paperclip

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose is coherent, but its install and execution footprint is not: it directs users to a CLI name, repo, and curl|bash installer that do not match the verified official Paperclip publisher evidence. Because the skill then supplies a Paperclip API key to that third-party CLI, the main risk is credential forwarding through an unverified supply chain rather than overt malicious behavior.

Confidence: 91%Severity: 86%
Audit Metadata
Analyzed At
Apr 4, 2026, 07:47 AM
Package URL
pkg:socket/skills-sh/ckorhonen%2Fclaude-skills%2Fpaperclip%2F@86d331e14ef2c625543f085e40885c2effbfaaa1