paperclip-source-capture
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
paperclipaiCLI tool (e.g.,paperclipai context show --json) for environment discovery and context retrieval. These are standard operations for managing the Paperclip ecosystem. - [EXTERNAL_DOWNLOADS]: The documentation includes instructions to install the
paperclipaiglobal package and run@bbengamin/paperclip-mcp-servervia npx. Both are recognized as vendor-owned resources for the author 'bbengamin'. - [DATA_EXFILTRATION]: Network operations are restricted to communication with the Paperclip API via the CLI, MCP, or direct REST calls to plugin bridge routes (e.g.,
POST /api/plugins/paperclipai.plugin-llm-wiki/api/sources). The instructions emphasize that bearer tokens must never be printed and that the operator must approve structured data writes. - [PROMPT_INJECTION]: The skill uses phrases like 'bypasses the shared Wiki Maintainer,' which describes an operational workflow bypass within the Paperclip organizational model rather than an attempt to circumvent AI safety or ethical constraints.
Audit Metadata