Skip to content
CAI
Software that uses CAICheck a score

paperclipai/paperclip

51.0

Adequate · 28 September 2026

1221.5k

lines of production code

TypeScript

primary language

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Paperclip is a multi-tenant platform for managing AI agents and their execution workflows, providing a centralized control plane for orchestration, monitoring, and administration. It supports a diverse ecosystem of local and cloud-based coding agents through a modular adapter system and enables secure, sandboxed code execution via pluggable infrastructure providers. The platform facilitates team collaboration through structured issue tracking, automated skill catalogs, and a plugin architecture that extends core functionality with custom UI and logic.

Features

Add CreateOS sandbox provider plugin

A new sandbox provider plugin for CreateOS is available, allowing users to run Paperclip agents in CreateOS sandboxes. The plugin registers an environment driver named 'createos' and exposes configuration options for the API URL, API key, compute shape, root filesystem, region, command timeout, and lease reuse behavior. It implements sandbox lifecycle management (create, pause, resume, destroy), incremental command execution with NDJSON output, and file synchronization (sync in/out) with support for binary transfers, directory archives, and post-upload commands. The provider supports reusable leases to preserve workspace data across runs and includes safety measures such as path confinement, archive validation, and rate limiting for API requests.

packages/plugins/sandbox-providers/createos, packages/plugins/sandbox-providers/e2b/src, packages/plugins/sandbox-providers/modal · high confidence

Add File Browser and Hello World example plugins

Two new example plugins are available for local development: the File Browser plugin adds a 'Files' sidebar link and a project detail tab with a responsive file tree and code editor (including save support), plus comment file-link annotations; the Hello World plugin provides a minimal dashboard widget to demonstrate basic plugin structure. Both are repo-local examples intended for development and require a local build before installation.

packages/plugins/examples/plugin-file-browser-example · high confidence

Add Hermes Gateway Smoke Test Container

A new Dockerfile and entrypoint script have been added to the \docker/hermes-gateway-smoke\ directory to support a smoke test environment for the Hermes gateway. The container is based on Node 24 and installs the \hermes-agent\ Python and npm packages at version 0.17.0. The entrypoint configures the API server (enabled on port 8642), generates or uses an API key, and executes the \hermes gateway run\ command with hook acceptance enabled.

docker/hermes-gateway-smoke · high confidence

Add Hermes Gateway adapter for remote agent execution

Introduces a new \hermes\_gateway\ adapter that allows Paperclip to manage a remote Hermes Agent instance via its HTTP API server. This adapter creates runs through \POST /v1/runs\, observes progress via Server-Sent Events (SSE), and supports session continuity using configurable \X-Hermes-Session-Key\ strategies (issue, agent, run, or none). It includes a robust environment test that validates connectivity and enforces transport security by blocking remote plain HTTP connections unless a specific escape hatch is enabled. Additionally, it provides a CLI output parser that extracts real reasoning text from gateway events and strips ANSI escape codes for clean terminal display.

packages/adapters/hermes/src · high confidence

Add KV Demo MCP Server fixture for local demonstrations

A new standalone demo package (\@paperclipai/kv-demo-mcp-server\) is introduced to showcase Paperclip's MCP integration. It provides a single-process server exposing four key/value MCP tools (\kv\_list\, \kv\_get\, \kv\_set\, \kv\_delete\) over Streamable HTTP, alongside a lightweight web UI that visualizes the in-memory store state in real-time. The tools are annotated with risk levels (read, write, destructive) to demonstrate Paperclip's policy enforcement and audit logging, with \kv\_delete\ specifically quarantined by default. The server supports optional token-based authentication via the \KV\_DEMO\_TOKEN\ environment variable and is designed for local development and demo scenarios.

packages/kv-demo-mcp-server · high confidence

Add Novita Agent Sandbox provider plugin

Operators can now provision execution environments using the Novita Agent Sandbox service by installing the \@paperclipai/plugin-novita-sandbox\ plugin. The plugin registers a new environment driver that manages sandbox lifecycle (creation, connection, execution, and lease reuse) via the Novita SDK. Configuration is handled in Instance Settings -\> Environments, where users can provide an API key (stored as a company secret), specify a template ID, set timeouts, and enable features like auto-pause and lease reuse.

packages/plugins/sandbox-providers/novita · high confidence

Add native in-app announcements with persistent dismissal

The application now supports native in-app announcements that can be dismissed persistently. This change introduces the underlying data structure and example configurations for these announcements, including a staging preview and an animated example featuring a 'Plan, Build, Review' workflow visualization.

announcements · high confidence

Add plugin orchestration smoke example

Introduces a first-party smoke test plugin that validates the orchestration-grade plugin host surface. It exercises API routes, restricted database migrations, plugin-owned rows joined to public issues, child issue creation with namespaced metadata, billing codes, workspace inheritance, blocker relations, documents, wakeups, and orchestration summaries. The plugin registers UI slots for a dashboard widget, issue detail tab, and settings page to surface route, capability, namespace, and smoke status information.

packages/plugins/examples/plugin-authoring-smoke-example, packages/plugins/examples/plugin-orchestration-smoke-example · high confidence

Claude Local adapter UI configuration and transcript parsing

The Claude Local adapter now includes dedicated UI utilities to build configuration objects and parse agent stdout into structured transcript entries. The new \buildClaudeLocalConfig\ function translates UI form inputs into adapter settings, specifically handling the selection of the execution engine (defaulting to 'auto' to allow runtime fallback, while supporting explicit 'cli' or 'acp' pins), managing environment variable bindings (preserving user-scoped secrets and plain values), and configuring workspace strategies like git worktrees. Additionally, the \parseClaudeStdoutLine\ function processes raw agent output into detailed transcript entries, supporting text, thinking blocks, tool calls, and results, while delegating ACP-specific events to the shared ACP parser.

packages/adapters/claude-local/src/ui, packages/adapters/codex-local/src/ui · high confidence

Codex local adapter introduces ACP execution engine and device-login authentication

The Codex local adapter now supports the ACP execution engine as the default runtime, replacing the legacy CLI engine when environment constraints allow, and introduces a secure device-login flow that promotes credentials into company-scoped homes. This change adds structured stream event formatting for the CLI, robust quota classification that extracts retry times from provider limits, and a new auth precedence system that prioritizes configured API keys and host credentials over sandbox snapshots while warning when sandbox logins are shadowed.

packages/adapters/codex-local/src/server · high confidence

Cursor local adapter now supports remote sandbox and SSH execution

The Cursor local adapter has been extended to execute agent commands in remote environments, including both sandboxed runtimes and SSH-connected workspaces. Users can now run Cursor agents outside their local machine, with the adapter automatically resolving the correct agent binary (preferring \\~/.local/bin\ or \\~/.cursor/bin\), injecting Paperclip skills, and managing workspace synchronization. The adapter also includes a new environment testing flow that verifies command availability and authentication before execution, and robustly parses Cursor's JSONL output streams to surface session details, costs, and errors.

packages/adapters/cursor-local/src/server · high confidence

Database schema foundation for agent operations, issue tracking, and multi-tenant isolation

The database schema has been established with migrations 0000 through 0026, introducing core tables for multi-tenant isolation (companies, company\_memberships), agent lifecycle and runtime state (agents, agent\_api\_keys, agent\_runtime\_state, agent\_task\_sessions), and issue management (issues, issue\_comments, issue\_labels, issue\_read\_states). It also adds support for project workspaces (project\_workspaces, workspace\_runtime\_services), cost tracking (cost\_events), and secure credential management (company\_secrets, company\_secret\_versions).

packages/db/src/migrations · high confidence

Daytona sandbox provider plugin introduces duplex command streaming and secure login PTY sessions

The Daytona sandbox provider plugin now supports a duplex command stream for bidirectional host-to-sandbox communication, enabling real-time command execution and output streaming via a pseudo-terminal (PTY) with raw mode and echo disabled to ensure clean frame delivery. Additionally, the plugin implements a secure login PTY session mechanism that uses a closed command map to launch login commands (Claude, Codex, Grok) safely, preventing command injection by encoding session home paths and using \exec\ to replace the shell process. The plugin also includes comprehensive file-sync capabilities with zstd-3 compression for efficient file transfers, and robust error handling for scratch file cleanup during sync operations.

packages/plugins/sandbox-providers/daytona/src · high confidence

Documentation of new architectural plans for module system, agent authentication, and permissions

Added a series of dated planning documents in \doc/plans\ outlining upcoming architectural changes. These include the Paperclip Module System for extending the control plane, a tiered Agent Authentication strategy (including local JWT adapters and self-registration), a comprehensive Humans and Permissions model with Better Auth integration, and implementation plans for storage, issue orchestration, and CEO hiring governance.

doc/plans · high confidence

Gemini Local adapter UI support for ACP engine and Gemini CLI v0.38 wire format

The Gemini Local adapter now includes UI-layer support for configuring and running the Gemini CLI via the ACP (Agent Control Protocol) engine, allowing users to pin the engine to 'acp' or 'cli' and configure specific ACP parameters like agent commands, modes, and permissions. Additionally, the adapter's stdout parser has been updated to handle the Gemini CLI v0.38 stream-json wire format, correctly interpreting new message structures, token usage statistics, and error states while maintaining backward compatibility with legacy formats.

