iOS Forensics MCP Server for analyzing iPhone/iPad file systems
iOS Forensics MCP has solid naming conventions (all tools start with action verbs: list_, read_, identify_, search_, find_, analyze_, execute_, parse_, extract_, generate_). Descriptions are present and generally informative (averaging ~80-120 chars, within the 10-1024 baseline). Input schemas are well-defined with JSON Schema format and parameter descriptions. However, there are moderate gaps: output schemas are not documented (critical for agent chaining), some parameter descriptions lack specific constraints (e.g., search_type enum values not listed), error handling is minimal (returns generic error messages without recovery guidance), and no tool annotations (readOnlyHint, idempotentHint) despite all tools being read-only operations. The server follows basic composition patterns well, tools are focused and single-purpose, but lacks support for pagination/limits (critical for forensic analysis where result sets could be large) and does not address sensitive data handling in outputs (forensic data is inherently sensitive).
Analyze the schema of a SQLite database
Analyze SQLite WAL (Write-Ahead Log) file
Execute a SQL query on a SQLite database
Extract potentially deleted records from WAL files
Find SQLite databases in the iOS file system
Generate a forensic analysis report
Identify the type of a file based on content
List contents of a directory in the iOS file system
No output schemas documented. LLMs cannot understand what fields to expect from tool responses, preventing proper downstream chaining and data extraction. This violates the pattern:tool and pattern:response-shaper requirements.
search_files uses free-form 'search_type' parameter with values 'filename', 'content', 'regex' but these are not declared as enums. Without enum constraints, LLMs may hallucinate invalid search_type values.
generate_report has 'template' and 'format' parameters with known enum values (standard/timeline/executive/technical and markdown/html/json) but these are not declared as enums in the schema, only as descriptions.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 74 | <=2025-11-25 | v2 |
| 2026-03-09 | D | 54 | - | v1 |
Parse a plist file
Read the contents of a file in the iOS file system
Search for files in the iOS file system
No pagination support. Tools like list_directory, search_files, and execute_query can return arbitrarily large result sets that may exhaust the context window. Missing limit, offset/cursor parameters and result truncation guidance.
Error handling is minimal. Responses return generic error strings ('Failed to list directory', 'Failed to read file') without recovery guidance. Violates pattern:recovery-guide, agents cannot self-correct.
No tool annotations (readOnlyHint, idempotentHint, destructiveHint). All 11 tools are read-only and idempotent, but this is not declared to clients. Clients cannot infer safety properties without explicit annotations.
Forensic data outputs (file contents, database records, deleted entries) are sensitive and personally identifying. No guidance on data sanitization, PII handling, or audit logging in tool descriptions. Missing pattern:secret-injection guardrails.
Parameter descriptions lack specificity on constraints. E.g., 'Number of bytes to read' (length param in read_file) has no documented max value; 'SQL query to execute' lacks guidance on allowed SQL dialects or injection prevention; offset/length in read_file lack minimum/maximum bounds.
Path traversal risk. Paths are accepted as 'relative to iOS root' but no validation is shown in tool descriptions. Agents may attempt '../../../' sequences. Server-side validation exists in code (is_path_valid) but not mentioned in tool descriptions, leaving LLMs unaware of the safeguard.
Missing composition: No tool to resolve symbolic links, handle file permissions, or report file metadata (size, timestamps, ownership). Agents need these to reason about forensic evidence validity and chain-of-custody.