# Defense-in-Depth Score: Paperclip

**Repo:** https://github.com/paperclipai/paperclip · **Commit:** `1c07b5903b1b11139b1e1ce052a3cd4885865d90` (canary/v2026.1004.0-canary.2) · **Reviewed:** 2026-10-05
**What it is:** Open-source app for managing fleets of agents at work (multi-agent orchestration)
**Category:** Agent Frameworks
**Scored configuration:** Paperclip server in its default local_trusted mode (loopback bind, no login) running local Claude Code and Codex adapters with their shipped adapter defaults, standard trust preset, and no budgets or timeouts configured.
**Agent surface (default):** code execution yes · filesystem write yes · network egress yes · external credentials yes · persistent memory yes · untrusted input yes · third party extensions opt-in · sub agents yes · external communication yes

## Score: 2.9 / 10.0 (Minimal)

| # | Criterion | S | C | D | B | Raw | Cap | Score | Confidence |
|---|---|---|---|---|---|---|---|---|---|
| C1 | Identity & least privilege | L1 | L1 | L0 | L0 | 0.15 | — | **0.15** | High |
| C2 | Approval gates | L2 | L0 | L0 | L0 | 0.15 | C2-SELFAPPROVE | **0.15** | High |
| C3 | Tool & action scoping | L2 | L1 | L0 | L0 | 0.23 | — | **0.23** | High |
| C4 | Code-execution isolation | L2 | L2 | L0 | L2 | 0.40 | G1 | **0.40** (alt) | High |
| C5 | Untrusted input blast radius | L2 | L1 | L0 | L1 | 0.28 | G1 | **0.28** (alt) | High |
| C6 | Memory, context & configuration integrity | L1 | L1 | L1 | L0 | 0.20 | — | **0.20** | High |
| C7 | Third-party extensions | L1 | L1 | L1 | L0 | 0.20 | — | **0.20** | High |
| C8 | Secrets & sensitive-data protection | L2 | L2 | L1 | L0 | 0.35 | — | **0.35** | High |
| C9 | Audit & traceability | L3 | L2 | L2 | L2 | 0.57 | — | **0.57** | High |
| C10 | Limits & kill switch | L2 | L2 | L0 | L1 | 0.35 | G1 | **0.35** | High |


Paperclip ships serious governance machinery (a default-deny tool gateway with human review, per-request authorization with a responsible user, encrypted secrets, a structured activity log, budgets and opt-in Bubblewrap confinement), but almost none of it constrains the agents in the default setup. Out of the box it launches Claude Code and Codex on your machine with their permission prompts and sandboxes turned off, as your OS user, with no budget or timeout, and its default local mode treats every loopback request as the administrator. The dominant risk is a single hijacked or confused agent acting with your full local authority; turn on authenticated mode, per-agent confinement, budgets and timeouts before letting agents run unattended.

## Critical gaps
- Approval for the most powerful path is off by default and, in local_trusted mode, human-only review decisions are reachable from the agent's own process. (ASI09, ASI02, T10; C2) — [packages/adapters/claude-local/src/server/execute.ts:437](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/claude-local/src/server/execute.ts#L437); [server/src/middleware/auth.ts:229-239](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/middleware/auth.ts#L229-L239)
- A hijacked agent holds the OS user's full ambient authority plus implicit administrator access to the control plane. (ASI03, T3; C1) — [packages/adapter-utils/src/server-utils.ts:4686-4689](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/server-utils.ts#L4686-L4689); [server/src/middleware/auth.ts:237](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/middleware/auth.ts#L237)
- Agent code runs unsandboxed on the host with the server's inherited environment in the default configuration. (ASI05, T11; C4) — [packages/adapters/claude-local/src/server/execute.ts:570-571](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/claude-local/src/server/execute.ts#L570-L571); [packages/adapter-utils/src/server-utils.ts:4686-4689](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/server-utils.ts#L4686-L4689)
- A prompt-injected agent can both exfiltrate host secrets and take irreversible actions with no human involved. (ASI01, LLM01, T6; C5) — [packages/adapters/claude-local/src/server/execute.ts:437](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/claude-local/src/server/execute.ts#L437); [packages/shared/src/trust-policy.ts:5](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/shared/src/trust-policy.ts#L5)
- External adapter packages from npm are imported into the server process, which holds every secret and connection. (ASI04, T17; C7) — [server/src/routes/adapters.ts:336-344](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/routes/adapters.ts#L336-L344); [server/src/adapters/plugin-loader.ts:195](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/adapters/plugin-loader.ts#L195)

