
Security News
GPT-6 Astra Attempts Supply Chain Attacks Against Open Source Maintainers in Testing
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.
@papi-ai/server
Advanced tools
PAPI MCP server — AI-powered sprint planning, build execution, and strategy review for software projects
Structured planning for AI-assisted development. PAPI gives Claude Code a persistent planning layer — every cycle builds on the last, so your project gets smarter over time instead of starting fresh every session.
Takes about 2 minutes.
.mcp.json snippet.mcp.json in your project rootrun setup, then run planThat's it. You're planning.
| Without PAPI | With PAPI |
|---|---|
| Start every session by re-explaining the project | Orient in one call — cycle state, next action, blocked tasks |
| Tasks grow in scope mid-build | BUILD HANDOFFs define scope boundary and acceptance criteria upfront |
| Architectural decisions get forgotten | Active Decisions persist across cycles with confidence levels |
| No way to know if you're going faster or slower | Estimation accuracy tracked every cycle |
PAPI collects anonymous usage data (tool name, duration, project UUID — no code or task content). To opt out, add PAPI_TELEMETRY=off to your .mcp.json env block.
PAPI is configured with PAPI_PROJECT_ID and PAPI_DATA_API_KEY — both are generated by the onboarding wizard at getpapi.ai and pasted into your .mcp.json. If those env vars aren't set, PAPI will fall back to local file storage (md mode) and emit a stderr warning that your cycles aren't visible on the dashboard. To get on the dashboard, sign up at getpapi.ai and use the config it gives you.
The stdio server exits cleanly after two minutes without input, including its
database adapter pool, so abandoned client sessions do not accumulate. Set
PAPI_STDIO_IDLE_TIMEOUT_MS=0 to disable this behavior, or provide another
non-negative millisecond value in the .mcp.json environment block. This
setting applies only to stdio mode; hosted HTTP instances are not idle-killed.
Elastic License 2.0 — free to use, self-host, and modify. Commercial hosting requires a license.
FAQs
PAPI MCP server — AI-powered sprint planning, build execution, and strategy review for software projects
The npm package @papi-ai/server receives a total of 640 weekly downloads. As such, @papi-ai/server popularity was classified as not popular.
We found that @papi-ai/server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
GPT-6 Astra hits 100% on ExploitBench and finds zero-days autonomously, while independent tests reveal scope violations and monitoring gaps.

Product
Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel.

Security News
pnpm 12 rewrites the package manager in Rust, cutting install times by up to 90% while preserving pnpm 11 workflows and lockfiles.