paperclip-clarify

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed as a non-mutating clarification agent. It contains explicit instructions to never create or update records, goals, or projects, effectively limiting its operations to information gathering and summarization.
  • [SAFE]: All external references and tools, such as the paperclipai CLI, the Paperclip MCP tools, and the paperclip-wiki-fetch functionality, are integrated components of the vendor's ecosystem. The use of the domain paperclip.ing is consistent with the vendor's infrastructure.
  • [SAFE]: The skill's ingestion of external wiki data via paperclip-wiki-fetch is a controlled process within the agent's workflow. Because the skill lacks the capability to execute code or mutate the environment based on this input, the risk of indirect prompt injection is negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 08:26 PM
Security Audit — agent-trust-hub — paperclip-clarify