Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | XcodeBuildMCPWatchlist candidate | Windows-MCPMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | Community implementation com.xcodebuildmcp · Publisher source ↗ | Community implementation io.github.CursorTouch · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Aug 12, 2026 Package: Jul 23, 2026 | Repo: Aug 14, 2026 Package: Aug 1, 2026 |
| Popularity evidence | ||
| GitHub stars | 6,236 GitHub stars · checked 2026-08-14T18:46:26.000Z | 6,749 GitHub stars · checked 2026-08-14T18:46:26.000Z |
| 30-day package downloads | 511,181 30-day package downloads · checked 2026-08-14T18:46:26.000Z | 40,449 PyPI Stats package downloads · checked 2026-08-14T18:46:26.000Z |
| External adoption evidence |
|
|
| Client coverage | ||
| Client coverage details | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | Local stdio and on-demand setup are documented without MCP authentication or tokens. Device operations require Xcode code signing. | Stdio has no network listener. Non-loopback HTTP requires an auth key or OAuth unless insecure access is explicitly allowed; IP allowlists, TLS, CORS, and host validation are documented. |
| Cost | The MIT-licensed npm and Homebrew distributions list no MCP fee. macOS, Xcode, devices, client, and model costs are separate. | The MIT-licensed project lists no MCP fee. Windows, Python, hosting, client, and model costs are separate. |
| Permissions | Builds and tests Xcode projects, controls simulators and devices, automates UI, captures screenshots, debugs, and performs related iOS and macOS workflows. Official manifests mark build operations as non-read-only. | Runs with the invoking user's full Windows permissions, including PowerShell, files, registry, processes, UI input, screenshots, and web scraping; many actions are irreversible. |
| Data handling | Processes project paths, build products, logs, simulator and device state, screenshots, and test and debug output. The publisher says Sentry receives internal runtime error telemetry; retention and model-training behavior are not documented. | Processing is local. Telemetry excludes screenshots, state captures, arguments, and outputs but includes status, duration, tool and client information, anonymized sessions, and possibly paths in error messages. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | Can build, test, launch, inspect, and automate projects and devices using non-read-only operations and runtime telemetry. Restrict project and device scope and review commands before execution. | It is not sandboxed and can delete files, alter registry or system settings, type into applications, and execute PowerShell. Use a VM or low-privilege account, backups, supervision, loopback binding, and disabled high-risk tools. |
| Evidence date | ||
| Editorial review | 2026-08-11 | 2026-08-11 |
| Candidate evidence | 2026-08-14T18:46:26.000Z | 2026-08-14T18:46:26.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →