creator-record-strategy
Fail
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to fetch and process content from
https://paperclip.right.link/, a domain specifically flagged as malicious and blacklisted by URLite scanners. - [EXTERNAL_DOWNLOADS]: The file
references/docs/paperclip-operator/cli-contract.mdhas been flagged as infected by antivirus software (MD:HttpRequest-inf [Susp]). - [REMOTE_CODE_EXECUTION]: The skill instructions require the execution of remote code via
npx -y @bbengamin/paperclip-mcp-server, which downloads and runs a package at runtime. - [COMMAND_EXECUTION]: The workflow requires the global installation of the
paperclipaipackage from npm, which typically involves elevated privileges and the execution of external binaries. - [CREDENTIALS_UNSAFE]: The skill and its references describe the management and use of
PAPERCLIP_API_KEYand bearer tokens stored in local configuration files (~/.paperclip/auth.json), which are accessed by the CLI and MCP tools.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- AI detected serious security threats
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata