Orchesis is an open-source HTTP proxy that sits between Paperclip agents and LLM APIs to detect loops at API call #3, scan for injection on every request, and meter real costs independently of what the agent reports.
12 attack surfaces · $0.05 loop catch · 0 Paperclip security docs · 96% injection detected
Each one has an issue number.
Works with Claude Code, Codex, Cursor, and OpenClaw adapters.
Orchesis covers 9. Five surfaces have zero protection from any tool.
5 surfaces marked "Blind spot" require fixes in Paperclip itself. We report these through responsible disclosure, not marketing.
Methods and assumptions are published.
Also available: See our OpenClaw integration →
Nobody else in this space does this. You need them to make real security decisions.
won't tell you.
Works whether AI wins or loses.