has a defined role.

Naming Consistency4/5

Tool names consistently use snake_case and domain prefixes such as reports_, jobs_, intelligence_, and audit_. A few names are noun-oriented rather than verb_noun, but the overall convention is predictable.

Tool Count4/5

At 17 tools the server is slightly above the ideal 3-15 range, but the surface covers several legitimate areas: auditing, intelligence, jobs, reports, runtime, and policy. Each tool appears to earn its place without obvious redundancy.

Completeness4/5

The set covers core audit lifecycle operations, cached intelligence access, report reading/comparison, background job control, dependency checks, and runtime planning. Minor gaps remain, such as policy CRUD or report deletion/export, but these are not fatal for the apparent domain.

Maintenance

ActivityMaintained
ResponsivenessNo issues