paperclip/packages/paperclip-runner
Nicky Leach c1b55537ba
fix(paperclip-runner): bump claude-agent-acp pin to 0.73.0 (#13162)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - The Claude local adapter can run agent turns through an ACP (Agent
Client Protocol) server, `claude-agent-acp`, instead of the plain CLI
> - Two separate packages each pin their own copy of that dependency:
`packages/adapters/claude-local` (the server-side adapter) and
`packages/paperclip-runner` (which builds the provider pack baked into
every managed sandbox image)
> - `claude-local` moved to `^0.73.0` in #12730, but `paperclip-runner`
was never bumped past `0.70.0` — nothing keeps the two in sync when only
one changes
> - That split means a sandbox image built from `paperclip-runner`'s
provider pack ships a `claude-agent-acp` the server-side adapter was
never actually compatible with
> - This pull request bumps `paperclip-runner`'s pin to `0.73.0`, the
only version that satisfies both packages' declared ranges at once, and
fixes the matching hardcoded version assertion in
`docker/daytona-runner/Dockerfile`
> - The benefit is one consistent, compatible `claude-agent-acp` version
across both the server host and every sandbox image built from this
source, instead of a silent split that only surfaces as a runtime
failure

## Linked Issues or Issue Description

No public issue exists for this specific split; opening directly per
CONTRIBUTING.md path B, following the bug report template fields.

**What happened?**
`packages/paperclip-runner/package.json` pins
`@agentclientprotocol/claude-agent-acp` at an exact `0.70.0`.
`packages/adapters/claude-local/package.json` requires `^0.73.0` (added
in #12730, 2026-09-02). Nobody re-synced `paperclip-runner`'s pin after
that change — the two packages' dependency graphs are independent, so a
bump in one doesn't propagate to the other. `paperclip-runner`'s copy is
what the fleet sandbox image's provider pack actually ships, so every
managed sandbox built from current source carries a `claude-agent-acp`
version the server-side adapter's own declared compatibility range
excludes.

**Expected behavior**
The two packages' `claude-agent-acp` pins should stay within a mutually
compatible range, so a sandbox image built from this source always ships
a version the server-side adapter actually supports.

**Steps to reproduce**
1. Check `packages/adapters/claude-local/package.json`'s
`@agentclientprotocol/claude-agent-acp` range (`^0.73.0`).
2. Check `packages/paperclip-runner/package.json`'s pin for the same
package (`0.70.0` before this PR).
3. Note that `^0.73.0` on a `0.x` version only admits patch releases
(`>=0.73.0 <0.74.0` per semver caret rules), so `0.70.0` falls outside
it.

**Paperclip version or commit**
`master` as of this PR (paperclip-runner still at `0.70.0` prior to this
change; claude-local's `^0.73.0` requirement landed in #12730).

**Deployment mode**
Any deployment that runs `claude_local` agents through the ACP engine
against a sandbox image built from `packages/paperclip-runner`'s
provider pack (managed cloud sandboxes in particular).

Related PRs for context (not duplicates — none of these touch
`paperclip-runner`'s pin):
- #12730 — introduced the `^0.73.0` requirement in `claude-local`
- #11873 — the last time `paperclip-runner`'s pin moved (`0.69.0` →
`0.70.0`)
- #13105 — separately made an unavailable ACP engine a hard failure
instead of a silent CLI fallback, which is what turned this version
split into a visible, run-blocking error rather than a quiet downgrade

## What Changed

- Bump `@agentclientprotocol/claude-agent-acp` from `0.70.0` to `0.73.0`
(exact pin, matching this package's existing pin style for its other
agent-CLI dependencies) in `packages/paperclip-runner/package.json`.
- Update the corresponding hardcoded version assertion (`test
"$(claude-agent-acp --version)" = "0.70.0"`) in
`docker/daytona-runner/Dockerfile` to `0.73.0`, so its own build-time
check stays accurate instead of failing on the next build for an
unrelated reason.
- `pnpm-lock.yaml` is intentionally **not** included —
`pr-trusted.yml`'s `Validate dependency resolution and regenerate stale
lockfile` step already regenerates it for the merge tree and hands it to
downstream `--frozen-lockfile` jobs as an artifact, so a manual lockfile
commit here would just be stale the moment CI runs.