## Criterion details

### C1 Identity & least privilege — 0.15 (high)

Paperclip gives each agent its own API identity, and its server-side authorization layer checks every agent API call against the agent's company and grants, intersected with a responsible human user and enforced (not just logged) by default. But that layer only governs the Paperclip API. The coding agents themselves (Claude Code, Codex and others) run as ordinary processes of the same OS user as the server, inheriting its environment apart from Paperclip's own variables, so they hold whatever cloud, Git and SSH credentials that user has. In the default local mode the API also treats every loopback request without a credential as the instance administrator, so agent-level scoping is not a boundary there.

- **S L1:** Agents get a dedicated Paperclip API identity, but run on the host with the launching user's ambient OS authority; only PAPERCLIP_-prefixed variables are removed from the inherited environment. — [packages/adapter-utils/src/server-utils.ts:3491-3504](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/server-utils.ts#L3491-L3504); [packages/adapter-utils/src/server-utils.ts:4686-4689](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/server-utils.ts#L4686-L4689) (verified)
  - *To reach the next level:* No narrowing of the OS-level credentials the agent processes inherit (scrubbed environment, scoped tokens per tool).
- **C L1:** The Paperclip API path is checked per request (company scope, grants, responsible-user intersection), but agent shell and file actions use the server user's ambient credentials. — [server/src/routes/authz.ts:76-79](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/routes/authz.ts#L76-L79); [server/src/services/authorization.ts:504-508](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/authorization.ts#L504-L508); [packages/adapter-utils/src/server-utils.ts:4686-4689](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/server-utils.ts#L4686-L4689) (verified)
  - *To reach the next level:* Agent subprocesses and their tools do not pass through the authorization layer or a scoped identity.
- **D L0:** The default deployment mode is local_trusted, in which any loopback request without a bearer credential is the instance administrator. — [server/src/config-file.ts:52-57](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/config-file.ts#L52-L57); [server/src/middleware/auth.ts:229-239](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/middleware/auth.ts#L229-L239); [server/src/middleware/auth.ts:237](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/middleware/auth.ts#L237) (verified)
  - *To reach the next level:* Default should require authenticated principals so agent processes on the same host cannot act with administrator authority.
- **B L0:** A hijacked agent holds the OS user's full authority on the host plus implicit administrator access to every company on the instance. — [packages/adapter-utils/src/server-utils.ts:4686-4689](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/server-utils.ts#L4686-L4689); [server/src/middleware/auth.ts:237](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/middleware/auth.ts#L237) (verified)
  - *To reach the next level:* Agent processes would need to run without the operator's ambient credentials and without administrator reach to the control plane.
- **Cap:** none

### C2 Approval gates — 0.15 (high)

Paperclip has a real approval system for actions that go through its tool gateway (connected apps and MCP tools): calls are denied unless a profile or policy allows them, policies can require a per-call human review, argument filters and rate limits exist, and a changed tool definition forces re-review. The most powerful path, though, is the coding agent's own shell and file tools, and Paperclip launches Claude Code with --dangerously-skip-permissions and Codex with its approvals-and-sandbox bypass by default, so those actions run with no human gate. Hiring new agents does not need board approval by default. In the default local mode the review endpoints accept any loopback caller as the human board, which the agent processes on the same host can reach.