packages/adapters/gemini-local/src/ui · high confidence

Generated telemetry types for agent and interaction events

The shared telemetry module now includes generated TypeScript types for Paperclip events, enabling structured tracking of agent lifecycle events (creation, heartbeats, task runs/completions) and interaction outcomes (creation, resolution). The diff introduces specific dimension interfaces for these events, including new fields such as \adapter\_type\ (supporting local, HTTP, and cloud adapters like Codex and Kimi) and \agent\_role\ (covering roles from CEO to Engineer), which allows downstream systems to capture detailed context about how and by whom tasks are executed and decisions are resolved.

packages/shared/src/telemetry/generated · high confidence

Initial CLI release with bundled build and changelog

The CLI package is now available as a standalone npm distribution, starting with version 0.3.1. This release introduces a new esbuild-based build process that bundles workspace packages into a single executable targeting Node 24, alongside a comprehensive CHANGELOG.md documenting the version history from 0.2.1 through 0.3.1 and a new README.md with updated documentation and links.

cli · high confidence

Initial release of the @paperclipai/db package with Drizzle ORM support

This change introduces the new \packages/db\ package, establishing the project's database layer using Drizzle ORM with a PostgreSQL dialect. It includes the core configuration files (\drizzle.config.ts\, \tsconfig.json\, \vitest.config.ts\) and a changelog tracking versions from 0.2.1 through 0.3.1. A key behavioral addition is the configuration of \.gitattributes\ to treat Drizzle migration snapshots as binary files, which prevents merge conflicts and reduces diff noise by disabling text-based merging and diffing for these generated files.

packages/db · high confidence

Initial repository scaffolding and contributor guidance

The repository now includes foundational configuration and documentation files to support development and contribution workflows. A \.dockerignore\ file is introduced to optimize Docker build contexts by excluding test files, documentation, and build artifacts from the \paperclip-runner\ package, while explicitly preserving generated files and regression tests required for traceability checks. Developer experience is enhanced with an \.nvmrc\ file pinning the Node.js version to 24, a \.mailmap\ for consistent author attribution, and a \.gitattributes\ rule for whitespace handling. New documentation files provide comprehensive guidance: \AGENTS.md\ defines engineering rules, data path distinctions (Telemetry, Observability, Run Log), and database workflows; \CONTRIBUTING.md\ outlines PR requirements, including search-first policies, template usage, and Greptile review standards; \DESIGN.md\ establishes the single-source token layer in \ui/src/index.css\ and design principles; \ROADMAP.md\ details the product vision and milestone status; and \SECURITY.md\ provides a vulnerability reporting channel. Additionally, an example environment file \.env.runner-e2e.example\ is added to support end-to-end testing configurations.

(repo-wide) · high confidence

Initial teams catalog package with bundled and optional team definitions

The new \@paperclipai/teams-catalog\ package introduces a structured catalog for team definitions, including a \MIGRATION.md\ that documents the transition from legacy onboarding assets. It ships three bundled teams: the \Core Exec Team\ (CEO, CTO, QA) which is set to install by default, the \Product Engineering\ pod (CTO, Senior Coder, QA), and the \Product Design\ team (UX Designer). Additionally, it includes an optional \Content Machine\ team for content operations. The package also provides the \catalog-builder\ tooling to generate a \catalog.json\ manifest and validate team structures, ensuring that agent skills, project slugs, and recurring tasks are correctly resolved and documented.

packages/teams-catalog · high confidence

Interactive setup prompts for database, storage, secrets, and server configuration

The CLI now includes a new set of interactive configuration wizards in the \cli/src/prompts\ directory, guiding users through initial setup for database, storage, secrets, LLM, logging, and server settings. Users can choose between embedded PostgreSQL and external PostgreSQL for the database, select between local disk and S3-compatible storage, configure secret providers (local encrypted, AWS Secrets Manager, GCP Secret Manager, or HashiCorp Vault), and define server reachability modes (loopback, LAN, Tailnet, or custom) with specific authentication and exposure profiles. These prompts use the \@clack/prompts\ library to collect and validate user input, defaulting to recommended local configurations while allowing customization for production or multi-user environments.

cli/src/prompts · high confidence

Introduce Cursor Cloud adapter for remote agent execution

A new \cursor\_cloud\ adapter has been added to the \packages/adapters/cursor-cloud\ location, enabling Paperclip to run Cursor Cloud Agents through the official Cursor SDK. This adapter supports durable remote agent sessions that persist across Paperclip heartbeats, allowing Cursor to handle remote code execution while Paperclip retains task state. Users can configure the adapter with a Git repository URL, select a runtime environment (cloud, self-hosted pool, or named machine), and optionally enable features like auto-creating pull requests. The implementation includes CLI event formatting, server-side execution logic, session management, and environment validation to ensure proper authentication and configuration.

packages/adapters/cursor-cloud · high confidence

Introduce Cursor Local adapter UI and CLI formatting

Adds the user-facing interface for the new Cursor Local adapter, including CLI event formatting and UI stdout parsing. The CLI now displays structured run logs with color-coded user/assistant messages, thinking blocks, and tool calls/results. The UI parses the adapter's stdout into transcript entries, handling shell tool output truncation and error states, enabling users to view and interact with Cursor Local agent runs in the interface.

packages/adapters/cursor-local/src/ui · high confidence

Introduce Fake Sandbox Provider plugin for local testing

A new first-party 'Fake Sandbox Provider' plugin has been added to the Paperclip ecosystem, enabling deterministic, infrastructure-free testing of the sandbox provider-plugin integration. This plugin registers a 'fake-plugin' environment driver that executes commands within isolated local temporary directories, supporting the full lifecycle of environment management including lease acquisition, workspace realization, command execution, and interactive setup. It also provides capabilities for capturing and deleting snapshot templates, allowing developers to exercise provider-plugin interactions and verify behavior without relying on external sandbox infrastructure.

packages/plugins/paperclip-plugin-fake-sandbox · high confidence

Introduce Gemini CLI local adapter with ACP engine support

A new local adapter for the Gemini CLI is now available, allowing Paperclip to run Gemini locally on the host machine. The adapter defaults to the ACP engine (requiring Node 24+) for persistent, resumable sessions and skill injection, while also supporting a legacy CLI engine. It includes a comprehensive list of supported models (including Gemini 3.1 Pro, 3.8 Flash, and 2.5 Pro) and handles headless execution by suppressing browser auth prompts. The adapter automatically installs the \@google/gemini-cli\ package in its sandbox and injects local skills into \\~/.gemini/skills/\.

packages/adapters/gemini-local/src · high confidence

Introduce Google Sheets MCP server with HTTP and stdio modes

Adds a new first-party Google Sheets MCP server that exposes nine tools (list\_spreadsheets, get\_spreadsheet\_info, read\_values, search\_rows, append\_rows, update\_values, add\_sheet\_tab, clear\_values, delete\_rows) to interact with Google Sheets API v4. The server supports two transport modes: a local stdio process for Paperclip's gallery connections and a local Streamable HTTP server (default port 8849) for remote HTTP access. Access is restricted to a configured allowlist of spreadsheet IDs, and the HTTP mode enforces a bearer token when bound to non-loopback hosts. Configuration is handled via environment variables (GOOGLE\_SHEETS\_SERVICE\_ACCOUNT\_JSON/PATH, GOOGLE\_SHEETS\_ALLOWED\_SPREADSHEET\_IDS) and CLI flags, with service account credentials validated using Zod.

packages/google-sheets-mcp-server · high confidence

Introduce Kimi Code CLI local adapter with dual execution engines

Users can now run the Kimi Code CLI locally via a new \kimi\_local\ adapter that supports both the ACP (Agent Control Protocol) engine and a direct CLI engine. The adapter exposes several Kimi models (K2.8 Preview, K2.7 Coding Highspeed, K3, and K3 256K) and allows users to configure thinking effort levels (low, high, max) for compatible models. It handles session persistence by capturing and resuming session IDs, manages skill injection through a dedicated skills directory, and provides robust error handling for authentication, network issues, and session failures. The adapter defaults to the ACP engine but allows explicit selection of the CLI engine, with appropriate environment setup for headless execution.

packages/adapters/kimi-local/src · high confidence

Introduce Kubernetes sandbox provider plugin

Adds the \@paperclipai/plugin-kubernetes\ plugin, enabling Paperclip to dispatch agent runs in per-tenant Kubernetes namespaces. The plugin supports two backend modes: a default \sandbox-cr\ mode (alpha) using the \kubernetes-sigs/agent-sandbox\ controller for multi-command exec, and a stable \job\ fallback using \batch/v1\ Jobs. It includes native file-sync over pod exec, task-scoped egress grants (via standard NetworkPolicy or CiliumNetworkPolicy), adapter-specific runtime defaults, and a hardened security baseline (non-root, read-only root filesystem, restricted capabilities, and deny-all ingress).

packages/plugins/sandbox-providers/cloudflare, packages/plugins/sandbox-providers/kubernetes · high confidence

Introduce LLM Wiki plugin for local knowledge management and maintenance

Adds the LLM Wiki plugin, which provides a local-file wiki system for source ingestion, browsing, querying, and automated maintenance. The plugin introduces a Wiki Maintainer agent, managed skills (ingest, query, lint, distill), and three background routines (cursor-window processing, nightly linting, and index refreshing) to keep wiki content structured and up-to-date. It includes a dedicated UI for managing wiki spaces, viewing operations, and editing content, along with event ingestion capabilities to automatically process Paperclip issues, comments, and documents into the wiki.

