ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      pors

      Safety Report

      Paperzilla

      @pors

      Use the Paperzilla CLI (pz) to search, filter, and browse high-signal academic papers. Trigger when the user wants to check research feeds, list projects, in...

      266Downloads
      0Installs
      2Stars
      1Versions
      Workflow Automation3,323Search & Retrieval2,116CLI & Shell Tools1,805

      Security Analysis

      medium confidence
      Clean0.12 risk

      The skill is internally consistent with its stated purpose (driving the Paperzilla CLI), but it omits a couple of small details and its install instructions ask the user to download and install a binary — so verify sources before installing.

      Feb 20, 20261 files3 concerns
      Purpose & Capabilityok

      The name/description match the SKILL.md: all instructions center on using the 'pz' CLI and a Paperzilla account. No unrelated credentials or capabilities are requested. Minor mismatch: SKILL.md documents an optional PZ_API_URL environment variable but the skill metadata does not list it as a required/optional env var.

      Instruction Scopenote

      Instructions tell the agent/user to install the pz CLI, run 'pz login', run feed/project commands, and optionally set PZ_API_URL. They also note that --atom prints a URL with an embedded feed token (sensitive). The instructions do not request reading unrelated files or credentials, but printing or piping the Atom URL (with token) to third-party services or LLMs could leak access tokens.

      Install Mechanismnote

      No install spec is embedded in the skill (instruction-only). SKILL.md recommends brew/scoop or downloading a GitHub release archive. GitHub releases and official package managers are typical, but the Linux curl|tar -> sudo mv flow installs an arbitrary binary and should be verified (checksums/signature or official release page) before running as root.

      Credentialsnote

      The skill declares no required env vars or credentials (metadata), which is reasonable because 'pz login' handles authentication interactively. It does reference an optional PZ_API_URL and warns about feed tokens. There are no requests for unrelated secrets or broad credentials.

      Persistence & Privilegeok

      The skill is not always-on and does not request persistent system privileges. It does not modify other skills or system-wide configs in the provided instructions.

      Guidance

      This skill is just a set of instructions for using the Paperzilla CLI; it appears coherent. Before installing: confirm the package sources (brew tap URL, scoop bucket, or the GitHub release) are official; avoid running curl|tar|sudo pipelines unless you verify the release and checksums; be careful with Atom feed URLs — they include embedded tokens that grant access to your feed and could be leaked if you paste output into external LLMs or services; expect to authenticate interactively with 'pz login' (check where 'pz' stores credentials on your system). If you need higher assurance, inspect the pz repository/release or prefer the package-manager install (brew/scoop) over a direct curl download.

      Latest Release

      v0.1.0

      Initial release

      More by @pors

      Clawdbot Release Check

      11 stars

      B2B First Ten

      4 stars

      Crucial Conversations Coach

      2 stars

      Paperzilla CLI

      0 stars

      self-improving-agent

      @pskoett · 1,456 stars

      Gog

      @steipete · 672 stars

      Published by @pors on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]