Back to skill

Security audit

Paperless Cloud Intake Hardening

Security checks for vulnerabilities and agentic risk

Overview

This is a guidance-only skill for making Paperless cloud-folder intake safer, and its file access and automation advice is disclosed, scoped, and purpose-aligned.

Before installing, confirm you want agent guidance for Paperless document intake workflows that may read, stage, move, and verify files from cloud-synced folders. Keep any helper automation narrowly scoped to the intake folder, avoid broad macOS privacy permissions for generic runtimes, and require explicit approval before cleanup or deletion of leftovers.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.