- **S L2:** Gateway tool calls can require per-call approval that only a human actor may resolve, with argument-filtered trust rules and re-review when a tool definition changes. — [server/src/services/tool-access-policy.ts:1452-1458](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/tool-access-policy.ts#L1452-L1458); [server/src/services/tool-action-review.ts:34-35](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/tool-action-review.ts#L34-L35); [server/src/services/tool-access-policy.ts:1438-1447](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/tool-access-policy.ts#L1438-L1447); [server/src/services/tool-access-policy.ts:1433](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/tool-access-policy.ts#L1433) (verified)
  - *To reach the next level:* Not verified that the reviewer sees the exact arguments and that the approved call is bound to the executed call; no argument-level escalate rules for the shell path.
- **C L0:** The coding CLIs' shell and file tools, the most powerful action path, are launched with their own approval prompts disabled and never cross Paperclip's gate. — [packages/adapters/claude-local/src/server/execute.ts:437](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/claude-local/src/server/execute.ts#L437); [packages/adapters/claude-local/src/server/permissions.ts:11-13](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/claude-local/src/server/permissions.ts#L11-L13); [packages/adapters/codex-local/src/index.ts:14](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/codex-local/src/index.ts#L14); [packages/adapters/codex-local/src/server/codex-args.ts:80](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/codex-local/src/server/codex-args.ts#L80) (verified)
  - *To reach the next level:* Shell and code execution would need to traverse an approval gate.
- **D L0:** Approval for agent shell actions is effectively opt-in: the permission-skip flags default to true, and agent hiring approval defaults to false. — [packages/adapters/claude-local/src/server/execute.ts:437](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/claude-local/src/server/execute.ts#L437); [packages/adapters/codex-local/src/index.ts:14](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/codex-local/src/index.ts#L14); [packages/db/src/schema/companies.ts:18-20](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/db/src/schema/companies.ts#L18-L20) (verified)
  - *To reach the next level:* Approvals for consequential agent actions should be on by default and disabled only by an explicit operator flag.
- **B L0:** Unreviewed actions include arbitrary shell commands on the host, git pushes and external API calls, with no undo beyond what the workspace's git history offers. — [packages/adapters/claude-local/src/server/permissions.ts:11-13](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/claude-local/src/server/permissions.ts#L11-L13); [packages/adapter-utils/src/server-utils.ts:4686-4689](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/server-utils.ts#L4686-L4689) (verified)
  - *To reach the next level:* No checkpoints, previews or spend/recipient bounds on agent shell actions.
- **Cap:** C2-SELFAPPROVE — In the default local_trusted mode every loopback request without a credential is the instance administrator and board-mutation origin checks are skipped for it, so human-only review decisions are reachable from the agent's own unsandboxed process.

### C3 Tool & action scoping — 0.23 (high)

Tools that go through Paperclip's tool gateway are default-deny and can be narrowed by profiles, argument filters and rate limits. But the tools agents actually use most are the coding CLI's built-ins: an unrestricted shell, file read and write anywhere the OS user can reach, and network access, all enabled because Paperclip turns the CLI's own permission prompts off. There is no default narrowing of what an agent can run or where it can write.

- **S L2:** The gateway evaluates schema-validated calls against profiles, block policies and argument filters with a default deny. — [server/src/services/tool-access-policy.ts:1482](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/tool-access-policy.ts#L1482); [server/src/services/tool-access-policy.ts:1433](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/tool-access-policy.ts#L1433); [server/src/services/tool-access-policy.ts:1413](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/tool-access-policy.ts#L1413) (verified)
  - *To reach the next level:* No resolved-path, host or command allowlists on the agent's own shell and file tools.
- **C L1:** Only connector and gateway tools are validated; the coding CLI's shell, file and fetch tools take raw arguments. — [packages/adapters/claude-local/src/server/permissions.ts:11-13](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/claude-local/src/server/permissions.ts#L11-L13); [packages/adapters/codex-local/src/server/codex-args.ts:80](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/codex-local/src/server/codex-args.ts#L80) (verified)
  - *To reach the next level:* Agent built-in tools would need to pass through the same validation layer.
- **D L0:** By default agents get write, exec and network tools with the CLI's permission system bypassed. — [packages/adapters/claude-local/src/server/execute.ts:437](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/claude-local/src/server/execute.ts#L437); [packages/adapters/codex-local/src/index.ts:14](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/codex-local/src/index.ts#L14) (verified)
  - *To reach the next level:* Default tool set should exclude unrestricted exec and write until enabled per agent.
- **B L0:** A misused shell tool reaches the whole host as the server's OS user. — [packages/adapter-utils/src/server-utils.ts:4686-4689](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/server-utils.ts#L4686-L4689); [packages/adapter-utils/src/local-process-sandbox.ts:157-161](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/local-process-sandbox.ts#L157-L161) (verified)
  - *To reach the next level:* Tools would need to be scoped to the workspace with bounded quantities.
- **Cap:** none

### C4 Code-execution isolation — 0.40 (high)

By default the coding agents run directly on the host as the same OS user as the Paperclip server, with no sandbox, and the CLIs' own sandboxes are switched off (Codex is launched with its sandbox bypass flag). Paperclip ships an opt-in Bubblewrap confinement that can limit the filesystem to the workspace and deny or allowlist network access, and it refuses to run if Bubblewrap is missing rather than falling back to the host; remote sandbox providers are also available as plugins. None of this is on unless an operator configures it per agent.

