No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by skwallace36 · MCP Server · ★ 104
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is Pepper safe to install? View the security audit →
Pepper Pepper gives AI agents eyes and hands inside iOS Simulator apps. It injects a shared library into any running simulator app — no source changes, no SDK, no build step. Your agent sees the screen as structured data, taps buttons, inspects live objects, intercepts network calls, reads the heap, and debugs layout issues. Dylib injection requires the simulator; device support uses a different mechanism. https://github.com/user-attachments/assets/42ab3f1b-21f8-48e6-820f-7ca4012fb03b Claude navigating and inspecting Ice Cubes (Mastodon client) with zero source access. Works with Claude Code · Cursor · Claude Desktop · any MCP client Quickstart Requires macOS 14+, Python 3.10+, and an iOS Simulator runtime. Then ask your agent: "Tap through the onboarding flow and make sure every screen looks right" That's it. The agent uses Pepper's MCP tools to see, tap, and inspect — no extra config needed. Other MCP clients (Cursor, Claude Desktop, etc.) Homebrew Tap: [](https://github.com
| Stars | 104 |
| Forks | 10 |
| Language | Swift |
| Category | MCP Server |
| License | MIT |
| Quality Score | 61.5488845660523/100 |
| Open Issues | 40 |
| Last Updated | 2026-04-29 |
| Created | 2026-03-24 |
| Platforms | claude-code, mcp |
| Est. Tokens | ~222k |
These tools work well together with Pepper for enhanced workflows:
Looking for a Pepper alternative? If you're comparing Pepper with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
iOS development ClaudeCode plugin for mindful token and context usage. Contains modular MCPs that group variou
AI-powered E2E testing for 10 platforms. 253 MCP tools. Zero config. Works with Claude, Cursor, Windsurf, Copi
DeepSeek Harness (DSH) plugin: a live iOS Simulator — and a USB-connected iPhone — inside the conversation. 22
Google Analytics 4 data to AI agents, agentic workflows, and MCP clients. Give agents analysis-ready access to
A Model Context Protocol (MCP) server that provides advanced code analysis and reasoning capabilities powered
XCode CLI MCP: Convenience wrapper for Xcode CLI tools & iOS Simulator. Progressive disclosure of tool respons
Explore other popular mcp server tools:
Pepper is iOS dynamic library MCP for agents. It is categorized as a MCP Server with 104 GitHub stars.
Pepper is primarily written in Swift. It covers topics such as accessibility, ai-agent, claude.
You can find installation instructions and usage details in the Pepper GitHub repository at github.com/skwallace36/Pepper. The project has 104 stars and 10 forks, indicating an active community.
Pepper is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to Pepper on Agent Skills Hub include xclaude-plugin, flutter-skill, dsh-ios. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: