2026-02-16 13:31:58 -06:00
|
|
|
{
|
2026-03-03 08:45:26 -06:00
|
|
|
"name": "@paperclipai/server",
|
2026-03-12 13:09:22 -05:00
|
|
|
"version": "0.3.1",
|
2026-03-17 15:49:42 -05:00
|
|
|
"license": "MIT",
|
|
|
|
|
"homepage": "https://github.com/paperclipai/paperclip",
|
|
|
|
|
"bugs": {
|
|
|
|
|
"url": "https://github.com/paperclipai/paperclip/issues"
|
|
|
|
|
},
|
|
|
|
|
"repository": {
|
|
|
|
|
"type": "git",
|
|
|
|
|
"url": "https://github.com/paperclipai/paperclip",
|
|
|
|
|
"directory": "server"
|
|
|
|
|
},
|
2026-02-16 13:31:58 -06:00
|
|
|
"type": "module",
|
2026-03-03 14:46:16 -06:00
|
|
|
"exports": {
|
|
|
|
|
".": "./src/index.ts"
|
|
|
|
|
},
|
|
|
|
|
"publishConfig": {
|
|
|
|
|
"access": "public",
|
|
|
|
|
"exports": {
|
|
|
|
|
".": {
|
|
|
|
|
"types": "./dist/index.d.ts",
|
|
|
|
|
"import": "./dist/index.js"
|
|
|
|
|
}
|
|
|
|
|
},
|
|
|
|
|
"main": "./dist/index.js",
|
|
|
|
|
"types": "./dist/index.d.ts"
|
|
|
|
|
},
|
|
|
|
|
"files": [
|
2026-03-03 15:45:45 -06:00
|
|
|
"dist",
|
2026-03-03 16:06:12 -06:00
|
|
|
"ui-dist",
|
|
|
|
|
"skills"
|
2026-03-03 14:46:16 -06:00
|
|
|
],
|
2026-02-16 13:31:58 -06:00
|
|
|
"scripts": {
|
2026-04-09 08:35:41 -05:00
|
|
|
"dev": "tsx src/index.ts",
|
|
|
|
|
"dev:watch": "cross-env PAPERCLIP_MIGRATION_PROMPT=never PAPERCLIP_MIGRATION_AUTO_APPLY=true tsx ./scripts/dev-watch.ts",
|
2026-03-09 07:21:33 -05:00
|
|
|
"prepare:ui-dist": "bash ../scripts/prepare-server-ui-dist.sh",
|
2026-04-09 08:35:41 -05:00
|
|
|
"build": "tsc && mkdir -p dist/onboarding-assets && cp -R src/onboarding-assets/. dist/onboarding-assets/",
|
2026-03-09 07:21:33 -05:00
|
|
|
"prepack": "pnpm run prepare:ui-dist",
|
|
|
|
|
"postpack": "rm -rf ui-dist",
|
2026-03-03 14:46:16 -06:00
|
|
|
"clean": "rm -rf dist",
|
2026-02-16 13:31:58 -06:00
|
|
|
"start": "node dist/index.js",
|
test: isolate CLI company import e2e state (#4560)
## Thinking Path
> - Paperclip orchestrates AI agents for zero-human companies, and its
CLI import/export path is part of how operators move company state
safely between environments.
> - The `paperclipai company import/export` e2e test is supposed to
validate that portability flow inside a hermetic harness, not against a
developer's live Paperclip home.
> - This regression showed nested CLI subprocesses could silently fall
back to ambient `PAPERCLIP_*` state and mutate a real local instance by
creating extra companies such as `CLI-1-Roundtrip-Test`.
> - The first job was to pin the test subprocesses to isolated config,
home, instance, auth, and context paths, and to add a regression
assertion that proves the nested CLI writes stay inside the test-owned
state.
> - Once the PR was up, CI and Greptile exposed two follow-on issues
that were blocking merge: plugin SDK typecheck bootstrap was racing
across packages in fresh CI, and the new lock helper needed one more fix
to release its lock on failure.
> - This pull request therefore ends up doing two tightly related
things: fixing the original CLI isolation leak, and hardening the
supporting typecheck/bootstrap path enough for the fix to verify cleanly
in CI.
> - The benefit is that the portability e2e test is now actually
isolated, and the PR verification path is stable enough to catch
regressions instead of introducing its own nondeterministic failures.
## What Changed
- Hardened `cli/src/__tests__/company-import-export-e2e.test.ts` so
nested CLI subprocesses re-seed isolated `PAPERCLIP_CONFIG`,
`PAPERCLIP_HOME`, `PAPERCLIP_INSTANCE_ID`, `PAPERCLIP_CONTEXT`,
`PAPERCLIP_AUTH_STORE`, and throwaway `HOME` values instead of falling
back to ambient machine state.
- Added a regression assertion around `paperclipai context set --json`,
then cleared the temporary `context.json` so the isolation check and the
later export/import flow stay independent.
- Passed the same isolated `HOME` into the server subprocess so both
sides of the e2e harness are symmetric.
- Introduced locking in `scripts/ensure-plugin-build-deps.mjs` and
switched the server/plugin example `typecheck` scripts to use that
helper instead of launching concurrent raw `@paperclipai/plugin-sdk`
builds.
- Fixed the helper failure path so it releases the lock before exiting
non-zero, which prevents stale-lock timeouts during parallel typecheck
runs.
## Verification
- `pnpm vitest run cli/src/__tests__/company-import-export-e2e.test.ts
--project paperclipai`
- `pnpm --filter paperclipai typecheck`
- `pnpm -r typecheck`
- PR checks now pass on the current head, including `policy`, `verify`,
`e2e`, `security/snyk`, and `Greptile Review`.
## Risks
- Low risk. The product-facing behavior change is scoped to test harness
code in the CLI e2e suite.
- The CI stabilization changes only affect bootstrap/typecheck helper
paths for the server and plugin/example packages, but they do touch
shared verification plumbing; the main risk is changing how fresh build
artifacts are prepared in local/CI typecheck runs.
## Model Used
- Anthropic Claude via Paperclip `claude_local`, model
`claude-opus-4-7`, high-effort local coding agent, used for the initial
implementation and first peer-reviewed verification.
- OpenAI Codex via Paperclip `codex_local`, model `gpt-5.4`, high
reasoning-effort local coding agent with tool use, used for CI triage,
Greptile follow-up fixes, verification, and PR maintenance.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] If this change affects the UI, I have included before/after
screenshots
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] I will address all Greptile and reviewer comments before
requesting merge
2026-04-26 19:10:01 -07:00
|
|
|
"typecheck": "pnpm --filter @paperclipai/plugin-sdk ensure-build-deps && tsc --noEmit"
|
2026-02-16 13:31:58 -06:00
|
|
|
},
|
|
|
|
|
"dependencies": {
|
2026-03-03 11:22:18 -06:00
|
|
|
"@aws-sdk/client-s3": "^3.888.0",
|
Add ACPX local adapter runtime (#4893)
## Thinking Path
> - Paperclip orchestrates AI-agent companies through a control plane
that can start, supervise, and recover agent runs.
> - Local adapters are the bridge between Paperclip issues and concrete
agent runtimes such as Claude, Codex, and other ACP-compatible tools.
> - The roadmap calls out broader “bring your own agent” and claw-style
agent support, and ACPX gives Paperclip one path to normalize multiple
ACP agents behind a single adapter.
> - The branch needed to become one reviewable PR against current
`paperclipai/paperclip:master`, without carrying stale base conflicts or
generated lockfile churn.
> - This pull request adds an experimental built-in `acpx_local`
adapter, integrates it through the server/CLI/UI adapter surfaces, and
adds regression coverage for runtime execution, skill sync, stream
parsing, diagnostics, and log redaction.
