paperclip
Warn
Audited by Socket on Jul 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose mostly matches its capabilities, but its trust model is weak. The main issue is a remote-installed, insufficiently verifiable Paperclip executable that then receives API credentials and mediates access to remote corpora; optional upload/share/fetch features add additional data-egress risk even though the instructions try to scope them to explicit user intent.
Confidence: 89%Severity: 84%
Audit Metadata