- **default configuration** (default; raw 0.00 → 0.00)
  - **S L0:** Local adapter runs spawn the CLI as a same-user host process; confinement is only built when filesystemScope or networkScope is configured. — [packages/adapters/claude-local/src/server/execute.ts:570-571](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/claude-local/src/server/execute.ts#L570-L571); [packages/adapter-utils/src/local-process-sandbox.ts:157-161](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/local-process-sandbox.ts#L157-L161); [packages/adapters/codex-local/src/server/codex-args.ts:80](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/codex-local/src/server/codex-args.ts#L80) (verified)
    - *To reach the next level:* No isolation boundary in the default local execution path.
  - **C L0:** The main execution path (the agent CLI and everything it spawns) runs on the host. — [packages/adapters/claude-local/src/server/execute.ts:570-571](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/claude-local/src/server/execute.ts#L570-L571) (verified)
    - *To reach the next level:* The main agent execution path is not sandboxed by default.
  - **D L0:** Confinement settings default to null, so sandboxing is off by default. — [packages/adapter-utils/src/local-process-sandbox.ts:157-161](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/local-process-sandbox.ts#L157-L161) (verified)
    - *To reach the next level:* Sandboxing should be on by default for local agent runs.
  - **B L0:** Agent processes see the host filesystem, the user's home directory and credentials, the server's inherited environment, and the network. — [packages/adapter-utils/src/server-utils.ts:4686-4689](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/server-utils.ts#L4686-L4689); [packages/adapter-utils/src/server-utils.ts:3491-3504](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/server-utils.ts#L3491-L3504) (verified)
    - *To reach the next level:* Agent code would need a workspace-only mount, no inherited secrets and restricted egress.
- **opt-in Bubblewrap local confinement (filesystemScope/networkScope)** (alt; raw 0.40, cap G1 → 0.40) ← counted
  - **S L2:** Bubblewrap with new PID/IPC/UTS namespaces, a tmpfs root with only system paths read-only and the workspace read-write, and an optional separate network namespace with deny or proxy-allowlisted egress. — [packages/adapter-utils/src/local-process-sandbox.ts:381-388](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/local-process-sandbox.ts#L381-L388); [packages/adapter-utils/src/local-process-sandbox.ts:475-477](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/local-process-sandbox.ts#L475-L477) (verified)
    - *To reach the next level:* No seccomp profile, and network denial is a separate setting from filesystem confinement rather than part of one hardened profile.
  - **C L2:** Applies to local runs of the adapters that wire it (Claude and Codex local); remote targets use their own isolation, and other host-side paths such as workspace runtime services are not covered. — [packages/adapters/claude-local/src/server/execute.ts:570-571](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/claude-local/src/server/execute.ts#L570-L571) (verified)
    - *To reach the next level:* Not every execution path (all adapters, workspace services, spawned helpers) is confined.
  - **D L0:** Off unless configured per agent; when configured it fails closed if Bubblewrap is missing. — [packages/adapter-utils/src/local-process-sandbox.ts:157-161](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/local-process-sandbox.ts#L157-L161); [packages/adapter-utils/src/server-utils.ts:3643-3651](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/server-utils.ts#L3643-L3651) (verified)
    - *To reach the next level:* Confinement should be the shipped default.
  - **B L2:** Inside the confinement the workspace and the agent's CLI config directory are writable, the Paperclip API stays reachable, and the inherited environment still carries non-Paperclip variables. — [packages/adapters/claude-local/src/server/execute.ts:585-588](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/claude-local/src/server/execute.ts#L585-L588); [packages/adapter-utils/src/server-utils.ts:4686-4689](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/server-utils.ts#L4686-L4689) (verified)
    - *To reach the next level:* Would need no inherited secrets and egress limited to an allowlist that excludes the control plane's administrative API.
- **Cap:** G1 — Opt-in mechanism: off in the scored default configuration.