packages/plugins/plugin-llm-wiki/src · high confidence

Introduce LLM Wiki plugin package with local file ingestion and wiki management

Adds the \@paperclipai/plugin-llm-wiki\ package, providing a standalone local-file LLM Wiki plugin for source ingestion, wiki browsing, query, lint, and maintenance workflows. The plugin introduces a manifest-declared Wiki page, sidebar entry, and settings page, along with trusted local folder declarations for raw and wiki content. It includes a plugin database namespace migration for wiki instances, sources, pages, operations, query sessions, and resource bindings, as well as managed \Wiki Maintainer\ agent and \LLM Wiki\ project configurations. The package supports local source capture into \raw/\ with metadata persistence, opt-in company-scoped Paperclip event ingestion controls, and manual Paperclip project/root issue distillation with bounded backfill actions. It also features wiki page writes with plugin path validation, atomic local-folder writes, metadata/revision rows, backlink extraction, and optional stale-hash protection, alongside tools for search, read, write, propose patch/source/log/index/backlinks workflows. The entry point for this change is the new \packages/plugins/plugin-llm-wiki\ directory, which contains the plugin's configuration, build scripts, and documentation.

packages/plugins/plugin-llm-wiki · high confidence

Introduce OpenClaw Gateway adapter UI configuration and log parsing

This change adds the UI-layer support for the new OpenClaw Gateway adapter, enabling users to configure and interact with OpenClaw-based agents. The \build-config.ts\ module constructs the gateway configuration object, applying safe defaults for timeouts (120s/120000ms) and identity (role: operator, scopes: operator.admin) while handling authentication tokens, device auth settings, and custom headers. The \parse-stdout.ts\ module implements log parsing to translate OpenClaw gateway output streams into structured transcript entries, distinguishing between assistant messages, errors, and lifecycle events. These components are exported via \index.ts\ to integrate with the broader adapter system.

packages/adapters/openclaw-gateway/src/ui · high confidence

Introduce OpenClaw Gateway adapter with CLI event formatting and stream normalization

The new openclaw-gateway adapter adds CLI capabilities for handling stream events. It includes a stream normalization utility that parses lines prefixed with 'stdout' or 'stderr' to distinguish output sources, and a CLI formatter that prints these events with color coding (cyan for debug events, blue for standard gateway events, gray for others) when debug mode is enabled, or plain text otherwise.

packages/adapters/openclaw-gateway/src/cli, packages/adapters/openclaw-gateway/src/shared · high confidence

Introduce OpenClaw Gateway adapter with WebSocket-based agent configuration

A new 'openclaw\_gateway' adapter has been added, enabling Paperclip to invoke OpenClaw via the Gateway WebSocket protocol rather than standard HTTP endpoints. This adapter supports native gateway authentication and connection semantics, allowing users to configure connection details such as the WebSocket URL, shared tokens, and client identity. It includes specific configuration options for session routing strategies, timeout handling, and automatic device pairing on first connect. The adapter also defines how wake payloads are structured, ensuring compatibility with the gateway agent schema by embedding Paperclip context in message text rather than sending unsupported root-level parameters.

packages/adapters/openclaw-gateway/src · high confidence

Introduce OpenCode local adapter UI parsing and configuration

The OpenCode local adapter now includes a UI integration layer that handles configuration building and stdout parsing. The new \build-config.ts\ module maps adapter settings (such as working directory, model, and environment bindings) into the specific format required by the OpenCode CLI, while \parse-stdout.ts\ implements a parser that converts OpenCode's JSON-based stdout stream into structured transcript entries, supporting assistant text, thinking/reasoning blocks, tool calls with results, and step completion metrics.

packages/adapters/opencode-local/src/ui · high confidence

Introduce OpenCode local adapter for local agent runtime

A new 'opencode\_local' adapter is added, allowing users to run the OpenCode CLI locally as the agent runtime. This adapter manages its own sandbox installation via a custom script to optimize for bandwidth-constrained environments and supports a wide range of models from providers like OpenAI, Anthropic, Google, and xAI. It enables provider/model routing, session resumption, and configurable permissions (including a headless-safe 'allow-all' mode), while explicitly preventing config file pollution in the workspace by disabling OpenCode's project config writing.

packages/adapters/opencode-local/src · high confidence

Introduce OpenCode local adapter with remote execution and environment-driven configuration

This change adds the \opencode-local\ adapter, enabling the system to execute AI tasks using the OpenCode runtime. It supports both local and remote (SSH) execution targets, including workspace preparation, skill injection, and environment syncing for remote runs. The adapter features a new CLI event formatter for structured JSONL output, robust model discovery with retry logic and caching, and environment-driven configuration via \PAPERCLIP\_OPENCODE\_PROVIDERS\ and \PAPERCLIP\_OPENCODE\_SMALL\_MODEL\ to support custom providers and cost optimization. It also includes a session codec for handling session persistence and a parser for OpenCode's JSONL stream to extract summaries, usage, and errors.

packages/adapters/opencode-local/src/server · high confidence

Introduce PR Gardening skill to maintain instance-authored pull requests

A new automated workflow has been added to actively manage pull requests opened by the Paperclip instance itself. The skill discovers candidates by scanning recent issues for PR mentions, then mechanically verifies their readiness by checking status checks, Greptile results, merge conflicts, and review decisions. It restricts its scope to the instance's own GitHub identity by default, excluding community contributions, and drives non-ready PRs toward a green state using the \/prepare-paperclip-pr\ skill without ever merging or approving them. The workflow includes safeguards against duplicate task creation, respects activity windows and cooldowns, and can optionally tidy the user's inbox by archiving originating issues once a PR is confirmed merged.

.agents/skills/pr-gardening · high confidence

Introduce Paperclip Eval Kernel and standalone Runner devtools

This change introduces the \@paperclipai/paperclip-eval-kernel\ package, a workspace-private, provider-neutral matrix orchestrator for evaluations that enforces fail-closed compatibility checks via \assertPaperclipRunnerCompatibility\ before execution. It also adds a standalone browser-based devtool for the Paperclip Runner, featuring a live console for interactive protocol debugging, a static PRP replay viewer for inspecting protocol fixtures, and a local runner diagnostics view, all supported by new Playwright acceptance tests and a comprehensive README.

packages/paperclip-runner · high confidence

Introduce Paperclip Plugin SDK for authoring and testing plugins

The \@paperclipai/plugin-sdk\ package is now available in \packages/plugins/sdk/src\, providing the core tooling for plugin authors. It includes \definePlugin\ for declaring plugin behavior (events, jobs, UI data), \createPluginBundlerPresets\ for esbuild/rollup configuration, and a local development server (\startPluginDevServer\) for previewing plugin UIs. The SDK also exposes a comprehensive \TestHarness\ for unit testing plugin logic and defines the JSON-RPC protocol and capability-gated host-client interfaces that enable secure worker-to-host communication.

packages/plugins/sdk/src · high confidence

Introduce Pi Local adapter with remote execution and custom provider support

The new \pi-local\ adapter enables running the Pi coding agent locally or via remote SSH, including workspace preparation, skill synchronization, and session management. It supports custom LLM gateway routing through the \PAPERCLIP\_PI\_PROVIDERS\ environment variable, which allows injecting provider configurations into a managed \models.json\ file. The adapter also includes robust parsing of Pi's JSONL output for streaming text, tool execution, and usage/cost tracking, along with comprehensive tests for remote execution flows and model discovery.

packages/adapters/pi-local/src/server · high confidence

Introduce Pi-local adapter UI components for configuration and transcript parsing

This change adds the user-facing UI layer for the new pi-local adapter, including build configuration logic and a parser for the adapter's stdout stream. The configuration module maps environment bindings, model settings, and execution commands to the adapter's runtime requirements. The parser translates the Pi agent's JSON-based output into structured transcript entries, handling agent lifecycle events, streaming text and thinking content, and tool results (including extraction from array-formatted content and matching tool names).

packages/adapters/pi-local/src/ui · high confidence

Introduce agent-shim tool for sandboxed adapter execution

Added a new Go-based shim tool in the tools directory that reads a runtime command specification (JSON) and executes the specified adapter binary within the current process. This shim enables sandboxed execution of agent adapters by resolving the command path and replacing the shim process with the target adapter, allowing signals like SIGTERM to reach the adapter directly.

tools · high confidence

Introduce built-in grok\_local adapter with device-login authentication and streaming output formatting

The grok\_local adapter is now available as a built-in option, allowing Paperclip to run the native Grok Build CLI locally on the host machine. This update introduces a secure device-login flow that parses the Grok CLI's authorization prompt, validates the credentials, and promotes them to the company-scoped home directory. It also adds a streaming event formatter that displays real-time agent thoughts, assistant responses, and run completion status directly in the CLI. The adapter supports model-specific reasoning efforts (including xhigh for grok-4.7 and grok-4.6) and stages project skills and instructions into the execution workspace.

packages/adapters/grok-local · high confidence

Introduce local Cursor adapter with sandbox support and auto-injected skills

A new local adapter for the Cursor Agent CLI has been added, enabling users to run Cursor locally as the agent runtime. This adapter handles installation via the official Cursor installer script and provides a comprehensive list of supported model IDs for fallback discovery. Key behavioral changes include piping prompts to Cursor via stdin, resuming chat sessions across heartbeats, and automatically injecting Paperclip local skills into the Cursor environment. The adapter also defaults to the '--yolo' execution flag and supports structured JSON stream output in run logs.

