paperclipai/paperclip · error · Error
Refusing to install into unsafe payload root
Error message
Refusing to install into unsafe payload root ${sourceRoot}. What it means
Path-safety guard when staging an npm payload: the computed payload root (sourceRoot) resolves outside the managed install store layout the installer controls, so the copy/extract step aborts rather than writing to an arbitrary filesystem location.
Solutions
- Do not install from an untrusted payload root; use the official npm package or a verified repo/ref.
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at cli/src/commands/install.ts:196 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of paperclipai/paperclip@01ad858492 (2026-08-18).
Data as JSON: /api/errors/a4825140aee9a0df.
Report an issue: GitHub.
Appendix: source
Thrown at cli/src/commands/install.ts:196
throw new Error(`Installed CLI smoke check reported ${reportedVersion || "no version"}; expected ${expectedVersion}.`);
}
}
export async function installNpmPayload(
version: string,
runCommand: CommandRunner,
paths = resolveInstallStorePaths(),
): Promise<{ payloadPath: string; reused: boolean }> {
const payloadPath = payloadPathFor(paths, "npm", version);
if (fs.existsSync(payloadPath)) {
await smokePayload(payloadPath, version, runCommand);
return { payloadPath, reused: true };
}
const sourceRoot = path.dirname(payloadPath);
fs.mkdirSync(sourceRoot, { recursive: true, mode: 0o700 });
const sourceStat = fs.lstatSync(sourceRoot);
if (!sourceStat.isDirectory() || sourceStat.isSymbolicLink()) {
throw new Error(`Refusing to install into unsafe payload root ${sourceRoot}.`);
}
fs.chmodSync(paths.cliRoot, 0o700);
fs.chmodSync(paths.installsRoot, 0o700);
fs.chmodSync(sourceRoot, 0o700);
const stagingPath = path.join(sourceRoot, `.${version}.tmp-${process.pid}-${Date.now()}`);
const npmUserConfigPath = path.join(sourceRoot, `.npmrc-${process.pid}-${Date.now()}`);
fs.rmSync(stagingPath, { recursive: true, force: true });
try {
fs.writeFileSync(
npmUserConfigPath,
`registry=${PUBLIC_NPM_REGISTRY}\n@paperclipai:registry=${PUBLIC_NPM_REGISTRY}\n`,
{ mode: 0o600 },
);
await runCommand(
"npm",
[
"install",
"--prefix",View on GitHub (pinned to 01ad858492)