### C5 Untrusted input blast radius — 0.28 (high)

Agents read a lot of content their operator did not write: task descriptions and comments written by other agents, repository files, web pages, connector results and inbound routine triggers. In the default configuration nothing structural limits what a hijacked agent can do with that: the prompt tells agents to treat some inputs as untrusted, but the same session holds the host user's credentials, an unrestricted shell with network access and no approval prompts. An opt-in low-trust review preset forces isolated workspaces and quarantines low-trust output from higher-trust agents, but it is off by default.

- **default configuration** (default; raw 0.00, cap C5-WORSTCASE → 0.00)
  - **S L0:** Default handling of untrusted content is prompt guidance only. — [server/src/services/heartbeat.ts:8800](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/heartbeat.ts#L8800); [packages/shared/src/trust-policy.ts:5](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/shared/src/trust-policy.ts#L5) (verified)
    - *To reach the next level:* No code-enforced restriction of egress or state change once untrusted content is read.
  - **C L0:** Content from issues, comments, other agents and tool results enters agent context with no provenance-based limit in the standard preset. — [packages/shared/src/trust-policy.ts:5](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/shared/src/trust-policy.ts#L5) (verified)
    - *To reach the next level:* Untrusted sources are not distinguished in code for standard runs.
  - **D L0:** The standard trust preset is the default. — [packages/shared/src/trust-policy.ts:5](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/shared/src/trust-policy.ts#L5) (verified)
    - *To reach the next level:* A containment preset would need to be on by default.
  - **B L0:** A hijacked agent can read host secrets and send them anywhere, and push, delete or deploy, with no human in the loop. — [packages/adapters/claude-local/src/server/execute.ts:437](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/claude-local/src/server/execute.ts#L437); [packages/adapter-utils/src/server-utils.ts:4686-4689](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/server-utils.ts#L4686-L4689) (verified)
    - *To reach the next level:* Exfiltration and irreversible actions would need to require approval.
- **opt-in low_trust_review trust preset** (alt; raw 0.28, cap G1 → 0.28) ← counted
  - **S L2:** Low-trust runs must use an isolated execution workspace within a declared issue boundary, and their output is quarantined from higher-trust agents' context. — [server/src/services/low-trust-runtime-containment.ts:63-68](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/low-trust-runtime-containment.ts#L63-L68); [server/src/services/source-trust.ts:12-13](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/source-trust.ts#L12-L13) (verified)
    - *To reach the next level:* Low-trust runs themselves still have egress and state change without per-action approval.
  - **C L1:** Applies only to runs, agents, projects or issues explicitly marked low-trust. — [packages/shared/src/trust-policy.ts:5](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/shared/src/trust-policy.ts#L5); [server/src/services/low-trust-runtime-containment.ts:63-68](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/low-trust-runtime-containment.ts#L63-L68) (verified)
    - *To reach the next level:* Untrusted sources in standard runs are not covered.
  - **D L0:** The preset is opt-in; standard is the default. — [packages/shared/src/trust-policy.ts:5](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/shared/src/trust-policy.ts#L5) (verified)
    - *To reach the next level:* Would need to be on by default.
  - **B L1:** Within a low-trust run the agent still has a shell and network egress, but its output cannot flow raw into higher-trust agents. — [server/src/services/source-trust.ts:12-13](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/source-trust.ts#L12-L13); [packages/adapters/claude-local/src/server/execute.ts:437](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/claude-local/src/server/execute.ts#L437) (verified)
    - *To reach the next level:* Low-trust sessions would need no egress or approval-gated egress.
- **Cap:** G1 — Opt-in mechanism: off in the scored default configuration.

### C6 Memory, context & configuration integrity — 0.20 (high)

Paperclip is built around persistent shared context: issues, comments, documents, company skills and agent instruction files persist and are fed into later runs of every agent in the company. Edits to an agent's instructions through the API are versioned and, for agents with only suggest rights, require a human-accepted change with a displayed diff; an agent may edit its own instructions directly. Agents can create company skills by default, and issue and comment content is not validated before it reaches other agents. Because agent processes run unsandboxed as the server's user, they can also write instruction files and the instance's own configuration on disk.

