hopper-debugger

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill includes a specific license order ID (HOP140213-7833-95831) and provides instructions on how to retrieve the associated .hopperLicense file from a 1Password vault using a placeholder variable ($one-password).
  • [COMMAND_EXECUTION]: The skill uses osascript to automate UI interactions with the System Events process to dismiss application dialogs. It also executes local shell commands to configure and communicate with the HopperMCPServer binary through the mcporter tool.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The agent is instructed to read and summarize disassembly and pseudo-code from native binaries and system frameworks, which are potentially untrusted external inputs.
  • Boundary markers: Absent. There are no instructions to use delimiters or specific ignore-rules when processing the output from the disassembler.
  • Capability inventory: The skill allows shell command execution, macOS UI automation via AppleScript, and local file access.
  • Sanitization: Absent. There is no mention of sanitizing strings or code patterns extracted from binaries before they are processed by the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:27 PM
Security Audit — agent-trust-hub — hopper-debugger