hopper-debugger
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECREDENTIALS_UNSAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill includes a specific license order ID (
HOP140213-7833-95831) and provides instructions on how to retrieve the associated.hopperLicensefile from a 1Password vault using a placeholder variable ($one-password). - [COMMAND_EXECUTION]: The skill uses
osascriptto automate UI interactions with theSystem Eventsprocess to dismiss application dialogs. It also executes local shell commands to configure and communicate with theHopperMCPServerbinary through themcportertool. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The agent is instructed to read and summarize disassembly and pseudo-code from native binaries and system frameworks, which are potentially untrusted external inputs.
- Boundary markers: Absent. There are no instructions to use delimiters or specific ignore-rules when processing the output from the disassembler.
- Capability inventory: The skill allows shell command execution, macOS UI automation via AppleScript, and local file access.
- Sanitization: Absent. There is no mention of sanitizing strings or code patterns extracted from binaries before they are processed by the LLM.
Audit Metadata