## Verification

- `0.73.0` is a real published version on npm (confirmed via `npm view
@agentclientprotocol/claude-agent-acp versions`), and it's the *only*
version satisfying claude-local's `^0.73.0` range, so this isn't a guess
at compatibility — it's the unique intersection of both packages'
declared ranges.
- `grep -rn "0\.70\.0" docker/ packages/paperclip-runner/package.json`
after this change shows no remaining stale references to the old pin.
- I did not run a full local install/test pass against a hand-updated
lockfile, since regenerating one locally would conflict with leaving
`pnpm-lock.yaml` untouched per the note above; CI's own
lockfile-regeneration step is the intended verification path for a
manifest-only dependency bump like this one.
- Downstream/full verification (does a sandbox image actually built with
this pin work end-to-end) is tracked separately in `paperclip-cloud` —
an unrelated internal-only repo, so not linked here — where a sibling
fix restores the ACP servers to the runtime `PATH` in the fleet sandbox
image itself; both fixes are needed together for a working sandbox, but
this PR is scoped to the version pin alone.

## Risks

- Low risk: single-line dependency version bump plus a matching
test-assertion update, no code changes. `0.73.0` is a patch release
within claude-local's own already-declared-safe range, so there's no
reason to expect it changes behavior tenants depend on.
- The main risk is unknown breaking changes between `claude-agent-acp`
0.70.0 and 0.73.0 that aren't caught by the version-string assertion
alone (that check only confirms the binary reports the right version,
not that its behavior is unchanged). I have not audited that package's
own changelog between those versions.
- `docker/daytona-runner/Dockerfile` is a parallel/reference image (per
its own header comment, meant to stay aligned with the private
`paperclip-cloud/fleet-sandbox-image/Dockerfile`, which is out of scope
here) — this PR does not touch that other Dockerfile.

## Model Used

Claude Sonnet 5 (`claude-sonnet-5`), via Claude Code, with tool use
(file edits, shell/git, `gh` CLI, `npm view` for version verification).
No extended-thinking mode. Standard Claude Code context window.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass — see Verification: a
manifest-only bump with the lockfile intentionally left to CI's own
regeneration step; no local test run applicable
- [x] I have added or updated tests where applicable — version-pin bump
only, no new behavior to test
- [x] I have updated relevant documentation to reflect my changes — none
applicable
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green — pending CI run on this PR
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups —
pending review
- [x] I will address all Greptile and reviewer comments before
requesting merge

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 11:35:33 -07:00
..
devtools feat(runner): add guarded API search and call fallback (#13003) 2026-09-07 14:14:43 -05:00
docs feat: add experimental native chat connectors (#13038) 2026-09-10 10:06:45 -05:00
examples feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
generated feat: add experimental native chat connectors (#13038) 2026-09-10 10:06:45 -05:00
infra feat(runner): restore direct live eval campaigns and reports (#12909) 2026-09-05 20:18:11 -05:00
protocol Add end-to-end session goals to Paperclip Runner 2026-09-08 16:18:47 -05:00
runner fix(paperclip-runner): bump claude-agent-acp pin to 0.73.0 (#13162) 2026-09-10 11:35:33 -07:00
scripts fix(paperclip-runner): bump claude-agent-acp pin to 0.73.0 (#13162) 2026-09-10 11:35:33 -07:00
spec feat: add experimental native chat connectors (#13038) 2026-09-10 10:06:45 -05:00
src fix(paperclip-runner): bump claude-agent-acp pin to 0.73.0 (#13162) 2026-09-10 11:35:33 -07:00
test fix(paperclip-runner): bump claude-agent-acp pin to 0.73.0 (#13162) 2026-09-10 11:35:33 -07:00
test-fixtures feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
test-support fix(runner): restore local session and task integrity (#12721) 2026-09-02 16:11:26 -05:00
.gitignore feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
README.md fix: repair runner configuration, macOS execution, and artifact galleries (#13062) 2026-09-08 19:10:09 -05:00
SEMANTIC_ACTIONS.md feat(runner): authorize semantic tool dispatch (#12126) 2026-08-24 17:28:54 -05:00
package.json fix(paperclip-runner): bump claude-agent-acp pin to 0.73.0 (#13162) 2026-09-10 11:35:33 -07:00
rust-toolchain.toml feat(runner): define package API and verification boundary (#12129) 2026-08-25 09:31:48 -05:00
styles.css feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
tsconfig.browser.json feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
tsconfig.json feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
tsconfig.surfaces.json feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
vite.config.ts feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
vite.issue-thread-stream.config.ts feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
vite.issue-thread.config.ts feat(runner): restore direct live eval campaigns and reports (#12909) 2026-09-05 20:18:11 -05:00
vite.scenarios.config.ts feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
vite.sdk.config.ts feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
vite.standalone.config.ts feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00
vitest.config.ts feat(runner): add SDK and developer tooling (#12608) 2026-08-31 21:33:11 -05:00

