Files
fusion/plugins/fusion-plugin-paperclip-runtime
gsxdsm 8bc3d7b0a5 FN-6042: raise dependency security floors
Harden dependency floors and update the Vitest toolchain to patched releases.

- upgrade workspace vitest and @vitest/coverage-v8 dependencies to the 4.1 line across packages and plugins
- pin transitive protobufjs via pnpm overrides and lockfile updates to patched versions
- adapt Vitest configs, engine test helpers, and security-floor coverage for the new dependency baselines
- add the published CLI changeset and related workspace/package metadata updates included in the task branch

Files changed:
 .changeset/fn-6042-security-dependencies.md        |   5 +
 AGENTS.md                                          |   4 +
 Dockerfile                                         |   3 +
 docs/PLUGIN_AUTHORING.md                           |   2 -
 package.json                                       |   3 +-
 packages/cli/package.json                          |   4 +-
 packages/cli/vitest.config.ts                      |   2 +-
 packages/core/package.json                         |   4 +-
 packages/core/vitest.config.ts                     |   2 +-
 packages/dashboard/app/test/mockApi.ts             |   4 +-
 packages/dashboard/package.json                    |   4 +-
 packages/dashboard/vitest.config.ts                |   2 +-
 packages/desktop/package.json                      |   4 +-
 packages/desktop/vitest.config.ts                  |   2 +-
 packages/droid-cli/package.json                    |   2 +-
 packages/droid-cli/vitest.config.ts                |   2 +-
 packages/engine/package.json                       |   4 +-
 .../engine/src/__tests__/executor-test-helpers.ts  |  29 +-
 .../engine/src/__tests__/gridlock-detector.test.ts |   5 +-
 .../src/__tests__/heartbeat-scheduler.test.ts      |   3 +-
 packages/engine/src/__tests__/scheduler.test.ts    |  24 +-
 packages/engine/src/__tests__/self-healing.test.ts |   5 +
 packages/engine/tsconfig.json                      |   3 +-
 packages/engine/vitest.config.ts                   |  10 +-
 packages/i18n/package.json                         |   2 +-
 packages/i18n/vitest.config.ts                     |   7 +
 packages/mobile/package.json                       |   2 +-
 packages/mobile/vitest.config.ts                   |   2 +-
 packages/pi-claude-cli/package.json                |   2 +-
 packages/pi-claude-cli/vitest.config.ts            |   2 +-
 packages/pi-llama-cpp/package.json                 |   2 +-
 packages/pi-llama-cpp/vitest.config.ts             |   2 +-
 packages/plugin-sdk/package.json                   |   2 +-
 packages/plugin-sdk/vitest.config.ts               |   2 +-
 .../examples/fusion-plugin-auto-label/package.json |   2 +-
 .../fusion-plugin-auto-label/vitest.config.ts      |   2 +-
 .../examples/fusion-plugin-ci-status/package.json  |   2 +-
 .../fusion-plugin-ci-status/vitest.config.ts       |   2 +-
 .../fusion-plugin-notification/package.json        |   2 +-
 .../fusion-plugin-notification/vitest.config.ts    |   2 +-
 .../fusion-plugin-settings-demo/package.json       |   2 +-
 .../fusion-plugin-settings-demo/vitest.config.ts   |   2 +-
 plugins/fusion-plugin-acp-runtime/package.json     |   2 +-
 plugins/fusion-plugin-acp-runtime/vitest.config.ts |   2 +-
 plugins/fusion-plugin-agent-browser/package.json   |   2 +-
 .../fusion-plugin-agent-browser/vitest.config.ts   |   2 +-
 .../fusion-plugin-cli-printing-press/package.json  |   2 +-
 .../vitest.config.ts                               |   2 +-
 .../package.json                                   |   2 +-
 .../src/__tests__/orchestrator-live-output.test.ts |   4 +-
 .../vitest.config.ts                               |   2 +-
 plugins/fusion-plugin-cursor-runtime/package.json  |   4 +-
 .../fusion-plugin-dependency-graph/package.json    |   4 +-
 .../vitest.config.ts                               |   2 +-
 plugins/fusion-plugin-droid-runtime/package.json   |   2 +-
 .../fusion-plugin-droid-runtime/vitest.config.ts   |   2 +-
 plugins/fusion-plugin-even-cards/package.json      |   2 +-
 plugins/fusion-plugin-even-cards/vitest.config.ts  |   2 +-
 .../package.json                                   |   2 +-
 .../vitest.config.ts                               |   2 +-
 plugins/fusion-plugin-hermes-runtime/package.json  |   2 +-
 .../fusion-plugin-hermes-runtime/vitest.config.ts  |   2 +-
 .../fusion-plugin-openclaw-runtime/package.json    |   2 +-
 .../vitest.config.ts                               |   2 +-
 .../fusion-plugin-paperclip-runtime/package.json   |   2 +-
 .../vitest.config.ts                               |   2 +-
 plugins/fusion-plugin-reports/package.json         |   2 +-
 .../src/__tests__/review-panel.test.ts             |   6 +-
 plugins/fusion-plugin-reports/vitest.config.ts     |   2 +-
 plugins/fusion-plugin-roadmap/package.json         |   2 +-
 plugins/fusion-plugin-roadmap/vitest.config.ts     |   2 +-
 plugins/fusion-plugin-whatsapp-chat/package.json   |   2 +-
 .../fusion-plugin-whatsapp-chat/vitest.config.ts   |   2 +-
 pnpm-lock.yaml                                     | 626 ++++++++-------------
 .../__tests__/dependency-security-floor.test.mjs   |  95 ++++
 75 files changed, 475 insertions(+), 491 deletions(-)