packages/adapters/cursor-local/src · high confidence

Introduce local Pi coding agent adapter

A new adapter for running the Pi AI coding agent locally has been added, allowing users to execute Pi as the agent runtime within Paperclip. This change enables provider/model routing in Pi format, supports session resumption across heartbeats, and provides access to Pi's built-in tool set (read, bash, edit, write, grep, find, ls). The adapter includes a specific sandbox installation command for the Pi coding agent and defines configuration options for working directories, instructions, prompts, and timeouts.

packages/adapters/pi-local/src · high confidence

Introduce managed CLI install, service lifecycle, and onboarding flow

The Paperclip CLI now supports a managed per-user installation model, allowing users to install, update, and uninstall the CLI via dedicated commands while preserving user data. An interactive onboarding wizard guides first-time setup, including the option to install and start a background service (managed via systemd or launchd) and automatically open the dashboard. The CLI also includes a doctor command for diagnostics, a test-drive command for isolated local testing, and telemetry tracking for installation and company import events.

cli/src · high confidence

Introduce paperclip-page skill for publishing static sites to S3/CloudFront

Added the \paperclip-page\ skill, which provides a secure helper script (\publish.sh\) and documentation for publishing static HTML directories to a dedicated Paperclip S3 bucket served via CloudFront. The skill enforces a strict security posture by scoping AWS credentials to the helper process only (using \PAPERCLIP\_PAGE\AWS\\*\ variables), rejecting symlinks and hidden files, and preventing destructive operations like \s3 sync --delete\. It includes a test suite (\publish.test.mjs\) validating credential scoping, slug validation, and dry-run behavior.

.agents/skills/paperclip-page · high confidence

Introduce sandbox duplex frame codec and bridge transport contract

The adapter-utils package now includes a versioned, newline-delimited JSON frame codec (v2) for the sandbox duplex channel, enforcing a 256 KB per-frame size limit to prevent oversized payloads. It also defines the shared bridge transport contract, including the \duplex\_channel\_lost\ error code, run disposition logic, and nested timeout budgets (30s forward, 32s response, 35s gateway wait), while providing a utility to identify safe HTTP methods for retryable operations.

packages/adapter-utils/src · high confidence

Introduce standalone Paperclip MCP server package

Adds a new \@paperclipai/mcp-server\ package that exposes the Paperclip REST API as a Model Context Protocol (MCP) server. The package provides a set of MCP tools for reading and writing issues, managing approvals, handling comments, and controlling issue workspace services, along with runtime-scoped tools for connection search and requests. It is configured via environment variables (\PAPERCLIP\_API\_URL\, \PAPERCLIP\_API\_KEY\, etc.) and can be run via \npx\ or locally from the built distribution.

packages/mcp-server · high confidence

Introduces a comprehensive shared type system for access, agents, and company portability

This change establishes the foundational TypeScript type definitions for the application's core domain models. It introduces a new shared types package that defines the data contracts for multi-tenant access control (including company memberships, permission grants, and invites), agent lifecycle and configuration (covering agent details, runtime settings, and adapter authentication sessions), and company portability (defining the structure for exporting and importing company data, skills, and issues). Additionally, it adds types for operational concerns such as activity tracking, budget policies, and artifact management, providing a unified schema layer for the rest of the system.

packages/shared/src/types · high confidence

Introduces a structured telemetry client with privacy safeguards and wire-compliant batching

This change adds a new telemetry client implementation in \packages/shared/src/telemetry\ that enforces a strict data contract for event emission. It introduces typed helpers for first-party events (such as \agent.task\_run\ and \interaction.resolved\) and a separate path for dynamic plugin events. The client ensures privacy by hashing private identifiers (like \task\_id\) before emission and strictly forbids sending sensitive data like credentials or prompts. It also implements wire-compliant batching, automatically splitting event queues into chunks based on count and byte-size limits, and includes deterministic retry logic with idempotency keys to handle network failures gracefully.

packages/shared/src/telemetry · high confidence

Introduces domain logic for run-dispatch policy and wake context

This change adds the core domain logic for the run-dispatch module, introducing pure decision rules for the scheduled-retry promotion gate and queued-run staleness checks. It defines the data structures and validation logic for handling agent invokability, budget blocks, issue status transitions (such as reassignment or cancellation), and review participant changes. Additionally, it implements wake-context classifiers to correctly interpret retry reasons, specifically distinguishing non-assignee workspace busy retries and resolving interaction continuations from comments or reviews.

server/src/modules/run-dispatch/domain · high confidence

Introduces durable ACPX provider runtime with suspension checkpoints and sidecar transport

The runner-core crate now includes a complete implementation for the Agent Client Protocol (ACPX) provider backend, enabling the Paperclip Runner to manage qualified AI agent sessions (specifically Claude and Codex profiles) with durable state. This change adds a sidecar transport layer for communicating with external agent processes, an event scope and payload decoder to validate and normalize runtime events (such as tool calls, permissions, and text deltas), and a provider state machine that tracks pending requests and turn status. Crucially, it introduces suspension checkpoints that allow sessions to be safely paused and resumed, preserving identity and tool catalog state across restarts, while enforcing strict bounds on event sizes, turn IDs, and permission modes to ensure stability and security.

packages/paperclip-runner/runner/crates/runner-core/src · high confidence

Introduces durable runner core with secure transport and state persistence

The Paperclip Runner now includes a new durable execution layer that persists session state and commands to disk, allowing workspaces and sessions to survive restarts and recover integrity. This change adds a secure WebSocket transport (wss://) with TLS support, authenticated connections, and encrypted frames to protect data in transit. It also implements a bootstrap ticket mechanism for secure initialization and defines a structured protocol (paperclip.runner v2) for managing commands, events, and launch profiles, ensuring that runner operations are reliable and auditable.

packages/paperclip-runner/runner/crates/runner-core/src/durable · high confidence

Introduces isolated local state management and hardened configuration storage

The CLI now supports isolating local runtime state via the new --data-dir flag, which allows users to specify a custom directory for instance-specific data, configuration, and secrets. This change introduces a robust configuration store that automatically migrates legacy database settings (pglite to embedded-postgres), validates config schemas, and safely backs up invalid configurations. Additionally, the CLI now manages environment variables and secrets more securely by automatically generating and persisting JWT and tool-action signing secrets in a local .env file, and by auto-creating a local secrets encryption key file during onboarding when using the local\_encrypted provider.

cli/src/config · high confidence

Kitchen Sink plugin example added to demonstrate full plugin API surface

A new reference plugin example has been added to showcase the complete Paperclip plugin API, including UI slots (pages, settings, sidebar, widgets, annotations), runtime launchers, agent tools, scheduled jobs, webhooks, and local workspace command execution. The example includes a build script for the UI bundle and a comprehensive manifest defining capabilities, configuration options, and entry points.

packages/plugins/examples/plugin-kitchen-sink-example/src · high confidence

LLM Wiki plugin includes fixture templates for knowledge base initialization

The LLM Wiki plugin now ships with a \basic-root\ fixture directory containing the initial file structure and configuration for a persistent, LLM-maintained personal wiki. This includes \AGENTS.md\ (the operational schema instructing the LLM on how to ingest sources, maintain pages, and handle queries), \IDEA.md\ (the conceptual pattern reference), and a pre-seeded wiki skeleton with directories for sources, projects, entities, concepts, and synthesis, along with an index and log. This allows users to quickly bootstrap a wiki instance that follows the documented 'LLM Wiki' pattern.

packages/plugins/plugin-llm-wiki/fixtures · high confidence

LLM Wiki plugin introduces database schema and agent operating instructions

The LLM Wiki plugin now includes the necessary database migrations and template files to support its core functionality. The database layer (migrations) defines the schema for managing wiki instances, sources, pages, revisions, operations, and query sessions, along with a 'paperclip distillation' subsystem for tracking project-related data ingestion and processing. Additionally, the plugin provides the \AGENTS.md\ and \IDEA.md\ templates that define the operational schema for LLM agents, instructing them on how to maintain a persistent, interlinked knowledge base by ingesting raw sources, updating wiki pages, and managing project standups.

packages/plugins/plugin-llm-wiki/migrations, packages/plugins/plugin-llm-wiki/templates · high confidence

New ACP execution engine and authentication infrastructure for Claude Local adapter

The \claude-local\ adapter now includes a new ACP (Agent Client Protocol) execution engine alongside the existing CLI engine, allowing users to run Claude agents via the ACP runtime. This change introduces robust authentication handling, including a new \setup-token\ flow for OAuth login, environment probes to detect missing or invalid credentials, and specific error mapping for auth failures. It also adds quota management to classify provider limits and retry windows, and implements secure config seeding that sanitizes local-only settings for remote sandbox environments. Comprehensive test coverage and characterization fixtures validate the new login, quota, and config behaviors.

packages/adapters/claude-local/src/server · high confidence

New AI assistant skills for UI design and company management

Added new skill definitions to guide the AI assistant in consistent UI development and company creation workflows. The \design-guide\ skill provides a comprehensive reference for the Paperclip design system, including React 19/TypeScript/Vite tech stack details, OKLCH-based design tokens, typography scales, status/priority color systems, and a full inventory of shadcn/ui primitives and custom components (like EntityRow, StatusBadge, and Identity). The \company-creator\ skill and \paperclip\ symlink establish the structural context for generating and managing company-related UI elements.

