paperless

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses the @nickchristensen/ppls package from the official npm registry. This is a standard way to manage dependencies and is considered a safe practice.
  • [COMMAND_EXECUTION]: The skill uses the ppls CLI tool to interact with Paperless-NGX. The commands are specific, well-defined, and restricted to managing documents and metadata within that system.
  • [CREDENTIALS_UNSAFE]: The skill properly manages sensitive information by using environment variables (PPLS_HOSTNAME, PPLS_TOKEN) as specified in the metadata frontmatter, rather than hardcoding secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 04:41 AM
Security Audit — agent-trust-hub — paperless