paperclip-source-capture

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the paperclipai CLI tool (e.g., paperclipai context show --json) for environment discovery and context retrieval. These are standard operations for managing the Paperclip ecosystem.
  • [EXTERNAL_DOWNLOADS]: The documentation includes instructions to install the paperclipai global package and run @bbengamin/paperclip-mcp-server via npx. Both are recognized as vendor-owned resources for the author 'bbengamin'.
  • [DATA_EXFILTRATION]: Network operations are restricted to communication with the Paperclip API via the CLI, MCP, or direct REST calls to plugin bridge routes (e.g., POST /api/plugins/paperclipai.plugin-llm-wiki/api/sources). The instructions emphasize that bearer tokens must never be printed and that the operator must approve structured data writes.
  • [PROMPT_INJECTION]: The skill uses phrases like 'bypasses the shared Wiki Maintainer,' which describes an operational workflow bypass within the Paperclip organizational model rather than an attempt to circumvent AI safety or ethical constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 08:26 PM
Security Audit — agent-trust-hub — paperclip-source-capture