.claude/skills · high confidence

New CLI authentication flow and context management

The CLI now supports a browser-based authentication flow for board access, introducing a new \board-auth.ts\ module that handles challenge creation, polling, and credential storage in a local JSON store. A new \context.ts\ module manages multi-profile configurations (supporting 'board' and 'agent' personas) with home-based defaults and ancestor-directory resolution. The HTTP client (\http.ts\) has been updated to include a \putRaw\ method for binary uploads and improved error handling with automatic token recovery on auth failures.

cli/src/client · high confidence

New CLI client command suite for access, adapters, agents, approvals, assets, auth, and company management

The CLI now includes a comprehensive set of new commands under \cli/src/commands/client/\ to manage core platform resources. Users can now inspect and manage access policies, invites, and join requests (\access\); install, update, and configure adapters (\adapter\); manage agent keys, skills, instructions, and sessions (\agent\); handle approval workflows (\approval\); upload and download company assets like images and logos (\asset\); authenticate via board or agent credentials (\auth\); and perform full company import/export, feedback trace management, and company profile operations (\company\). These commands provide programmatic access to the Paperclip API for automation and administration.

cli/src/commands/client · high confidence

New CLI commands for configuration, diagnostics, and release management

The CLI now includes several new commands to improve setup and maintenance: \paperclip configure\ allows interactive editing of config sections (database, LLM, server, etc.); \paperclip doctor\ runs a suite of health checks with optional repair; \paperclip channels\ displays current and available release channels (stable, beta, nightly, canary); \paperclip db:backup\ creates manual database backups with retention controls; \paperclip auth-bootstrap-ceo\ generates bootstrap CEO invites for authenticated deployments; \paperclip allowed-hostname\ manages allowed hostnames for private deployments; \paperclip env\ exports deployment environment variables; \paperclip env-lab\ manages SSH environment lab fixtures; and \paperclip heartbeat-run\ invokes agent heartbeats manually.

cli/src/commands · high confidence

New CLI tools for stream formatting and quota monitoring

The local Claude adapter now includes a new CLI module that formats Claude stream events for the terminal (coloring assistant text, tool calls, and errors) and provides a \quota-probe\ command to check usage limits via OAuth, CLI, or aggregated sources, outputting results in JSON or human-readable text.

packages/adapters/claude-local/src/cli · high confidence

New CLI utility modules for banner, networking, and path resolution

The CLI now includes a set of new utility modules in the utils directory to support core functionality. A new banner module displays the 'paperclip' ASCII art and updated tagline ('The app people use to manage AI agents for work') upon startup. Networking utilities have been added to check if a specific port is available and to construct local application and health-check URLs, handling host normalization (e.g., 0.0.0.0 to 127.0.0.1) and IPv6 formatting. Additionally, a path resolver utility helps locate runtime files by expanding home prefixes and searching through config, workspace, and current working directories.

cli/src/utils · high confidence

New MCP and ACP fixture servers for testing

Added a suite of deterministic fixture servers in \scripts/mcp-fixtures\ to support testing of MCP and ACP integrations. This includes a tool catalog (\catalog.mjs\) defining synthetic tools (echo, calculator, time, todo, KV, email, social, blog) with varying risk levels and transports (stdio/HTTP), alongside specific server implementations: \stdio-fixture.mjs\ and \http-fixture.mjs\ for standard MCP tool execution, \acp-echo-agent.mjs\ for basic ACP session handling, \acp-cwd-report-agent.mjs\ to verify working directory decoupling during host spawning, \acp-isolation-agent.mjs\ to test spawning and inspecting child stdio servers, and \acp-stop-agent.mjs\ to simulate task interruption, cancellation, and safe continuation.

scripts/mcp-fixtures · high confidence

New OpenClaw smoke test harness for webhook validation

A new Docker-based smoke test service has been added to the \docker/openclaw-smoke\ directory to validate OpenClaw webhook integrations. The service, built on Node 24 Alpine, exposes a configurable webhook endpoint (defaulting to \/webhook\) that accepts POST requests, enforces optional authentication headers, and stores received events in memory for inspection via \/events\ and \/health\ endpoints. This tool allows users to quickly verify that webhook payloads are correctly formatted and received by the system during integration testing.

docker/openclaw-smoke · high confidence

New PR Report skill for generating maintainer-grade review artifacts

A new 'pr-report' skill has been added to the agent's capabilities, enabling it to produce detailed, maintainer-grade reports on pull requests or code contributions. This skill guides the agent to perform deep architectural and behavioral reviews, distinguishing between product scope and implementation quality, and to generate polished output artifacts. Users can now request deep PR reviews, design explanations, or merge recommendations, with the agent capable of producing standalone HTML reports (using a provided starter template and style guide) or Markdown summaries that follow an editorial, high-contrast visual design.

.agents/skills/pr-report · high confidence

New Plugin UI SDK for consistent, host-integrated plugin interfaces

Plugin developers can now import from \@paperclipai/plugin-sdk/ui\ to build UIs that match the host's design system and communicate safely with the plugin worker. This SDK provides React component type declarations (MetricCard, DataTable, TimeseriesChart, MarkdownBlock, MarkdownEditor, ActionBar, and more) whose implementations are injected by the host, ensuring visual consistency without requiring plugins to bundle their own UI libraries. It also exposes bridge hooks—usePluginData, usePluginAction, useHostContext, useHostNavigation, useHostLocation, and usePluginStream—allowing plugins to fetch data, trigger actions, read host context, navigate within the app, observe URL changes, and subscribe to real-time events. A dedicated copyTextToClipboard helper ensures copy actions work in plain-HTTP deployments by routing through the host's HTTP-safe clipboard implementation. All UI-to-worker communication is mediated by the host bridge, preventing plugins from accessing host internals directly.

packages/plugins/sdk/src/ui · high confidence

New Workspace Changes tab for viewing Git diffs

A new "Workspace Changes" plugin adds a Changes tab to execution and project workspaces, allowing users to view Git diffs directly in the UI. The plugin computes diffs locally using the \@pierre/diffs\ library and exposes a React-based UI that supports staged, unstaged, head, and untracked views, with features like file sidebar filtering, copy-to-clipboard, and handling of binary/oversized files. It registers a \detailTab\ slot for \execution\_workspace\ and \project\_workspace\ entity types, backed by a worker that queries workspace metadata and applies path filters and output caps.

packages/plugins/plugin-workspace-diff · high confidence

New app-detail UI panels and tests for connection management and activity tracking

The app-detail page now includes dedicated UI sections and corresponding test suites for managing app connections and viewing activity. The ActivityPanel displays a timeline of tool calls and lifecycle events, distinguishing between real agent runs and user-initiated test runs. The AdvancedPanel provides controls for reconnecting credentials and a DangerZone for removing apps and revoking access. The IdentitiesSection manages user and agent grants, while the PermissionsPanel allows configuring which agents can use the connection and managing action permissions. Additionally, the SetupPanel handles configuration for specific apps like Google Sheets and PostHog, and the RailwayAccessPanel enables SSH key management for Railway container access.

ui/src/pages/apps/app-detail · high confidence

New artifact upload helper for Paperclip skill

A new shell script, \paperclip-upload-artifact.sh\, has been added to the Paperclip skill scripts. This tool allows users to upload generated files (such as videos, images, or documents) to the current Paperclip issue as attachments and create corresponding work products. It supports various options for customizing titles, summaries, content types, and output formats, and handles authentication and error retries automatically.

skills/paperclip/scripts · high confidence

New bundled skills for documentation, issue triage, agent coaching, and status summarization

The skills catalog now includes several new bundled capabilities: a doc-maintenance skill to detect and fix documentation drift against code changes; an issue-triage skill to automate inbox management and issue status updates; a reflection-coach skill to analyze agent execution records and propose evidence-backed instruction or skill improvements; a status-card-query skill to compile prose prompts into structured company-search queries and write summaries; a summarize-status skill to generate actionable, human-readable status summaries for projects and workspaces; a task-planning skill to break down issues into structured implementation plans with child tasks and blockers; and a paperclip-capsules skill with references for generating and validating agent capsule visuals and brand assets.

packages/skills-catalog · high confidence

New database maintenance scripts for session cleanup and bootstrap invites

Added two new CLI scripts to the database package: \clean-poisoned-claude-sessions.ts\ detects and helps resolve sessions where the Claude adapter's \previous\_message\_id\ was incorrectly set to a synthetic UUID (causing 400 errors on resume), and \create-auth-bootstrap-invite.ts\ generates a new bootstrap CEO invite token while revoking any existing active ones. These scripts provide operational tools for fixing stranded chat sessions and managing initial user access.

packages/db/scripts · high confidence

New database schema definitions for core platform entities

The database schema package now includes definitions for a wide range of new tables supporting core platform capabilities. This includes agent management (agents, memberships, API keys, config revisions, runtime state, task sessions, and wakeup requests), authentication and session handling (auth users, sessions, accounts, and adapter auth sessions), and operational controls (activity logs, approvals, budget policies and incidents, and announcements). It also introduces structured data models for business workflows such as cases (with events, documents, labels, and issue links), chat integrations (endpoints and channels), and asset storage. These schema files establish the underlying data structures for these features.