Fusion-Task-Id: FN-6042

Fusion-Task-Lineage: fff6a1cb-8937-435c-9a91-b7c7a59cc80e
2026-06-08 15:19:27 -07:00
..
2026-05-31 20:05:32 -07:00

Paperclip Runtime Plugin

Drives a Paperclip agent (an "employee" in a Paperclip company) via the wakeup + heartbeat-run API. Each Fusion prompt becomes a Paperclip task, not a chat completion.

Mental model — read this first

Paperclip is a control plane for AI labor. Agents are long-lived employees with budgets, chains of command, and approval gates; Paperclip itself does not run models — it dispatches work to adapters (claude_local, codex_local, openclaw, http, …) which run the actual LLM call inside their own heartbeat.

This plugin proxies a Fusion conversation through one of those Paperclip agents:

  1. (Optionally) creates a Paperclip issue with the prompt as its body, assigned to your chosen agent.
  2. Calls POST /api/agents/{id}/wakeup with payload: { prompt, fusionSessionId, issueId } and an idempotency key.
  3. Streams GET /api/heartbeat-runs/{runId}/events, forwarding heartbeat.run.log chunks to the chat UI.
  4. On terminal status (succeeded | failed | cancelled | timed_out), reads the issue's final state and the agent's closing comment.

Implications:

  • Latency is task-shaped (seconds to minutes), not chat-shaped.
  • Governance applies: budget caps, approval requirements, audit log all come from Paperclip.
  • A single Paperclip agent can be proxied from many Fusion sessions concurrently.

Prerequisites

A running Paperclip server you can reach. For local development:

npm install -g paperclipai
paperclipai onboard      # interactive setup
paperclipai run          # starts the server (default: http://localhost:3100)

Verify the server is up:

curl http://localhost:3100/api/health

Connection modes

The dashboard settings card lets you pick API or CLI mode:

API mode (default)

Paste an apiUrl and an agent apiKey. Get a key from the Paperclip UI's agent detail page → "Create API Key" (the full value is shown once). For local-trusted deployments, the key may be omitted.

CLI mode

Auto-derive the apiUrl from the local paperclipai install. The plugin reads ~/.paperclip/instances/default/config.json and uses that host:port as the apiUrl. No token needs to be pasted into Fusion. For non-local-trusted deployments, you can still set an override apiKey.

CLI key bootstrap

For authenticated Paperclip deployments (e.g. paperclip-dev or any non-local_trusted instance), a bearer token is required. The dashboard offers a one-click "✨ Mint API key via paperclipai" button that appears in CLI mode when:

  • A connection has been attempted but available === false (typically "API key rejected"), AND
  • The user has already selected an agent in the agent picker.

The button calls POST /api/providers/paperclip/cli-mint-key on the Fusion backend, which spawns:

paperclipai agent local-cli <agentRef> --json --no-install-skills --key-name fusion-runtime

On success the returned apiKey is written into the API key field and a save-prompt toast is shown. On failure (e.g. CLI not authenticated) the toast shows the error and instructs the user to run paperclipai onboard.

Requirement: The local paperclipai CLI must be authenticated (~/.paperclip/context.json must have a valid profile). Run paperclipai onboard to authenticate if the mint fails.

Conversation modes

Independent of transport, the mode setting controls how prompts map to Paperclip issues:

Mode Behavior
rolling-issue (default) Creates one Paperclip issue per Fusion session; subsequent prompts add comments. Closest to chat.
issue-per-prompt Each prompt creates a new top-level issue. Maximally explicit; clutters the board.
wakeup-only No issue side-effects; the prompt is delivered via the wakeup payload only. Requires the agent's prompt template to handle payload-driven wakes.