README.md

Paperclip Native Runner

This package is the standalone development boundary for Paperclip's native runner protocol, process supervision, durable transport, provider drivers, and normalized session backends. Rust owns the production runner under runner/; TypeScript provides the control-plane reference, browser SDK, scenario tools, and conformance oracle.

The package includes one coherent set of capabilities: PRP v1 validation and replay, a supervised local runner with a scripted fake harness, durable WebSocket delivery and recovery, qualified Codex, OpenCode, ACPX, Claude Managed, and AWS AgentCore drivers, live session and issue-thread surfaces, a public browser/React SDK, a standalone adapter demo, and a deterministic mock control plane. None of these surfaces imports or starts Paperclip's server, UI, CLI, or production database.

Public package surfaces

  • @paperclipai/paperclip-runner — production contracts, clients/backends, PRP validation/replay, canonical catalog/dispatcher, and compatibility check.
  • @paperclipai/paperclip-runner/testing — deterministic mocks plus PRP and semantic conformance kits. Tests and external conformance consumers import this explicitly.
  • @paperclipai/paperclip-runner/evals — versioned native-attempt metadata, fail-closed package/binary compatibility checks, and explicit runnerd artifact resolution for eval consumers.

The package root has no mock or scenario exports. Generic credential-free matrix orchestration lives in the workspace-private @paperclipai/paperclip-eval-kernel; scenario content and provider-backed eval campaigns remain outside the runtime package. See ADR 0001.

The two conformance surfaces intentionally prove different contracts. The existing runControlPlanePortConformance suite checks narrow PRP run/event persistence. CAPABILITY_HIGH_RISK_SEMANTIC_VECTORS and runSemanticConformanceKit compare normalized tool authorization, state, effects, audit, retries, conflicts, redaction, continuation, and terminal decisions. The production adapter stays App-owned and invokes Paperclip's real route/service authorities; it does not copy those rules into this package.

Quick start

The package also builds paperclip-runner-acpx-sidecar. This bounded v2 stdin/stdout bridge admits the pinned Claude and Codex ACPX profiles. It validates the exact model, session identity, tool catalog, structured input, and terminal settlement at the process boundary. Pi remains unavailable.

Runnerd selects only qualified provider profiles. Claude Managed and AWS AgentCore receive immutable company-profile snapshots with explicit retention, spend, and invocation limits. No provider process receives a Paperclip API credential or unrestricted server environment.

Claude Managed resolves its API key from the company secret bound to the selected profile. AWS AgentCore uses workload identity only; long-lived static AWS access keys are intentionally removed from the runner environment.

The Rust core includes a bounded client for the sidecar protocol. It enforces request identity, event order, frame and queue limits, timeouts, redacted diagnostics, and process-group cleanup. Runnerd selects this package-local transport only through an exact qualified provider descriptor.

Before a later provider adapter consumes a valid sidecar event, the Rust core also requires its optional or mandatory run and turn scope to match the active execution. Process and diagnostic events can remain global. All operational, tool, input, permission, and terminal events require the exact active binding.

A package-local payload boundary decodes events only after that scope check. It validates control identities, terminal status, question sets, and the admitted runtime event types and bounded fields. It redacts diagnostic and retained event values again before they can enter provider state.

Validated ACPX runtime events normalize into the same provider-neutral activity families as the direct Codex transport. Reasoning contents stay private. Tool targets are resolved within the workspace under the provider host's path semantics and receive a versioned sidecar boundary marker before becoming bounded, display-only PRP safe paths. Raw or unmarked provider locations fail closed. URI-scheme and Windows drive-shaped values require a separate sidecar attestation backed by an existing in-workspace entry or, for a not-yet-created edit target, an existing in-workspace parent. This preserves real POSIX colon filenames without treating arbitrary URI text as a path. Windows separators are canonicalized, and consumers must not reinterpret the display value as file-access authority. Operational semantic-result and terminal events remain reserved for the stateful adapter rather than being duplicated.