> - The benefit is that Paperclip can run Claude/Codex/custom ACP agents
through ACPX while keeping operator configuration, skills, logging, and
transcript rendering inside the existing adapter model.
## What Changed
- Added `@paperclipai/adapter-acpx-local` with server execution, config
schema, ACPX session handling, CLI formatting, UI config helpers, and
stdout parsing.
- Registered `acpx_local` across CLI, server, shared constants, UI
adapter metadata, adapter capabilities, and agent creation/editing
surfaces.
- Added ACPX runtime execution support with persistent sessions,
local-agent JWT environment handling, skill snapshots, runtime skill
materialization, and isolation/security regressions.
- Added ACPX adapter diagnostics and marked the adapter experimental in
the UI.
- Added command/env secret redaction for resolved command metadata in
adapter-utils, server event storage, and the Agent Detail invocation UI.
- Added Storybook coverage for ACPX config, transcript rendering, and
skill states, plus PR screenshots under `docs/pr-screenshots/pap-2944/`.
- Rebased the branch onto current `public-gh/master`; `pnpm-lock.yaml`
is intentionally not included and there are no migration/schema changes.
## Verification
- `pnpm exec vitest run
packages/adapters/acpx-local/src/server/execute.test.ts
packages/adapters/acpx-local/src/server/test.test.ts
packages/adapters/acpx-local/src/cli/format-event.test.ts
packages/adapters/acpx-local/src/ui/parse-stdout.test.ts
packages/adapter-utils/src/server-utils.test.ts
server/src/__tests__/redaction.test.ts
server/src/__tests__/acpx-local-execute.test.ts
server/src/__tests__/acpx-local-skill-sync.test.ts
server/src/__tests__/acpx-local-adapter-environment.test.ts
server/src/__tests__/adapter-routes.test.ts
server/src/__tests__/agent-skills-routes.test.ts
ui/src/adapters/metadata.test.ts` — 12 files, 87 tests passed.
- `pnpm --filter @paperclipai/adapter-acpx-local typecheck` — passed.
- `pnpm --filter @paperclipai/server typecheck` — passed.
- `pnpm --filter @paperclipai/ui typecheck` — passed.
- Confirmed PR diff does not include `pnpm-lock.yaml`, database schema
files, or migrations.
Screenshots:



## Risks
- Medium risk: this introduces a new built-in adapter package and
touches runtime execution, adapter registration, agent config, skills,
and transcript rendering.
- ACPX and ACP agent behavior can vary by installed tool versions; the
adapter is marked experimental to set operator expectations.
- `pnpm-lock.yaml` is excluded per repository PR policy, so dependency
lock refresh must be handled by the repo’s automation or maintainers.
- No database migration risk: no schema or migration files changed.
> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.
## Model Used
- OpenAI Codex coding agent based on GPT-5, with repository tool use,
shell execution, git operations, and local verification. Exact hosted
context window was not exposed in this environment.