- **S L1:** Instruction edits are revisioned and some require human consent, but self-edits, skill creation and issue/comment content persist without validation. — [server/src/services/authorization.ts:2284](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/authorization.ts#L2284); [server/src/services/change-consent-gate.ts:152-166](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/change-consent-gate.ts#L152-L166); [server/src/services/agent-permissions.ts:41-48](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/agent-permissions.ts#L41-L48) (verified)
  - *To reach the next level:* Persistent writes from agents (skills, comments, self instruction edits) are not gated or expiring.
- **C L1:** Only the instruction-edit API path carries a consent gate; skills, issues, documents and on-disk files do not. — [server/src/services/change-consent-gate.ts:152-166](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/change-consent-gate.ts#L152-L166); [server/src/services/agent-permissions.ts:41-48](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/agent-permissions.ts#L41-L48) (verified)
  - *To reach the next level:* Gate would need to cover all persistent stores and auto-loaded files.
- **D L1:** Agent API keys are bound to one company and queries are company-scoped, but in the default local mode a process that omits its credential is the instance administrator across companies. — [server/src/routes/authz.ts:76-79](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/routes/authz.ts#L76-L79); [server/src/middleware/auth.ts:229-239](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/middleware/auth.ts#L229-L239) (verified)
  - *To reach the next level:* Company isolation would need to hold for every local caller, not only for requests that present an agent key.
- **B L0:** Poisoned skills, instructions or task content persist across sessions and agents and drive later tool use. — [server/src/services/agent-permissions.ts:41-48](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/agent-permissions.ts#L41-L48) (verified)
  - *To reach the next level:* Persistent content would need to be limited to text output or gated actions.
- **Cap:** none

### C7 Third-party extensions — 0.20 (high)

Operators can add third-party code in several ways: Paperclip plugins and external adapter packages installed from npm, skills imported from GitHub, and MCP servers through connections. Plugins run in a separate worker process with a minimal environment and are installed with npm scripts disabled, and skills are pinned to a commit. Adapter packages are installed without that flag and imported directly into the server process, and npm installs take the latest version unless one is given. Installs require the instance administrator, which in the default local mode is any loopback caller.

- **S L1:** npm-based plugin and adapter installs are unpinned unless a version is specified and have no integrity or signature check; skills from GitHub are pinned to a commit. — [server/src/services/plugin-loader.ts:1242-1256](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/plugin-loader.ts#L1242-L1256); [server/src/routes/adapters.ts:336-344](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/routes/adapters.ts#L336-L344); [server/src/services/skill-sources.ts:98](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/skill-sources.ts#L98) (verified)
  - *To reach the next level:* Pin and verify every extension (hash or signature), not only skills.
- **C L1:** Only skill imports are pinned; plugins, adapter packages and MCP servers are not verified. — [server/src/services/skill-sources.ts:98](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/skill-sources.ts#L98); [server/src/routes/adapters.ts:336-344](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/routes/adapters.ts#L336-L344) (verified)
  - *To reach the next level:* Verification would need to cover all extension types.
- **D L1:** Extensions require an explicit instance-admin install, but in local_trusted mode any local process is the instance admin. — [server/src/routes/adapters.ts:303-304](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/routes/adapters.ts#L303-L304); [server/src/middleware/auth.ts:237](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/middleware/auth.ts#L237) (verified)
  - *To reach the next level:* Install should require an authenticated operator and show what will run.
- **B L0:** External adapter packages are imported into the server process, which holds the database, secrets master key and every connection. — [server/src/adapters/plugin-loader.ts:195](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/adapters/plugin-loader.ts#L195); [server/src/services/plugin-worker-manager.ts:2871-2881](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/plugin-worker-manager.ts#L2871-L2881) (verified)
  - *To reach the next level:* Every extension type would need to run out of process with a scrubbed environment, as plugins already do.
- **Cap:** none

### C8 Secrets & sensitive-data protection — 0.35 (high)

Stored secrets are encrypted with AES-256-GCM under a master key file written with owner-only permissions, and Paperclip redacts known secret values and secret-looking fields from run logs, activity records and HTTP logs. Anonymous product telemetry is on by default but sends event names and IDs, not prompts or tool output, and can be turned off. The weak point is exposure to the agents themselves: bound secrets are handed to agent processes as environment variables, agent processes inherit the server's other environment variables, and because they run as the same OS user they can read the master key file.

