paperclip
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPERSISTENCEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructions include a command to install the software by fetching a shell script from a remote URL and piping it directly into the bash interpreter:
curl -fsSL https://paperclip.gxl.ai/install.sh | bash. This pattern is considered high risk as it executes unverified remote code with user privileges.\n- [EXTERNAL_DOWNLOADS]: The documentation describes installing the Python SDK from an unversioned remote wheel file athttps://paperclip.gxl.ai/paperclip.whlinstead of using a standard, version-pinned package from a secure registry.\n- [PERSISTENCE]: The installation guide recommends that users modify their shell profile files, such as~/.bashrcor~/.zshrc, to add the tool's binary path to their environment, which is a method for maintaining the tool's availability across different shell sessions.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes extensive full-text biomedical papers and regulatory documents which could contain embedded malicious instructions.\n - Ingestion points: Data is ingested through
paperclip search,grep,cat, andmapcommands as defined in the skill instructions.\n - Boundary markers: The skill includes explicit rules for the agent to treat all server-returned content as data and to ignore any instructions found within that content.\n
- Capability inventory: The skill possesses the
Bash Read Writetool, allowing it to perform local file system operations.\n - Sanitization: The security relies on the agent's adherence to natural language instructions to separate data from commands, rather than technical validation steps.\n- [COMMAND_EXECUTION]: The skill relies on executing a local binary and various shell operations, including the sourcing of
.envfiles for environment variable management.
Recommendations
- HIGH: Downloads and executes remote code from: https://paperclip.gxl.ai/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata