mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 21:05:21 +02:00
## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The runner action catalog defines what scenario tools can exist > - A catalog entry must not grant authority by itself > - Scenario runs need run-scoped discovery and invocation checks > - Observable results must not expose protected values > - This pull request adds an authorized package-local scenario tool runtime > - The benefit is deterministic tool testing without production service authority ## Linked Issues or Issue Description **Subsystem affected** `packages/paperclip-runner` scenario tool runtime. **Problem or motivation** Scenario tests need to expose only authorized actions. They also need stable denial records, redaction, and idempotent command handling. **Proposed solution** Project the canonical scenario contracts into a visible catalog. Recheck policy at invocation. Dispatch allowed operations through the mock control-plane port and return redacted receipts. **Alternatives considered** Direct production bindings are outside this pull request. The runtime uses only the package-local mock port. **Roadmap alignment** This supports runner conformance and scenario testing. It does not enable an adapter or production service call. ## What Changed - Added run-scoped scenario tool discovery. - Added claim, role, task-mode, and policy authorization. - Added input validation, redaction, and authorization records. - Added fake-agent and Codex definition projections. - Added deterministic mock dispatch and idempotency coverage. ## Verification - `pnpm --filter @paperclipai/paperclip-runner test:typescript` - `pnpm -r typecheck` - `pnpm build` - The focused semantic runtime test has 10 passing cases. ## Risks Low risk. The runtime is package-local and uses the mock control-plane port. It creates no production binding. ## Model Used OpenAI Codex with GPT-5.6 and repository tool use. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups - [x] I will address all Greptile and reviewer comments before requesting merge