- **S L2:** Encryption at rest with a local key file and value-based redaction of run logs and event payloads. — [server/src/secrets/local-encrypted-provider.ts:195-197](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/secrets/local-encrypted-provider.ts#L195-L197); [server/src/secrets/local-encrypted-provider.ts:74](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/secrets/local-encrypted-provider.ts#L74); [server/src/services/run-secret-redaction.ts:37-40](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/run-secret-redaction.ts#L37-L40); [server/src/redaction.ts:4](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/redaction.ts#L4) (verified)
  - *To reach the next level:* No redaction before content reaches the model and no opaque handles for secrets used by agents.
- **C L2:** Run logs, activity details and HTTP logs are redacted; model-bound messages and subprocess environments are not. — [server/src/services/run-secret-redaction.ts:37-40](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/run-secret-redaction.ts#L37-L40); [packages/adapter-utils/src/server-utils.ts:4686-4689](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/server-utils.ts#L4686-L4689) (verified)
  - *To reach the next level:* Subprocess environments and model-bound context are not protected.
- **D L1:** Telemetry is on by default with content-free events, disabled by an env var or config. — [packages/shared/src/telemetry/config.ts:66-86](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/shared/src/telemetry/config.ts#L66-L86); [packages/shared/src/telemetry/events.ts:76-79](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/shared/src/telemetry/events.ts#L76-L79) (verified)
  - *To reach the next level:* Telemetry would need to be opt-in.
- **B L0:** Long-lived keys (provider API keys, connection tokens, the secrets master key readable by the same OS user) are reachable from every agent process. — [packages/adapter-utils/src/server-utils.ts:4686-4689](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/server-utils.ts#L4686-L4689); [server/src/secrets/local-encrypted-provider.ts:74](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/secrets/local-encrypted-provider.ts#L74) (verified)
  - *To reach the next level:* Agents would need scoped, short-lived credentials and no access to the master key.
- **Cap:** none

### C9 Audit & traceability — 0.57 (high)

Paperclip keeps a structured activity log in its database that attributes each action to an agent, user, system or plugin actor, with run ID, API key and responsible user, and every agent run's output stream is appended to a run-log file as it arrives. Gateway tool decisions, including denials and human reviews, are audited. The record lives outside the agent's workspace but in the same database and home directory the unsandboxed agent processes can reach, and it is not hash-chained or shipped off-host by default.

- **S L3:** Structured activity records with actor type and ID, agent, run, API key and responsible user, plus gateway decision audits. — [server/src/services/activity-log.ts:54-67](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/activity-log.ts#L54-L67); [server/src/services/tool-access-policy.ts:1485](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/tool-access-policy.ts#L1485) (verified)
  - *To reach the next level:* No tamper-evident storage or standard export by default.
- **C L2:** Paperclip API actions and gateway calls are recorded; shell and file actions inside the coding CLI are captured only as the CLI's own output stream reports them. — [server/src/services/run-log-store.ts:503](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/run-log-store.ts#L503); [server/src/services/tool-access-policy.ts:1485](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/tool-access-policy.ts#L1485) (verified)
  - *To reach the next level:* No independent record of every tool call made inside the agent CLI.
- **D L2:** On by default and stored under the instance directory and database, outside the agent workspace. — [server/src/services/run-log-store.ts:503](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/run-log-store.ts#L503) (verified)
  - *To reach the next level:* Agent processes run as the same OS user and can alter the log files and database.
- **B L2:** Run output is appended per chunk and activity rows are written with the action. — [server/src/services/run-log-store.ts:352](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/run-log-store.ts#L352); [server/src/services/activity-log.ts:54-67](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/activity-log.ts#L54-L67) (verified)
  - *To reach the next level:* Not guaranteed that high-risk actions fail when their record cannot be written.
- **Cap:** none

### C10 Limits & kill switch — 0.35 (high)

Paperclip has the pieces of a good limit system: company, project and agent budgets that pause the scope and cancel running work when exceeded, per-run timeouts, a turn cap for Claude, a per-agent concurrency limit, and a stop that kills the agent's whole process group. But the shipped defaults are unlimited: budgets default to zero (meaning no limit), local runs have no timeout, and the turn cap defaults to unlimited. Spend is tracked from what adapters report, and scheduled routines keep firing until paused.

