.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

…/paperclip-converting-plans-to-tasks/security
home/skills/paperclip-converting-plans-to-tasks/security
getpaperclipai avatar

paperclip-converting-plans-to-tasks — security audits

Flagged by auditors

Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.

  • Gen Agent Trust Hub

    fail

    The skill's installation instructions contain a highly dangerous command that downloads and executes an obfuscated script from a suspicious domain (getpaperclipp.com). This domain appears to be a typosquat of the vendor's actual name, and the pattern of fetching, decoding Base64, and immediately executing code via Node.js is a classic mechanism for delivering malware and gaining remote control of a system.

    Risk: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTIONJul 21, 2026Full report
  • Socket

    warn

    1 alert: gptSecurity

    Jul 21, 2026Full report
  • Snyk

    fail

    Risk: CRITICAL · 3 issues

    Risk: CRITICALJul 21, 2026Full report