paperclip-plan-work

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Executes shell commands through the paperclipai CLI and curl for the purpose of managing Paperclip goals, projects, and issues.
  • [EXTERNAL_DOWNLOADS]: References the paperclipai global package and executes the @bbengamin/paperclip-mcp-server package via npx for fallback API operations.
  • [DATA_EXFILTRATION]: Communicates with an external Paperclip API endpoint to synchronize and update organizational data.
  • [PROMPT_INJECTION]: Processes data from parent issues, plan documents, and wiki pages which could contain untrusted instructions.
  • Ingestion points: Reads issue bodies, comments, and external wiki source material via paperclip-wiki-fetch.
  • Boundary markers: Proposes breakdowns in a structured format and requires explicit operator approval before performing any mutations.
  • Capability inventory: Has the ability to create and modify issues, projects, and goals via the Paperclip control plane.
  • Sanitization: Relies on manual human review of proposed breakdown structures as the primary safeguard.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 08:26 PM
Security Audit — agent-trust-hub — paperclip-plan-work