packages/db/src/schema · high confidence

New doctor checks validate configuration, dependencies, and runtime health

The CLI now includes a comprehensive set of pre-flight checks (accessible via the doctor command) that validate the environment before starting the server. These checks verify that the config file is valid, the database (PostgreSQL or embedded) is reachable and correctly configured, and that the required secrets (JWT, encryption keys, AWS credentials) are present and properly formatted. It also ensures the LLM API keys are functional, the server port is available, the log and storage directories are writable, and the Node.js runtime meets the minimum version. For managed installations, it verifies the integrity of the install store, shims, and PATH configuration, while also checking the status and health of background services.

cli/src/checks · high confidence

New exe.dev sandbox provider plugin

Operators can now install the \@paperclipai/plugin-exe-dev\ sandbox provider to provision and manage execution environments on exe.dev VMs. The plugin handles VM lifecycle (create, retain, delete) via the exe.dev HTTPS API and executes commands over direct SSH. Configuration is managed through Instance Settings -\> Environments, supporting API tokens, SSH key pasting or host identity files, and advanced options for VM sizing (CPU, memory, disk), custom setup scripts, and lease reuse. The default setup script installs Node 24 to ensure the Paperclip sandbox callback bridge runs correctly.

packages/plugins/sandbox-providers/exe-dev · high confidence

New garden-inbox skill for inbox cleanup

A new 'garden-inbox' skill has been added to scan a Paperclip user's Mine inbox, classify reversible archive candidates, request checkbox confirmation, and archive only accepted selections. The skill includes a bundled Node.js script (garden-inbox.mjs) and documentation (SKILL.md) that enforce a strict three-stage workflow: scan (read-only classification into buckets A–D), confirm (posting checkbox interactions on the driving issue), and apply (archiving only accepted options after user resolution). It handles safety constraints such as preserving declined candidates on reruns, respecting API row caps, and ensuring inbox archiving does not mutate underlying issues or workspaces.

.agents/skills/garden-inbox · high confidence

New isolated container environment for untrusted PR reviews

A new Docker-based setup is introduced in the docker/untrusted-review directory to enable reviewing untrusted pull requests in isolated containers. The Dockerfile provisions a Node 24 environment with essential CLI tools (git, gh, jq, ripgrep, etc.) and pre-installs AI coding assistants (Claude Code, Codex). It includes a helper script, review-checkout-pr, which automates cloning a repository and checking out a specific PR into a detached worktree, facilitating safe, isolated code review workflows.

docker/untrusted-review · high confidence

New least-privilege Tailscale HTTPS broker for managed branch runtimes

A new dedicated host service has been added to manage HTTPS-to-loopback listeners for managed branch runtimes, allowing the Paperclip app/agent to obtain automatic trusted HTTPS previews without being granted Tailscale operator authority. The broker runs as a separate system account, communicates via a Unix socket using Linux SO\_PEERCRED for strict identity verification, and enforces a deny-by-default policy that only permits same-number loopback bindings in a dedicated port range. It implements a reserve-then-expose workflow with short-lived, unguessable lease handles to prevent SSRF-style publication of unrelated services, and includes an operator-declared protected-port list to prevent accidental modification of critical routes like the primary :443 entry. The package includes the broker core logic, a systemd unit for deployment, and a native C addon for credential resolution.

packages/tailscale-https-broker · high confidence

New public evaluation history hub for Runner and Product E2E tests

A new script-based hub has been added to aggregate and display the latest results for two evaluation programs: Runner Evals (protocol correctness) and Product E2E Evals (end-to-end user workflows). The \build.py\ script fetches history data from CloudFront, validates the campaign structure and counts, and renders a static HTML page (\template.html\) that presents the most recent measurement date, pass/selected case counts, coverage status, and links to the full run history and the authoring guide. This provides a single, public-facing entry point for inspecting the current state of these tests.

scripts/evals-hub · high confidence

New runner-core binaries for conformance testing and provider simulation

The runner-core crate now ships with several new binary targets to support testing and development workflows. A conformance tracer binary is added to validate runner behavior against standard fixtures. Additionally, fake sidecar and harness binaries (fake-acpx-sidecar, fake-codex-app-server, fake-harness) are introduced to simulate external provider interactions and execute scripted test scenarios locally. The main daemon binary (paperclip-runnerd) is also included, providing the core execution engine with support for durable sessions and native provider backends.

packages/paperclip-runner/runner/crates/runner-core/src/bin · high confidence

New scaffolding tool for creating Paperclip plugins

A new CLI tool (\@paperclipai/create-paperclip-plugin\) is introduced to help developers quickly generate new Paperclip plugin projects. It scaffolds a complete starter structure including a typed manifest, worker entrypoint, example UI widget, and test files, supporting multiple templates (default, connector, workspace, environment) and categories. The tool provides a local development workflow with hot-reload capabilities and handles SDK dependency management for both internal workspace and external local development scenarios.

packages/plugins/create-paperclip-plugin · high confidence

New scripts for release automation, security validation, and testing

This change introduces a suite of new scripts in the \scripts/\ directory to support the release pipeline, improve security, and enhance testing. It adds \bootstrap-npm-package.mjs\ to create placeholder npm packages for trusted publishing, \build-npm.sh\ to bundle the CLI, and \build-standalone-public-packages.mjs\ to build isolated public packages. Security is strengthened with \app-brand-validation.mjs\ to validate SVG/PNG assets and \assert-cloud-image-sentry.mjs\ to verify container integrity. Operational reliability is improved with \assert-orphan-reaping.sh\ to prevent zombie processes in containers, \backup-db.sh\ for database backups, and \backfill-issue-reference-mentions.ts\ for data maintenance. Additionally, new test files like \acpx-patch-packaging.test.mjs\ and \app-brand-validation.test.mjs\ ensure the correctness of these new capabilities.

scripts · high confidence

New smoke-test harnesses for Hermes gateway, Notion integration, and chat webhook ingress

Added a suite of new smoke-test scripts in the \scripts/smoke\ directory to validate critical integration points. The \hermes-gateway-e2e.sh\ and \hermes-gateway-join.sh\ scripts automate the end-to-end lifecycle of the Hermes gateway, including Docker container provisioning, Paperclip adapter joining, and agent execution, with built-in redaction of API keys and secrets. The \notion-generic-live.mjs\ and \notion-generic-live-lib.mjs\ scripts provide a live smoke test for the Notion integration, handling OAuth flows, email verification code extraction, and browser-based UI interactions. Additionally, \chat-webhook-ingress.mjs\ introduces a diagnostic tool to verify Slack webhook signature validation and network reachability, while \mcp-fixture-harness.mjs\ supplies local fixture servers for testing Model Context Protocol tool integrations. Corresponding test files (\\*.test.mjs\) validate the logic, argument parsing, and security redaction of these new scripts.

scripts/smoke · high confidence

New validation schemas for access, adapters, and assets

The shared validators package now includes comprehensive Zod schemas for managing user access, adapter configurations, and asset namespaces. User profile and session parsing now coerces empty or whitespace-only names and emails to null, preventing invalid data from reaching downstream systems. Adapter registry entries are validated with strict typing for runtime images and environment keys, while asset namespaces now support identity-provider characters (such as \:\ and \\|\) and include a sanitizer to safely handle special characters and path traversal attempts.

packages/shared/src/validators · high confidence

OpenClaw Gateway adapter server-side execution and testing logic

The OpenClaw Gateway adapter now includes the core server-side execution logic and its test suite. This adds the \execute\ function that manages WebSocket connections to the gateway, handles session key resolution (supporting run, issue, and fixed strategies), and constructs agent wake payloads while stripping root-level paperclip parameters. It also introduces environment testing capabilities via \testEnvironment\ to probe gateway connectivity and authentication, along with comprehensive unit tests for session key routing, parameter building, and dispatch boundary behavior.

packages/adapters/openclaw-gateway/src/server · high confidence

Paperclip core skill beta release added

A new beta release for the core Paperclip skill is now available in the skills-releases directory. This release includes the v0 snapshot of the skill's documentation, API reference, and helper scripts, along with a v7-roster historical release. Users can now access the Paperclip skill's core functionality and documentation through this new beta release.

skills-releases · high confidence

Postgres adapter for run-dispatch module

Added a new Postgres adapter implementation for the run-dispatch module, providing the database persistence layer for managing agent run scheduling, retries, and execution state. This includes the core adapter logic in \postgres.ts\ and comprehensive integration tests in \postgres.test.ts\ that verify correct mapping between database rows and dispatch policy facts.

server/src/modules/run-dispatch/adapters · high confidence

Published architecture and implementation plans for native chat adapters

This change adds the foundational design documentation for the native chat-adapters subsystem, detailing how Paperclip agents will integrate with external platforms like Slack, Microsoft Teams, Discord, Telegram, and GitHub. The files define the core architecture, including a registry-driven adapter model, a 'one bot per agent' identity strategy, and specific persistence schemas for endpoints, conversations, and deliveries. The package also includes research notes on leveraging the Vercel Chat SDK and OpenTag patterns, a comprehensive UI surface specification for the connection wizard and endpoint management tabs, and a live browser E2E runbook to qualify the adapters against real provider APIs.

doc/plans/chat-adapters · high confidence

Security

Harden plugin installation security on managed instances

The server now enforces stricter security controls when installing plugins. It canonicalizes the \localPath\ for all instances to prevent path traversal, and on managed instances, plugin installation is restricted to bundled plugins only, preventing tenants from installing arbitrary code.

