creator-record-strategy

Fail

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to fetch and process content from https://paperclip.right.link/, a domain specifically flagged as malicious and blacklisted by URLite scanners.
  • [EXTERNAL_DOWNLOADS]: The file references/docs/paperclip-operator/cli-contract.md has been flagged as infected by antivirus software (MD:HttpRequest-inf [Susp]).
  • [REMOTE_CODE_EXECUTION]: The skill instructions require the execution of remote code via npx -y @bbengamin/paperclip-mcp-server, which downloads and runs a package at runtime.
  • [COMMAND_EXECUTION]: The workflow requires the global installation of the paperclipai package from npm, which typically involves elevated privileges and the execution of external binaries.
  • [CREDENTIALS_UNSAFE]: The skill and its references describe the management and use of PAPERCLIP_API_KEY and bearer tokens stored in local configuration files (~/.paperclip/auth.json), which are accessed by the CLI and MCP tools.
Recommendations
  • CRITICAL: 1 infected file(s) detected - DO NOT USE
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 16, 2026, 01:15 PM
Security Audit — agent-trust-hub — creator-record-strategy