The ACPX provider reducer preserves that order while it tracks one active turn, bounded assistant text, semantic results, and pending tool or input correlations. Terminal events flush the final assistant message first and clear unresolved turn-scoped requests.

The package-local session bootstrap starts the bounded sidecar transport, verifies the qualified capability handshake and effective model, opens one identity-bound session, and confirms its run attachment. Any failed bootstrap terminates the process; session shutdown preserves persistent provider state. The session can then start one immutable-workspace turn, request interruption, and reduce polled events through the scope-first state boundary. A mismatched command acknowledgement or invalid event terminates the session fail closed. Polled semantic calls pass through the run-scoped authorized tool bridge before they can be returned to a caller. Before a follow-up turn releases settled tool receipts, runner-core suspends and reaps the idle sidecar/provider generation, then resumes the same verified persistent identity in a fresh generation. This prevents a late session-lifetime MCP callback from inheriting the next turn's event authority.

The Rust question-response validator checks the versioned response envelope against the exact persisted question IDs, answer modes, options, required answers, custom-answer policy, and text constraints before provider delivery. Tool results and structured question responses then use two-phase resolution: validate retained identity and schema, require the exact sidecar acknowledgement, and only then clear pending local state. Codex permission requests violate its pinned sidecar policy and terminate the session fail closed. Safe suspension is available only with no active turn or pending request. The sidecar must return the exact persistent session identity before runnerd terminates the local process. Already validated ACPX reducer events project into provider-neutral durable events only with an exact run, session, turn, and item binding. Raw sidecar envelopes and permission requests are not admitted at this boundary. A safely suspended session can be recorded as a bounded private checkpoint. The checkpoint binds the exact provider identity, run, catalog revision, and catalog digest and is replaced atomically before a later recovery attempt. Recovery releases the stored identity only after those bindings match the prospective session configuration exactly.

Run the complete contract gate with:

pnpm install --filter @paperclipai/paperclip-runner --lockfile=false --offline --ignore-scripts --dev
pnpm --filter @paperclipai/paperclip-runner verify

The verification command requires a stable Rust toolchain with cargo on PATH, in addition to Node.js 24.11+ and pnpm 9+.

Minimal Debian/Ubuntu hosts without root access can extract the required Playwright browser libraries into a user-owned cache and run the same acceptance sequence with:

pnpm --filter @paperclipai/paperclip-runner verify:rootless

The tracer's final line is stable:

{
  "schemaVersion": "paperclip.runner.conformance.output.v1",
  "runIdentity": {
    "runId": "run_conformance_0001",
    "sessionId": "session_conformance_0001"
  },
  "result": {
    "status": "succeeded",
    "summary": "Standalone Conformance fixture accepted."
  }
}

Run only the tracer with:

pnpm --filter @paperclipai/paperclip-runner trace:conformance

Replay the Replay happy path, run a Local session, or open the browser devtool:

pnpm --filter @paperclipai/paperclip-runner replay:fixture
pnpm --filter @paperclipai/paperclip-runner trace:local-runner -- --scenario happy-path
pnpm --filter @paperclipai/paperclip-runner trace:codex
pnpm --filter @paperclipai/paperclip-runner demo:live-console -- --host 127.0.0.1 --port 4174

# Live console: chat with a live session in the browser.
pnpm --filter @paperclipai/paperclip-runner console:live-console
pnpm --filter @paperclipai/paperclip-runner browser:dev --host 127.0.0.1 --port 4179

# SDK: open the public-SDK reference console and mini consumer.
pnpm --filter @paperclipai/paperclip-runner console:sdk

# Standalone: run the standalone legacy/native/kill-switch tracer and page.
pnpm --filter @paperclipai/paperclip-runner trace:standalone
pnpm --filter @paperclipai/paperclip-runner trace:standalone -- --feature-flag enabled
pnpm --filter @paperclipai/paperclip-runner trace:standalone -- --feature-flag enabled --kill-switch enabled
pnpm --filter @paperclipai/paperclip-runner demo:standalone

Live console provider-backed routes are loopback-only and reject wildcard/LAN binds. Browser mutations require same-origin Fetch Metadata, matching Origin, and JSON content; see the protocol-server tutorial for direct curl examples.

