paperclipai/paperclip · error

Invalid install payload identifier

Error message

Invalid install payload identifier '${identifier}'.

What it means

payloadPathFor validates the payload identifier against a safe filename charset; the identifier contains characters outside [A-Za-z0-9._-] and would escape the payload directory scheme.

Solutions

  1. Use a valid install payload identifier (a simple name without path separators or traversal).
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at cli/src/install-store.ts:210 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of paperclipai/paperclip@01ad858492 (2026-08-18). Data as JSON: /api/errors/2bc006ece8f1da64. Report an issue: GitHub.

Appendix: source

Thrown at cli/src/install-store.ts:210

    return await callback();
  } finally {
    try {
      if (fs.readFileSync(paths.lockPath, "utf8").trim() === token) {
        fs.rmSync(paths.lockPath, { force: true });
      }
    } catch (error) {
      if ((error as NodeJS.ErrnoException).code !== "ENOENT") throw error;
    }
  }
}

export function payloadPathFor(
  paths: InstallStorePaths,
  source: InstallSource,
  identifier: string,
): string {
  if (!/^[A-Za-z0-9._-]+$/.test(identifier)) {
    throw new Error(`Invalid install payload identifier '${identifier}'.`);
  }
  return path.join(paths.installsRoot, source, identifier);
}

export function readInstallManifest(paths = resolveInstallStorePaths()): InstallManifest | null {
  try {
    const value = JSON.parse(fs.readFileSync(paths.manifestPath, "utf8")) as InstallManifest;
    if (
      value.schemaVersion !== INSTALL_MANIFEST_VERSION ||
      (value.source !== "npm" && value.source !== "git") ||
      !Array.isArray(value.previous) ||
      typeof value.payloadPath !== "string"
    ) {
      throw new Error("unsupported manifest shape");
    }
    return value;
  } catch (error) {
    if ((error as NodeJS.ErrnoException).code === "ENOENT") return null;

View on GitHub (pinned to 01ad858492)