paperclip-api
Use when managing Paperclip AI agent companies - creating tasks, managing agents, approving hires, running heartbeats, or any Paperclip control-plane…
Use when publishing, open-sourcing, exporting, sanitizing, or moving code, agent skills, prompts, templates, fixtures, datasets, workshop assets, or other artifacts from a private repository, vendor/runtime environment, or mixed working directory into a public repository or
$ npx -y skills add serejaris/personal-corp-os --skill safe-public-release --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/safe-public-releaseContext preview
The summary Claude sees to decide when to auto-load this skill.
Use when publishing, open-sourcing, exporting, sanitizing, or moving code, agent skills, prompts, templates, fixtures, datasets, workshop assets, or other artifacts from a private repository, vendor/runtime environment, or mixed working directory into a public repository or
name: safe-public-release description: >- Use when publishing, open-sourcing, exporting, sanitizing, or moving code, agent skills, prompts, templates, fixtures, datasets, workshop assets, or other artifacts from a private repository, vendor/runtime environment, or mixed working directory into a public repository or registry. Builds a provenance inventory, license/security review, explicit allowlist, clean staging package, approval dry run, and fresh public clone/install smoke. Triggers on "open source this", "publish these skills", "make this repo public", "export and sanitize", "подготовь публичный релиз", "выложи скиллы", "опенсорсни", "санитизируй и опубликуй". NOT for ordinary upstream bugfix PRs, vulnerability disclosure, or creating a corp-* department.
Turn a private, vendor-provided, runtime-generated, or mixed artifact into a public package without leaking secrets, private state, or material that cannot be redistributed.
One pipeline:
`intent → owner issue tree → inventory → provenance → license → security/privacy → allowlist → clean package → approval → publish → fresh public verification → maintenance`
The skill is **allowlist-first**. Never copy a whole runtime/private directory and hope denylist cleanup finds everything.
Publishing is an outward mutation. Before creating a public repository, changing visibility, pushing a release, or publishing to a registry:
1. complete the inventory and release manifest; 2. reach `PACKAGE-READY` with no unresolved provenance/license/security blockers; 3. show the user the release dry run; 4. receive explicit approval for the named public target and artifact set.
A request to "prepare" or "review" a release authorizes read-only analysis and private/internal artifacts, not public publication.
Resolve configuration from the user, project instructions, then defaults:
## Safe Public Release Config - internal_owner_repo: owner/corp-opensource-or-project - public_github_owner: owner - staging_root: /tmp/safe-public-release - allowed_public_licenses: MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause - secret_scanners: gitleaks, trufflehog - approval_mode: explicit-before-publish
Do not block preparation when optional scanners are unavailable. Record the limitation and keep the release blocked until equivalent manual and repository-native checks are completed. Never claim a scan ran when it did not.
Before extraction or packaging, find or create three scopes in the internal owner repo:
1. **Owner epic** — intended release, audience, source, risk owner, definition of done. 2. **Inventory/review child** — provenance, licenses, companion files, security classification, allowlist. 3. **Publish/verify child** — public repo/package creation after approval, fresh-clone verification, maintenance.
Separate unrelated work:
If the user has an issue-management skill such as `manager`, use it for the issue tree and cross-repo links.
Use exactly one current status:
Every blocked status needs one concrete `unblock_event`: source found, written permission, license clarified, secret removed and rotated, scope reduced, or owner approval.
Record:
Do not create the public repository yet.
Create `release-manifest.yaml` using [the bundled template](references/release-manifest.example.yaml).
For each candidate artifact record:
Visibility inside an application or runtime does not prove ownership or permission to redistribute.
| Class | Default decision | |---|---| | Owner-authored source | Candidate after license/security review | | Third
Personal Corp is a way to run a one-person company through AI agents: tasks out of your head, departments instead of one person's memory, a weekly retro instead of "I'll sort it out someday".
Use when managing Paperclip AI agent companies - creating tasks, managing agents, approving hires, running heartbeats, or any Paperclip control-plane…
Orchestrate iterative visual style searches with branch prompts, decision graphs, feedback loops, and final direction selection.
Use when user asks for Claude Code usage stats, weekly analytics, project activity summary, or wants to see what projects were worked on. Triggers on…
Use when needing strategic project analysis from multiple independent expert perspectives. Triggers on business decisions, growth strategy, product direction,…
Use when creating or refactoring CLAUDE.md files - enforces best practices for size, structure, and content organization
Use when a Personal Corp operating loop needs setup, repair, a new department, or task routing: HQ files and agent rules, GitHub issue workflow, corp-* owner…