## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - Governed MCP access spans contracts, runtime enforcement, adapters, UI surfaces, and operator verification > - The parity reference PR #9534 is too large for effective automated or human review > - The feature therefore needs a linear stack whose individual diffs stay below the 100-file review limit > - This pull request is split 1/8 and focuses on fixture and demo MCP servers > - The benefit is a standalone, testable review boundary while preserving byte-for-byte parity at the top of the stack ## Linked Issues or Issue Description - Related parity reference: #9534 - Problem: Developers need deterministic local MCP fixtures and visible demo servers without pulling in the governed production runtime. - Proposed solution: Adds the Google Sheets and KV demo MCP packages, fixture catalog/servers, smoke harness, guide, and the root smoke/typecheck registration hunks. - Alternatives considered: keeping #9534 as one 403-file review, or rewriting the feature to manufacture seams; both were rejected in favor of path extraction plus compile-driven boundary moves. - Roadmap alignment: this advances the existing governed MCP/tool-access work already represented by #9534; it does not introduce a separate roadmap initiative. - Stack position: base branch is `master`. - Merge policy: merge bottom-up, in order, only after the complete eight-PR stack has been reviewed and the top-of-stack parity gate remains empty. - Requested review: QA for fixture and smoke coverage; Greptile on every PR. ## What Changed - Adds the Google Sheets and KV demo MCP packages, fixture catalog/servers, smoke harness, guide, and the root smoke/typecheck registration hunks. - Keeps this PR below 100 changed files and independently typecheckable. - Preserves the final tree from #9534 when combined with the other seven stack levels. ## Verification - `pnpm typecheck` - `pnpm --filter @paperclipai/google-sheets-mcp-server test` — 27 tests passed - `pnpm --filter @paperclipai/kv-demo-mcp-server test` — 12 tests passed ## Risks - The new packages add dependencies that are intentionally not committed to `pnpm-lock.yaml`, per repository policy. - Stack risk: merging out of order can expose incomplete layers; mitigate by following the documented bottom-up merge policy. - Parity risk: later edits to an intermediate branch can drift from #9534; mitigate by re-running the empty top-of-stack diff before merge. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - OpenAI Codex, exact model ID `gpt-5.4`; runtime-managed context window; medium reasoning with repository, shell, Git, GitHub CLI, and code-execution tools enabled. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] Internal references are omitted except the execution-plan link explicitly required for this coordinated split stack - [x] My branch name describes the change and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge ## Stack Coordination - Internal execution plan: [PAP-13874](/PAP/issues/PAP-13874#document-plan) - Parity reference: #9534 - Stack: #9556 → #9557 → #9558 → #9559 → #9560 → #9561 → #9562 → #9563 - Merge bottom-up only after full-stack review and an empty parity diff at #9563. --------- Co-authored-by: Paperclip <noreply@paperclip.ing>
2.6 KiB
MCP Fixture Smoke Harness
Paperclip's MCP permission work uses deterministic fixture servers so policy logic can be tested without real customer credentials or live integrations.
Run the local smoke:
pnpm smoke:mcp-fixtures
The runner starts one local stdio fixture and one remote-style HTTP fixture,
checks the local Paperclip /api/health endpoint when available, then exercises:
- allow and deny decisions
- approval-gated writes
- audit records
- fixture runtime startup, health, slow response, crash response, and teardown
- missing-secret and fake OAuth failure paths
- schema-change quarantine
- malicious metadata/result handling
- approved-write idempotency
Use a specific dev instance URL:
pnpm smoke:mcp-fixtures -- --paperclip-url http://127.0.0.1:3100
Require the dev instance health check:
pnpm smoke:mcp-fixtures -- --require-paperclip
JSON output for CI or release-smoke ingestion:
pnpm smoke:mcp-fixtures -- --json
Fixture Catalog
The catalog lives in scripts/mcp-fixtures/catalog.mjs and includes:
- echo/calculator/time read tools
- synthetic todo and KV tools
- outbox email tools
- mock social/blog publishing tools
- malicious metadata and malicious result tools
- slow and crashing stdio tools
- fake OAuth and missing-secret tools
The catalog also defines the first profile set:
read-onlyapproval-gated-writessecurity-hostileruntime-lifecycle
The first-install demo definitions are:
paperclip-self-readchild-issue-proposalgithub-triageupdate-sendercontent-publishinglocal-project-helperops-statuscrm-sales-note-draft
Phase 5a User-Story Harness
The Phase 5a MCP production harness scripts the accepted user-story catalog from PAP-12338 section 5:
pnpm test:e2e:mcp-user-stories
By default this runs only the currently runnable stories (US-1..US-5 and
US-8..US-10) against the Playwright-managed local instance. Each scenario seeds
a real company, a real Scout agent, and a deterministic MCP fixture connection;
then it drives the gateway/Test-tab APIs plus the UI pages that provide
evidence screenshots under test-results/mcp-user-stories/.
Run the full catalog, including dependency-gated placeholders for US-6 and US-7, with:
pnpm test:e2e:mcp-user-stories -- --include-gated
The browser side uses the same PAPERCLIP_PLAYWRIGHT_CHANNEL override as the
rest of tests/e2e. In minimal containers, install the Playwright system
dependencies or point PAPERCLIP_PLAYWRIGHT_CHANNEL at the managed branch
service's known-good Chromium wrapper before running the browser smoke.