Skip to content

v0.12.7 — the Exceptions panel now reports decisions, and finds the ungoverned path

Latest

Choose a tag to compare

@conreo conreo released this 23 Sep 05:13

paperclip-codegraph v0.12.7

Install

npm install -g @colbymchenry/codegraph@1.6.0   # the CodeGraph CLI, if you do not have it
paperclipai plugin install paperclip-codegraph@0.12.7

Pin the version: Paperclip stores a caret range against what was installed, and for a
0.x version a caret does not cross a minor release, so a bare plugin install is a
no-op once the next minor is out.

The plugin installs disabled. Nothing changes for any agent until an organization
turns it on, in Settings → Plugins → CodeGraph.

The Exceptions panel told operators the wrong thing about their own decisions — and
missed the one state that matters.

What it said

On an organization where 20 agents had deliberately been left without an MCP client:

20 of 34 agents cannot receive these tools yet.
… Fix it per agent in its adapter settings, then restart that agent.

Every number was correct. The conclusion was not. Those 20 agents were a decision,
not a backlog — so the panel sent an operator looking for a fix nobody wanted, and it had
no way to say "this is already right".

The state it never looked for

Denying an agent here removes this plugin's tools. It does not remove the agent's
ability to start the organization's CodeGraph server itself, and that is a second,
separate path:

Path What it is Governed by Audited by
Plugin tools paperclip-codegraph:codegraph_search, via Paperclip's tool gateway the profile, per agent yes, every call
MCP server codegraph serve --mcp, spawned by the agent's own MCP client nothing no

A pi agent with --mcp-config therefore reads the codebase through a path this plugin
never sees — and if it is also switched off here, the switch appears to deny something
it does not deny. The panel never asked that question, so on this instance the state was
invisible: an agent could be revoked and fully reachable at the same time.

What it says now

  • The delivery warning is about MCP only, and says so: "N of M agents do not see
    CodeGraph under MCP."
    It then states what that agent can still do — "a missing
    convenience, not a missing capability"
    — because the plugin's own tools work with no
    MCP client at all. That was already true and the old copy implied the opposite by
    calling the state a failure.
  • A switched-off agent is no longer counted as a gap. Switching one off is the
    resolution, not the problem.
  • New: a switched-off agent that is still wired. Its own banner names the hole —
    those calls "never reach this plugin, so nothing here governs or records them" — and
    says what to do: remove the MCP client from the adapter as well. A client with no
    config is not flagged, because it names no server and every ambient discovery path is
    absent on a real host; that assumption is written down where it can be re-checked.
  • Per-row state is honest. A revoked agent on the MCP path reads "Revoked — but its
    adapter still reaches CodeGraph directly"
    rather than just "Revoked".

The counts moved into src/ui/exceptions.ts and are covered by tests/exceptions.spec.ts
(9 tests), because a rule that only exists as an inline filter can be changed without its
tests — which is how the false alarm survived this long.

How the claim was checked

The old copy claimed these agents "can still reach CodeGraph through the plugin API —
governed and audited". Rather than rewrite it on intuition, it was checked against the
running instance:

  • Paperclip documents POST /api/plugins/tools/execute as "the primary endpoint used by
    the agent service to invoke plugin tools during an agent run"
    , and it accepts agent
    identity.
  • The activity log holds 27 codegraph_tool_call rows attributed to an agent, plus
    tool_gateway.call_allowed / call_completed / call_denied records for
    paperclip-codegraph:codegraph_status|explore|node|search|files|callees|callers|impact.

So the sentence was true, the plugin path is real and does carry denials, and it is now
the part of the panel that stays.

Also in this release

The README gains "The third path, which nothing governs" — the first place this
plugin's documentation admits that a --mcp-config written into an agent's adapter
bypasses both Paperclip's gateway and this plugin. Anyone wiring agents up should know
that before they rely on a denial.