Security audit
Paperless Cloud Intake Hardening
Security checks for vulnerabilities and agentic risk
Overview
This is a guidance-only skill for making Paperless cloud-folder intake safer, and its file access and automation advice is disclosed, scoped, and purpose-aligned.
Before installing, confirm you want agent guidance for Paperless document intake workflows that may read, stage, move, and verify files from cloud-synced folders. Keep any helper automation narrowly scoped to the intake folder, avoid broad macOS privacy permissions for generic runtimes, and require explicit approval before cleanup or deletion of leftovers.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