## Checklist
- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] If this change affects the UI, I have included before/after
screenshots
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] I will address all Greptile and reviewer comments before
requesting merge
---------
Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-04-30 19:57:05 -05:00
|
|
|
"@paperclipai/adapter-acpx-local": "workspace:*",
|
2026-03-03 08:45:26 -06:00
|
|
|
"@paperclipai/adapter-claude-local": "workspace:*",
|
|
|
|
|
"@paperclipai/adapter-codex-local": "workspace:*",
|
2026-03-05 06:31:22 -06:00
|
|
|
"@paperclipai/adapter-cursor-local": "workspace:*",
|
2026-03-08 16:43:34 +05:30
|
|
|
"@paperclipai/adapter-gemini-local": "workspace:*",
|
2026-03-07 12:37:15 -05:00
|
|
|
"@paperclipai/adapter-openclaw-gateway": "workspace:*",
|
2026-03-04 16:48:54 -06:00
|
|
|
"@paperclipai/adapter-opencode-local": "workspace:*",
|
2026-03-06 18:29:38 -08:00
|
|
|
"@paperclipai/adapter-pi-local": "workspace:*",
|
2026-03-03 08:45:26 -06:00
|
|
|
"@paperclipai/adapter-utils": "workspace:*",
|
|
|
|
|
"@paperclipai/db": "workspace:*",
|
2026-03-13 16:22:34 -05:00
|
|
|
"@paperclipai/plugin-sdk": "workspace:*",
|
2026-03-03 08:45:26 -06:00
|
|
|
"@paperclipai/shared": "workspace:*",
|
2026-03-13 16:22:34 -05:00
|
|
|
"ajv": "^8.18.0",
|
|
|
|
|
"ajv-formats": "^3.0.1",
|
2026-03-04 10:02:23 -06:00
|
|
|
"better-auth": "1.4.18",
|
2026-03-14 12:07:04 -05:00
|
|
|
"chokidar": "^4.0.3",
|
2026-02-18 11:45:43 -06:00
|
|
|
"detect-port": "^2.1.0",
|
2026-03-06 17:18:43 -05:00
|
|
|
"dompurify": "^3.3.2",
|
2026-02-19 09:09:40 -06:00
|
|
|
"dotenv": "^17.0.1",
|
2026-05-09 21:31:57 -07:00
|
|
|
"drizzle-orm": "^0.45.2",
|
2026-03-04 14:46:03 -06:00
|
|
|
"embedded-postgres": "^18.1.0-beta.16",
|
2026-02-16 13:31:58 -06:00
|
|
|
"express": "^5.1.0",
|
2026-03-28 01:34:48 +01:00
|
|
|
"hermes-paperclip-adapter": "^0.2.0",
|
2026-03-06 17:18:43 -05:00
|
|
|
"jsdom": "^28.1.0",
|
2026-04-04 23:15:04 -07:00
|
|
|
"multer": "^2.1.1",
|
2026-03-03 11:22:18 -06:00
|
|
|
"open": "^11.0.0",
|
2026-02-16 13:31:58 -06:00
|
|
|
"pino": "^9.6.0",
|
|
|
|
|
"pino-http": "^10.4.0",
|
2026-02-19 09:09:40 -06:00
|
|
|
"pino-pretty": "^13.1.3",
|
2026-03-20 05:51:33 -05:00
|
|
|
"sharp": "^0.34.5",
|
2026-02-17 12:24:43 -06:00
|
|
|
"ws": "^8.19.0",
|
2026-02-16 13:31:58 -06:00
|
|
|
"zod": "^3.24.2"
|
|
|
|
|
},
|
|
|
|
|
"devDependencies": {
|
|
|
|
|
"@types/express": "^5.0.0",
|
|
|
|
|
"@types/express-serve-static-core": "^5.0.0",
|
2026-03-06 17:18:43 -05:00
|
|
|
"@types/jsdom": "^28.0.0",
|
2026-02-20 10:31:56 -06:00
|
|
|
"@types/multer": "^2.0.0",
|
2026-03-05 14:24:00 -03:00
|
|
|
"@types/node": "^24.6.0",
|
2026-03-20 05:51:33 -05:00
|
|
|
"@types/sharp": "^0.32.0",
|
2026-02-16 13:31:58 -06:00
|
|
|
"@types/supertest": "^6.0.2",
|
2026-03-05 12:39:37 -03:00
|
|
|
"@types/ws": "^8.18.1",
|
2026-03-09 22:08:50 +09:00
|
|
|
"cross-env": "^10.1.0",
|
2026-02-16 13:31:58 -06:00
|
|
|
"supertest": "^7.0.0",
|
|
|
|
|
"tsx": "^4.19.2",
|
|
|
|
|
"typescript": "^5.7.3",
|
2026-02-18 11:45:43 -06:00
|
|
|
"vite": "^6.1.0",
|
2026-02-16 13:31:58 -06:00
|
|
|
"vitest": "^3.0.5"
|
|
|
|
|
}
|
|
|
|
|
}
|