Aosp Platform Builder Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Aosp Platform Builder Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server that connects to a GCP-hosted AOSP build VM via IAP tunnel, uploads APKs as privileged system apps, and builds system.img.
aosp-platform-builder-mcp/
├── connection.json ← Your GCP/AOSP config (edit this)
├── .env.example
├── pyproject.toml
├── requirements.txt
├── skills.md ← Exhaustive Claude skill definition
├── README.md
└── src/
├── server.py ← MCP server (8 tools)
├── tools/
│ ├── gcp.py ← connect_gcp
│ ├── apk.py ← upload_apk
│ ├── module.py ← create_priv_app_module
│ ├── config.py ← patch_product_config
│ └── build.py ← run_lunch, build_systemimage,
│ stream_build_logs, exec_remote
└── utils/
├── config.py ← Loads connection.json
├── shell.py ← Local command execution
├── ssh.py ← gcloud compute ssh/scp (IAP)
└── validation.py ← Input sanitization# 1. Install
cd aosp-platform-builder-mcp
pip install -e .
# 2. Authenticate
gcloud auth login
# 3. Edit connection.json with your details (pre-filled for current setup)
# 4. Register with Claude Code — add to ~/.claude/settings.json:{
"mcpServers": {
"aosp-platform-builder": {
"command": "python",
"args": ["-m", "src.server"],
"cwd": "/Users/jai.goyal/aosp-platform-builder-mcp"
}
}
}| Setting | Value |
|---|---|
| GCP Project | glancecdn-sandbox-c32a |
| Zone | asia-south1-c |
| VM | aosp-build-vm-replica-1 |
| SSH User | jai.goyal |
| IAP Tunnel | enabled |
| AOSP Root | /home/jai.goyal/a16 |
| Lunch Target | aosp_arm64-bp2a-userdebug |
| Build Command | make -j96 |
| Output | out/target/product/generic_arm64/system.img |
User: "connect and upload my apk and add this apk as a priv-app"
Claude:
1. Asks for APK path
2. connect_gcp → auth + start VM + test SSH
3. upload_apk → validate + scp + extract package name
4. create_priv_app_module → Android.bp in vendor/glance/priv-app/
5. patch_product_config → PRODUCT_PACKAGES += Module
6. run_lunch → lunch aosp_arm64-bp2a-userdebug
7. build_systemimage → make -j96
8. Returns system.img path~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.