- **S L2:** Budget hard stops, configurable run timeouts, a turn cap and process-group kill exist in code. — [server/src/services/budgets.ts:252-253](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/budgets.ts#L252-L253); [server/src/services/budgets.ts:71-72](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/budgets.ts#L71-L72); [packages/adapter-utils/src/server-utils.ts:133](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/server-utils.ts#L133); [packages/adapters/claude-local/src/server/execute.ts:436](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/claude-local/src/server/execute.ts#L436) (verified)
  - *To reach the next level:* No default rate limits on side-effecting actions or repeated-action breaker, and the cost cap relies on adapter-reported spend.
- **C L2:** Budgets apply at company, project and agent scope, so delegated work counts against the company budget when one is set; timeouts apply per run. — [server/src/services/budgets.ts:71-72](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/budgets.ts#L71-L72); [packages/shared/src/constants.ts:77](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/shared/src/constants.ts#L77) (verified)
  - *To reach the next level:* No cap on delegation depth or on the number of agents an agent can hire.
- **D L0:** Budgets default to 0 (unlimited), local timeouts default to none, and the turn cap defaults to 0. — [packages/db/src/schema/companies.ts:15](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/db/src/schema/companies.ts#L15); [packages/db/src/schema/agents.ts:33](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/db/src/schema/agents.ts#L33); [packages/adapter-utils/src/execution-target.ts:591-599](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/execution-target.ts#L591-L599); [packages/adapters/claude-local/src/server/execute.ts:436](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapters/claude-local/src/server/execute.ts#L436) (verified)
  - *To reach the next level:* Ship finite default budgets and run timeouts.
- **B L1:** With defaults a runaway agent can run and spend without a ceiling, across up to 20 concurrent runs per agent, though stop kills the process group. — [packages/shared/src/constants.ts:77](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/shared/src/constants.ts#L77); [server/src/services/heartbeat.ts:677-679](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/server/src/services/heartbeat.ts#L677-L679); [packages/adapter-utils/src/server-utils.ts:133](https://github.com/paperclipai/paperclip/blob/1c07b5903b1b11139b1e1ce052a3cd4885865d90/packages/adapter-utils/src/server-utils.ts#L133) (verified)
  - *To reach the next level:* Tight default time and cost ceilings.
- **Cap:** G1 — Budgets, run timeouts and the turn cap all exist but are unlimited until an operator configures them.

## Rule-of-Two check
[A] untrusted input: Issues, comments and documents written by other agents, repository files and web content read by the coding CLI (server/src/services/heartbeat.ts:8800) · [B] sensitive data/systems: Host user's credentials and the server's inherited environment in every agent process (packages/adapter-utils/src/server-utils.ts:4687) · [C] state change / egress: Unrestricted shell with network access, CLI permissions skipped by default (packages/adapters/claude-local/src/server/execute.ts:437) · Same default session? Yes

## Highest-impact improvements
1. Default dangerouslySkipPermissions and the Codex bypass to false, or require confinement when they are true. — C2 D L0→L2, +0.100 before caps (Playbook 5)
2. Enable Bubblewrap workspace filesystem scope and an allowlisted network scope by default for local adapters on Linux. — C4 D L0→L2, +0.100 before caps (Playbook 3)
3. Ship finite default company budgets and a default per-run timeout for local adapters. — C10 D L0→L2, +0.100 before caps (Playbook 3 step 3)
4. Pass agent subprocesses an allowlisted environment instead of the server environment minus PAPERCLIP_ variables. — C8 C L2→L3, +0.075 before caps (Playbook 4)
5. Require a local credential for the API even in local_trusted mode so agent processes cannot act as the board. — C1 D L0→L2, +0.100 before caps (Playbook 4)

## Re-audit log
- No changes.

## Limitations
- Static source review of the pinned commit only; nothing was executed, installed, or probed.
- The repository is very large (about 8,300 files); review focused on the server's auth, authorization, tool gateway, budgets, secrets, activity log, plugin and adapter loaders, and the Claude and Codex local adapters. Other adapters (Gemini, OpenCode, Pi, Kimi, Grok, Hermes, OpenClaw, Cursor) and the remote sandbox provider plugins were sampled, not audited.
- The authenticated deployment mode and Paperclip Cloud managed configuration were not scored; they change the C1, C2, C6 and C7 defaults.
- Behaviour of the third-party coding CLIs (Claude Code, Codex) under their bypass flags is inferred from the flags' documented meaning.
- The server loads a .env file from its own working directory at startup; this is operator-controlled and was not treated as workspace configuration.