server/src · high confidence

Behavioural changes

ACP engine CLI output formatting and session resume behavior

The ACP engine now provides structured, color-coded CLI output for streaming events (sessions, text, tool calls, results, errors) via the new \printAcpxStreamEvent\ utility, and enforces safe session continuation when an operator stops a run: the engine verifies the ACP process can be stopped and preserves the session state to allow a follow-up run to resume from the interrupted checkpoint rather than starting fresh.

packages/adapter-utils/src/acpx-engine · high confidence

Codex local adapter model metadata, reasoning efforts, and fast mode support

The codex-local adapter now explicitly advertises current Codex-capable OpenAI models (including gpt-6-astra, gpt-6-sol, gpt-6-luna, gpt-5.6-sol, gpt-5.6-terra, gpt-5.6-luna, gpt-5.4, gpt-5.4-mini, gpt-5, o3, o4-mini, gpt-5-mini, gpt-5-nano, o3-mini, and codex-mini-latest) with the default set to gpt-5.6-sol. It introduces reasoning effort controls (low, medium, high, xhigh, max, ultra) tailored to specific models, supports Fast mode for GPT-6 and GPT-5.6 families, and normalizes legacy model aliases like gpt-5.6 to gpt-5.6-sol to prevent CLI warnings.

packages/adapters/codex-local/src · high confidence

Default model set to Claude Opus 5 with expanded reasoning controls and new model support

The local Claude adapter now defaults to the Claude Opus 5 model when no model is explicitly configured, while preserving any explicit model IDs or environment overrides. The adapter introduces granular reasoning effort controls (low, medium, high, xhigh, max) tailored to specific models, with Opus 5, Sonnet 5, and Fable 5.1 supporting the full range. The model selector has been updated to include Claude Opus 5.5, Opus 4.8, Opus 4.7, Opus 4.6, Sonnet 5, Sonnet 4.6, Sonnet 4.5, Fable 5.1, Fable 5, Mythos 5, and Haiku 4.5. Additionally, the adapter now supports ACP as the default engine, with specific configuration options for ACP session modes and state directories, and enforces Node 24+ for ACP runs.

packages/adapters/claude-local/src · high confidence

Design specs for monitor visibility across issue surfaces

Added a new design specification in the \design/pap-14557-monitor-visibility\ directory that defines how monitor status is displayed across task surfaces. The wireframes detail a consistent monitor banner on the issue page top, a monitor strip above the composer, and a redesigned row in the properties pane, all sharing a unified state matrix and copy rules for relative and absolute time formatting.

design · high confidence

Expanded Docker deployment options and hardened process management

The Docker configuration has been reorganized into the \docker/\ directory and expanded to support multiple deployment targets, including AWS ECS Fargate (with a new task definition and environment example), systemd/quadlet integration, and a dedicated smoke-test container. The main server image now enforces Node 24 and uses \tini\ as PID 1 to ensure orphaned agent processes are reaped, with a \pids\_limit\ of 2048 as a safety backstop. Additionally, the quickstart and review environments now explicitly pass \PAPERCLIP\_ALLOWED\_HOSTNAMES\ and other deployment settings, and the main compose file enforces database health checks before starting the server.

docker · high confidence

Gemini Local adapter now defaults to the ACP execution engine

The Gemini Local adapter has shifted its default execution engine from the legacy CLI mode to the ACP (Agent Control Protocol) engine. This change introduces a new configuration option allowing users to explicitly select between 'ACP' and 'CLI' modes, with ACP enabled by default. The ACP engine brings support for persistent sessions, configurable permission modes, and remote execution via SSH and sandboxed environments. To ensure compatibility, the adapter now enforces a minimum Node.js version (24.11.0) for ACP runs and provides clear diagnostic feedback if the engine is unavailable, rather than silently falling back or failing.

packages/adapters/gemini-local/src/server · high confidence

Introduce Hermes adapter compatibility shim and task bridge skill

The \@paperclipai/adapter-hermes-gateway\ package is now a deprecated compatibility shim that forwards exports to the unified \@paperclipai/hermes-paperclip-adapter\, allowing existing plugin installs to continue working during a migration window. Additionally, a new \paperclip-task-bridge\ skill has been added to Hermes, enabling agents to create, update, and list Paperclip tasks using scoped API credentials, supported by new publish/restore scripts to manage workspace dependency resolution.

packages/adapters/hermes-gateway, packages/adapters/hermes/scripts, packages/adapters/hermes/skills · high confidence

Introduce sandboxed agent-runtime Docker images with Node 24 base

The docker/agent-runtime directory now provides a family of container images designed for running coding-agent harnesses in sandboxed environments. A new base image (agent-runtime-base) establishes the runtime foundation using Ubuntu 22.04, Node.js 24, and the paperclip-agent-shim, while also including ripgrep to prevent runtime dependency downloads. Derived images for specific agents—Claude, Codex, Gemini, OpenCode, Pi, and a stub for Hermes—extend this base by installing their respective CLI tools and configuring necessary settings (such as headless authentication for Gemini). This change shifts the execution model to use these dedicated, non-root images for sandboxed agent runs.

docker/agent-runtime · high confidence

New shared validation and eligibility logic for agents and account handles

The shared package introduces new TypeScript modules and tests that enforce stricter validation and eligibility rules for agents and account handles. \account-handle.ts\ and its tests define a \toAccountHandle\ function that rejects identifiers containing whitespace, special characters, or shell metacharacters, ensuring safe directory and secret naming. \agent-eligibility.ts\ and its tests implement org-chain health checks, blocking work assignment and invocation for agents with terminated ancestors, missing managers, or reporting cycles, while warning about paused managers. Additionally, \agent-appearance.ts\ standardizes agent avatar palettes and states, and \adapter-auth-check-code.ts\ provides a stable constant for adapter authentication status checks.

packages/shared/src · high confidence

Standardized CLI adapter registry with HTTP and process fallbacks

The CLI now uses a centralized adapter registry to manage output formatting for various AI providers. This change introduces two new generic adapter types, \http\ and \process\, which handle standard output events by printing trimmed lines to the console. These serve as the default fallback behavior when a specific provider adapter is not found or selected. The registry also consolidates the existing provider-specific adapters (including Claude, Codex, Cursor, Gemini, Grok, Kimi, Hermes, OpenCode, Pi, and OpenClaw) into a single lookup mechanism, ensuring consistent event handling across all supported integrations.

cli/src/adapters · high confidence

Fixes

Enhanced isolation, reliability, and fidelity across chat adapters and agent runtimes

This update introduces several targeted fixes and capability improvements across the platform's integration layers. In the Discord adapter, new configuration options allow for granular control over thread creation and gateway event monitoring, while the Teams adapter now provides detailed permission error reporting and simplified thread ID encoding. The Slack adapter improves file upload reliability by confirming message identity and handles file edits more accurately, and the Telegram adapter adds durable draft control for streaming and configurable download limits. On the agent runtime side, the Claude ACP patch enforces strict context isolation in sandboxed environments and exposes granular token usage metadata, while the Codex ACP patch upgrades the underlying SDK and applies similar isolation policies. Finally, the Discord.js WebSocket library is patched to prevent race conditions during connection teardown, and the ACPX runtime now supports environment variable inheritance for spawned agents.

patches · high confidence

Improved build reliability and developer experience

The server build process now includes a verification script that ensures all runtime dependencies of the vendored paperclip-runner are correctly mirrored in the server's package.json, preventing production crashes caused by missing modules. Additionally, a new build-stamp script embeds the actual commit SHA into the service version, allowing for accurate identification of the running release. For developers, the local dev-watch script has been updated to use a stable entry point for tsx and includes improved exclusions for nested UI outputs, while worktree runtime isolation recovery has been hardened.

server/scripts · high confidence

Introduce built-in Hermes adapters with improved UI parsing

This change adds the \hermes\_local\ and \hermes\_gateway\ adapters as built-in components within the \packages/adapters/hermes\ package. The new UI parsers (\ui-parser.cjs\ and \gateway-ui-parser.cjs\) now strip ANSI escape codes from terminal output to ensure clean rendering in the Paperclip interface. Additionally, the gateway parser has been updated to correctly surface real reasoning text from \reasoning.available\ events, allowing users to see the agent's thought process rather than generic placeholders.

packages/adapters/hermes · high confidence

Test coverage

Added PostgreSQL connection recovery test fixtures; Added comprehensive test coverage for ACPX provider session lifecycle and event handling; Added test coverage for lifecycle heartbeat observation; Added test helpers for embedded Postgres and ZIP archive creation; Added tests for Plugin SDK environment lifecycle, sync negotiation, and host client security; Added tests for build, CI sharding, and release verification scripts; Added tests for chat webhook proxy diagnostics and native Codex provider startup; Comprehensive test coverage for database migrations and schema integrity; Expanded CLI test coverage for parity, configuration, and lifecycle commands; Initial test suite for the LLM Wiki plugin; New Playwright test suites for AI connections, agent chat, and canary onboarding.