Direct live protocol qualification

The canonical direct live protocol suite lives in the separate paperclip-evals repository under evals/paperclip-runner/. Its live-mini.json roster is the complete 35-case Codex qualification lane. Build this package's TypeScript output, release paperclip-runnerd, package tarball, and dist-issue-thread viewer, then use the roster runner documented in that repository. The package ships the required orchestration entry point as paperclip-runner-eval-session (dist/cli/eval-session.js). Evalbook owns the consistent HTML matrix and read-only attempt drill-down pages.

The hosted full-campaign workflow, parallel matrix, credential boundaries, canonical report merge, and versioned S3 index are documented in docs/runner-protocol-live-evals.md.

This direct protocol qualification is separate from the stress-derived Runner workflow schedule below and from the full-stack browser model E2E suite.

Stress-derived workflow, chaos, and AWS AgentCore operations

The deterministic workflow scorer and the chaos schedule do not require provider credentials:

pnpm --filter @paperclipai/paperclip-runner test:runner-workflow-evals
pnpm --filter @paperclipai/paperclip-runner report:runner-chaos-evals

report:runner-live-evals is a paid, provider-backed command. Native Codex requires OPENAI_API_KEY; ACPX Claude requires ANTHROPIC_API_KEY; OpenCode candidates require OPENROUTER_API_KEY. The live matrix admits no Pi profile and does not persist credential values. Set PAPERCLIP_EVAL_MAX_CAMPAIGN_COST_USD to a positive finite number to bound additional scheduling after the observed campaign total reaches that value:

PAPERCLIP_EVAL_MAX_CAMPAIGN_COST_USD=12 \
  PAPERCLIP_EVALS_ROOT=/path/to/paperclip-evals \
  pnpm --filter @paperclipai/paperclip-runner report:runner-live-evals

# Run two scheduled native Codex executions only.
PAPERCLIP_EVALS_ROOT=/path/to/paperclip-evals \
  pnpm --filter @paperclipai/paperclip-runner report:runner-live-evals -- \
  --candidate codex-luna --limit 2

GitHub-hosted live campaigns additionally require the default branch, an allowlisted numeric actor ID, the protected runner-e2e-paid environment, and an explicit repository variable before scheduled runs are enabled. Manual dispatches accept the same candidate, case, and execution-limit selectors. The paid job uses the reviewed RunsOn Fleet label when RUNNER_E2E_AWS_ENABLED=true and otherwise stays on ubuntu-latest. Uploaded reports contain redacted observations and trace digests, not raw provider frames, prompts, credentials, tool arguments, or hidden reasoning.

The AgentCore proof-of-concept uses an AWS CLI v2 profile to provision a dedicated invocation role and scoped resources. Its local mode-0600 metadata file contains no access keys; probes assume short-lived STS credentials and clear them after use. Validate locally, provision or inspect the stack, run the bounded lab/smoke, and tear it down explicitly with:

pnpm --filter @paperclipai/paperclip-runner test:aws-agentcore-provisioning
pnpm --filter @paperclipai/paperclip-runner aws-agentcore:provision -- --dry-run
pnpm --filter @paperclipai/paperclip-runner aws-agentcore:provision
pnpm --filter @paperclipai/paperclip-runner aws-agentcore:probe
pnpm --filter @paperclipai/paperclip-runner aws-agentcore:lab
pnpm --filter @paperclipai/paperclip-runner smoke:capability:aws-agentcore
pnpm --filter @paperclipai/paperclip-runner aws-agentcore:destroy -- --yes

To admit the hosted direct-eval workflow, provision with the account-local GitHub Actions OIDC provider and keep the default exact repository and protected environment binding:

pnpm --filter @paperclipai/paperclip-runner aws-agentcore:provision -- \
  --aws-profile paperclip-dev \
  --github-oidc-provider-arn arn:aws:iam::<account-id>:oidc-provider/token.actions.githubusercontent.com

This adds only repo:paperclipai/paperclip:environment:runner-e2e-paid as a web-identity subject on the scoped invocation role. The generated nonsecret profile records that role as both the local invocation role and the hosted execution role.

Provisioning can incur Bedrock, AgentCore Runtime/Memory, storage, and private networking charges. Provisioning refuses to modify a colliding stack unless its Paperclip ownership tags and template description match. A verified ROLLBACK_COMPLETE stack still requires --replace-failed-stack plus an interactive confirmation (or --yes) before it can be deleted and recreated. Destruction requires --yes and refuses to remove a stack with an active recorded lab unless --force is also supplied.

