Paperclip security — tenancy isolation, secrets, approval gates, hard budgets, signed adapter channel. Use when auditing or hardening Paperclip.
Scanned 9/5/2026
Install to Claude Code
npx -y skills add TheBeardedBearSAS/claude-craft --skill security-paperclip --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Security Paperclip?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/thebeardedbearsas-security-paperclip-claude-craft)More formats (shields.io, HTML) on the badges page.
---
name: security-paperclip
description: Paperclip security — tenancy isolation, secrets, approval gates, hard budgets, signed adapter channel. Use when auditing or hardening Paperclip.
---
# Paperclip Security
`companyId` from session/path only (never client body); secrets encrypted at rest + redacted in logs + resolved via `ctx.secrets.resolve(ref)` in plugins; approval gates server-only and append-only; budgets are hard limits enforced at dispatch; Better Auth for operator auth with a rotated `BETTER_AUTH_SECRET`; CSP/HSTS/COOP/CORP shipped on UI; plugin capabilities declared minimally; `pnpm audit --audit-level=high` in CI.
See ../../rules/11-security-paperclip.md for detailed documentation.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...