Dependencies

Introduce Paperclip CLI and standardize adapter packages on Node 24

This change introduces the new \paperclipai\ CLI package (\cli/package.json\) to orchestrate AI agent teams, bundling local adapters for Claude, Codex, Cursor, Gemini, Grok, Kimi, OpenCode, and Pi, along with the Hermes gateway adapter. It also standardizes the entire adapter suite (\packages/adapters/\*\) and core infrastructure packages (\packages/db\, \packages/mcp-server\, etc.) to require Node.js \>=24.11.0, upgrading \@types/node\ to v24 and TypeScript to v7.0.2, while aligning key dependencies such as \drizzle-orm\ (0.45.2), \commander\ (15.0.0), and \embedded-postgres\ (18.1.0-beta.16).

(dependencies) · high confidence

Upgrade lucide-react to v1.32.0

The lucide-react icon library has been upgraded from version 0.577.0 to 1.32.0. This update brings the latest icon set and component improvements to the application's UI.

ui · high confidence

Housekeeping

Release changelog documentation for v0.2.7 through v2026.416.0

The \releases/\ directory now contains structured markdown changelogs for versions v0.2.7, v0.3.0, v0.3.1, v2026.318.0, v2026.325.0, v2026.403.0, v2026.414.0, v2026.415.0, and v2026.416.0. These documents provide users with a consolidated view of new features (such as multi-user invites, execution policies, and plugin systems), behavioral improvements, and fixes included in each release, along with any necessary database migration steps.

releases · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 46 → 51 (+5.1)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 71 → 55 (-15.8)
  • Architecture 51 (new)
  • Maturity 85 → 73 (-12.3)
  • Readiness 29 → 45 (+16.8)
  • Security 52 → 69 (+17.6)
  • Event Sourcing 100 (new)
  • Accessibility 59 (new)
  • Performance 60 (new)

Resolved (182)

  • ADR lacks an enforcement field (doc/logs/2026-05-24-cli-api-parity-e2e-log.md)
  • ADR lacks an enforcement field (doc/plans/2026-02-16-module-system.md)
  • ADR lacks an enforcement field (doc/plans/2026-02-18-agent-authentication-implementation.md)
  • ADR lacks an enforcement field (doc/plans/2026-02-18-agent-authentication.md)
  • ADR lacks an enforcement field (doc/plans/2026-02-19-agent-mgmt-followup-plan.md)
  • ADR lacks an enforcement field (doc/plans/2026-02-19-ceo-agent-creation-and-hiring.md)
  • ADR lacks an enforcement field (doc/plans/2026-02-20-issue-run-orchestration-plan.md)
  • ADR lacks an enforcement field (doc/plans/2026-02-20-storage-system-implementation.md)
  • ADR lacks an enforcement field (doc/plans/2026-02-21-humans-and-permissions-implementation.md)
  • ADR lacks an enforcement field (doc/plans/2026-02-21-humans-and-permissions.md)
  • ADR lacks an enforcement field (doc/plans/2026-02-23-cursor-cloud-adapter.md)
  • ADR lacks an enforcement field (doc/plans/2026-02-23-deployment-auth-mode-consolidation.md)
  • ADR lacks an enforcement field (doc/plans/2026-03-10-workspace-strategy-and-git-worktrees.md)
  • ADR lacks an enforcement field (doc/plans/2026-03-11-agent-chat-ui-and-issue-backed-conversations.md)
  • ADR lacks an enforcement field (doc/plans/2026-03-13-TOKEN-OPTIMIZATION-PLAN.md)
  • ADR lacks an enforcement field (doc/plans/2026-03-13-agent-evals-framework.md)
  • ADR lacks an enforcement field (doc/plans/2026-03-13-company-import-export-v2.md)
  • ADR lacks an enforcement field (doc/plans/2026-03-13-features.md)
  • ADR lacks an enforcement field (doc/plans/2026-03-13-paperclip-skill-tightening-plan.md)
  • ADR lacks an enforcement field (doc/plans/2026-03-13-plugin-kitchen-sink-example.md)
  • …and 162 more

New (5917)

  • (anonymous) (cognitive 31) (ui/public/sw.js)
  • (anonymous) (cyclomatic 24) (ui/public/sw.js)
  • 2026-05-23-cli-api-parity-openapi-reference.applyDocumentFixups (cognitive 21) (doc/plans/2026-05-23-cli-api-parity-openapi-reference.ts)
  • AccessEditor.AccessEditor (cognitive 23) (ui/storybook/prototypes/github-chat/AccessEditor.tsx)
  • AccessEditor.AccessEditor (cyclomatic 22) (ui/storybook/prototypes/github-chat/AccessEditor.tsx)
  • AcpxCommandExecutor::execute (cyclomatic 21) (packages/paperclip-runner/runner/crates/runner-core/src/acpx_provider_backend.rs)
  • AcpxCommandExecutor::poll_provider (cognitive 43) (packages/paperclip-runner/runner/crates/runner-core/src/acpx_provider_backend.rs)
  • AcpxCommandExecutor::poll_provider (cyclomatic 18) (packages/paperclip-runner/runner/crates/runner-core/src/acpx_provider_backend.rs)
  • AcpxProviderDescriptor::validate_session (cyclomatic 16) (packages/paperclip-runner/runner/crates/runner-core/src/acpx_provider_backend.rs)
  • AcpxProviderSession::poll_event (cognitive 67) (packages/paperclip-runner/runner/crates/runner-core/src/acpx_provider_session.rs)
  • AcpxProviderSession::poll_event (cyclomatic 27) (packages/paperclip-runner/runner/crates/runner-core/src/acpx_provider_session.rs)
  • AcpxProviderSession::start_turn (cognitive 20) (packages/paperclip-runner/runner/crates/runner-core/src/acpx_provider_session.rs)
  • AcpxProviderSession::start_turn (cyclomatic 16) (packages/paperclip-runner/runner/crates/runner-core/src/acpx_provider_session.rs)
  • AcpxProviderSessionConfig::validate (cognitive 18) (packages/paperclip-runner/runner/crates/runner-core/src/acpx_provider_session.rs)
  • AcpxProviderSessionConfig::validate (cyclomatic 18) (packages/paperclip-runner/runner/crates/runner-core/src/acpx_provider_session.rs)
  • AcpxProviderState::accept_event (cognitive 17) (packages/paperclip-runner/runner/crates/runner-core/src/acpx_provider_state.rs)
  • AcpxProviderState::accept_event (cyclomatic 17) (packages/paperclip-runner/runner/crates/runner-core/src/acpx_provider_state.rs)
  • AcpxProviderState::accept_runtime_event (cognitive 16) (packages/paperclip-runner/runner/crates/runner-core/src/acpx_provider_state.rs)
  • AcpxRuntimeHost.open (cognitive 29) (packages/paperclip-runner/src/drivers/acpx/runtime-host.ts)
  • AcpxRuntimeHost.open (cyclomatic 29) (packages/paperclip-runner/src/drivers/acpx/runtime-host.ts)
  • …and 5897 more

Changes since last survey

  • 300 commits — 119 feature/other, 181 fixes

By area

  • server/src — 104 commits
  • ui/src — 64 commits
  • tests/runner-e2e — 19 commits
  • packages/paperclip-runner — 18 commits
  • .github/workflows — 13 commits
  • packages/adapter-utils — 12 commits
  • .github/scripts — 11 commits
  • (root) — 10 commits
  • packages/adapters — 10 commits
  • packages/shared — 6 commits
  • packages/db — 4 commits
  • packages/plugins — 4 commits
  • releases/beta — 4 commits
  • .agents/skills — 1 commit
  • .devin/wiki.json — 1 commit
  • .github/cloud-migrator-deploy — 1 commit
  • .github/dependabot.yml — 1 commit
  • cli/src — 1 commit
  • doc/DEVELOPING.md — 1 commit
  • doc/PUBLISHING.md — 1 commit

Notable commits

  • fix: Fix Codex API key authentication in tests and runs (#13260)
  • fix: Fix PostgreSQL recovery after a transaction connection closes (#13643)
  • fix: Fix default isolation for projects without workspace configuration (#13636)
  • fix: Fix oversized sandbox process launch payloads (#13793)
  • fix: Fix relative symlinks in secondary sandbox repositories (#13953)
  • fix: Fix workspace-ready notice rendering (#12716)
  • fix: fix(adapter-utils): stage selected skills into the sandbox for a remote Claude ACP run (#13196)
  • fix: fix(adapters): default legacy harnesses and connected tools to full auto (#13693)
  • fix: fix(apps): configure MCP aggregators from inline task cards (#13879)
  • fix: fix(apps): recover MCP OAuth setup after consent errors (#13855)
  • fix: fix(apps): reduce Google Chat scopes and block unread filters (#13820)
  • fix: fix(apps): restore action test picker scrolling and agent eligibility (#13414)
  • fix: fix(apps): temporarily hide Google connectors (#13551)
  • fix: fix(apps): update connector artwork and theme fallback (#13361)
  • fix: fix(chat): use the claimed Cloud origin for connector URLs (#13680)
  • fix: fix(ci): avoid empty pnpm caches from lockfile refresh (#13267)
  • fix: fix(ci): bake the managed runtime identity into cloud images (#13210)
  • fix: fix(ci): isolate chaos verification by caller workflow (#13208)
  • fix: fix(ci): make the Runner Rust cache key independent of the image toolchain (#13500)
  • fix: fix(ci): overlap preview migrator publication waits (#13454)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

paperclipai/paperclip was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0f14d261233c545aa6a8a38ec253c498a5130fff — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-eb9197011364.