Package-owned commands

Command Purpose
build Compile the TypeScript public surface, Rust workspace, and browser devtool.
typecheck Check TypeScript, Rust, generated schema sources, and browser types.
test Run Rust/TypeScript fixture, supervisor, fake-driver, live/replay, and boundary tests.
check:forbidden-imports Reject TypeScript imports and Cargo path dependencies that cross into Paperclip core.
check:tracked-imports Reject tracked imports and package.json entry points that only resolve against untracked files, so a clean checkout of any commit builds.
check:numbered-milestones Reject numbered construction-milestone names in tracked package paths and source.
check:package-boundaries Enforce the acyclic runtime/testing/eval dependency and manifest boundary.
check:clean-consumers Pack the runner and install its root, evals, and testing exports in a clean consumer.
test:eval-slice Run the credential-free eval bundle, scoring, and behavior/fault slice.
test:runner-workflow-evals Run the deterministic provider-neutral workflow matrix.
report:runner-workflow-evals Validate deterministic fail-closed results and write JSON, Markdown, JUnit, and GitHub-safe reports.
report:runner-live-evals Execute the paid provider schedule and render its immutable attempts with the canonical paperclip-evals HTML grid.
report:runner-chaos-evals Write the credential-free eight-scenario chaos schedule.
test:aws-agentcore-provisioning Validate the AgentCore template and wrapper safety contracts without provisioning.
aws-agentcore:provision / probe / lab / destroy Manage the scoped AgentCore proof-of-concept lifecycle.
smoke:capability:aws-agentcore Exercise the qualified AgentCore profile through the capability harness.
check:conformance-parity Require byte-for-byte equivalent Rust and TypeScript tracer output.
check:replay-goldens Require all reducer snapshots and cross-language summaries to match checked goldens.
check:replay-parity Run TypeScript and Rust against the same Replay fixture summaries.
check:browser-tokens Reject component-local visual literals and require the standalone token layer.
docs:validate Validate local documentation links.
trace:conformance Run the Rust mock-core tracer, print the stable result, and exit.
trace:conformance:typescript Run the TypeScript reference tracer directly.
replay:fixture Validate and reduce a fixture to a final snapshot.
trace:local-runner Run one native local session through the Rust runner and fake harness.
trace:codex Run the mock core with a real, local skillless Codex app-server session.
demo:live-console Start the package-local HTTP/SSE server with server-only Codex authentication.
console:live-console Start the standalone browser devtool with the Live console on 127.0.0.1:4180.
console:sdk Start the public-SDK reference console and mini consumer on 127.0.0.1:4181.
test:sdk Run targeted browser-client, reducer-projection, and React component contract tests.
test:browser:sdk Exercise both consumers with the fake driver, keyboard/a11y checks, reconnect/replay, measurements, and screenshots.
record:sdk:codex Run both public consumers against a safe real Codex session and capture live screenshots.
check:capability-contract Verify the generated capability, legacy MCP, and eval traceability contract.
check:semantic-contracts Verify the provider-neutral semantic tool contract is current.
trace:live-runner Run the real runnerd/Codex semantic loop against the mock control plane.
demo:scenarios Start the Capability scenario explorer over the mock control plane on 127.0.0.1:4183.
console:issue-thread Start the Paperclip-style issue thread on 127.0.0.1:4184.
test:scenarios Run the scenario index, run-artifact, parity, explorer component, and route tests.
test:browser:scenarios Exercise both the scenario explorer and issue-thread browser contracts.
browser:dev Start the standalone live/replay browser devtool.
test:browser Exercise static replay and live scenarios, then capture temporary screenshots under ignored test output.
verify Run the complete deterministic Conformance through SDK acceptance sequence.
verify:rootless Extract Debian/Ubuntu browser libraries without root, then run verify.

Navigate

Codex adds the package-local real-model reference driver, Live console adds the package-local browser console, and SDK extracts a reusable public SDK plus two standalone consumers. Runtime production Paperclip integration remains deferred; the App-owned production conformance adapter is test-only.

The SDK reference console opens in direct chat mode. Enter a normal prompt, then open the protocol inspector to review events and reducer state. Expand a Terminal row and its nested Debug details disclosure to inspect every canonical event retained for that command. The header marker 🖇️ v0.1.2 identifies the current console iteration.