Settings

Key Env var Default Notes
transport PAPERCLIP_TRANSPORT api api or cli.
apiUrl PAPERCLIP_API_URL http://localhost:3100 API mode only.
apiKey PAPERCLIP_API_KEY (none) API mode (and as a CLI-mode override).
cliBinaryPath PAPERCLIPAI_BIN paperclipai CLI mode only.
cliConfigPath PAPERCLIP_CLI_CONFIG ~/.paperclip/instances/default/config.json CLI mode only.
agentId PAPERCLIP_AGENT_ID auto-derived from /api/agents/me The Paperclip agent this Fusion runtime proxies.
companyId PAPERCLIP_COMPANY_ID auto-derived from /api/agents/me The Paperclip company.
mode PAPERCLIP_RUNTIME_MODE rolling-issue One of the conversation modes above.
parentIssueId PAPERCLIP_PARENT_ISSUE_ID (none) Optional issue scoping.
projectId PAPERCLIP_PROJECT_ID (none) Optional.
goalId PAPERCLIP_GOAL_ID (none) Optional.
runTimeoutMs PAPERCLIP_RUN_TIMEOUT_MS 600000 Local cap before Fusion stops polling. The run continues server-side.
pollIntervalMs PAPERCLIP_POLL_INTERVAL_MS 500 Initial poll interval.
pollIntervalMaxMs PAPERCLIP_POLL_INTERVAL_MAX_MS 2000 Max poll interval after exponential backoff.

Settings precedence: plugin settings → env var → default.

Public API

import {
  PaperclipRuntimeAdapter,
  // REST helpers
  agentsMe,
  listCompanies,
  listCompanyAgents,
  // Probes
  probePaperclipConnection,
  discoverPaperclipCliConfig,
  // CLI key minting
  mintAgentApiKeyViaCli,
  // Types
  type PaperclipAgentSummary,
  type PaperclipCompanySummary,
  type PaperclipConnectionStatus,
  type PaperclipCliDiscoveryResult,
  type MintCliKeyOptions,
  type MintedApiKey,
} from "@fusion-plugin-examples/paperclip-runtime";
  • probePaperclipConnection({ apiUrl, apiKey?, timeoutMs? }) → { available, identity?, reason? }. Powers the dashboard's "✓ Connected as " badge.
  • listCompanyAgents(apiUrl, apiKey, companyId) → list of agents in a company. Drives the agent picker.
  • discoverPaperclipCliConfig({ configPath? }) → { ok, apiUrl, deploymentMode? } from the local paperclipai config. Drives CLI-mode auth discovery.
  • mintAgentApiKeyViaCli(opts: MintCliKeyOptions) → Promise<MintedApiKey>. Spawns paperclipai agent local-cli <agentRef> --json --no-install-skills to mint a fresh agent API key. Throws on ENOENT, non-zero exit, or malformed JSON; includes a hint to run paperclipai onboard on auth failures.

Endpoints used (Paperclip side)

Method Path Purpose
GET /api/agents/me Identity + auto-derive agentId/companyId.
GET /api/companies Company list (board access).
GET /api/companies/{companyId}/agents Agent list (agent-key sees its own company).
POST /api/companies/{companyId}/issues Issue creation (issue-per-prompt / rolling-issue modes).
POST /api/agents/{agentId}/wakeup Trigger a heartbeat run with the Fusion prompt as payload.
GET /api/heartbeat-runs/{runId}/events Streaming run log + status.
GET /api/issues/{issueId} Final issue state.
GET /api/issues/{issueId}/comments Final comment fallback.

The adapter does not call /api/issues/{id}/checkout — checkout is the agent's job during its own heartbeat. The adapter does not call the legacy /api/agents/{id}/heartbeat/invoke.

Limitations

  • Latency. Heartbeat runs can take minutes; not a chat-completion drop-in.
  • Single-agent identity per connection. A Paperclip agent API key is scoped to one agent in one company. To proxy several agents, configure several Fusion connections.
  • Run-events schema is partially inferred. The events endpoint payload shape is documented but not formally schema'd; the client accepts both bare-array and { events: [...] } envelopes defensively.

Metadata

  • Plugin ID: fusion-plugin-paperclip-runtime
  • Runtime ID: paperclip
  • Package: @fusion-plugin-examples/paperclip-runtime

Development

pnpm --filter @fusion-plugin-examples/paperclip-runtime test    # 46 tests
pnpm --filter @fusion-plugin-examples/paperclip-runtime build