
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@papi-ai/server
Advanced tools
PAPI MCP server — AI-powered sprint planning, build execution, and strategy review for software projects
Structured planning for AI-assisted development. PAPI gives Claude Code a persistent planning layer — every cycle builds on the last, so your project gets smarter over time instead of starting fresh every session.
Takes about 2 minutes.
.mcp.json snippet.mcp.json in your project rootrun setup, then run planThat's it. You're planning.
| Without PAPI | With PAPI |
|---|---|
| Start every session by re-explaining the project | Orient in one call — cycle state, next action, blocked tasks |
| Tasks grow in scope mid-build | BUILD HANDOFFs define scope boundary and acceptance criteria upfront |
| Architectural decisions get forgotten | Active Decisions persist across cycles with confidence levels |
| No way to know if you're going faster or slower | Estimation accuracy tracked every cycle |
PAPI collects anonymous usage data (tool name, duration, project UUID — no code or task content). To opt out, add PAPI_TELEMETRY=off to your .mcp.json env block.
PAPI is configured with PAPI_PROJECT_ID and PAPI_DATA_API_KEY — both are generated by the onboarding wizard at getpapi.ai and pasted into your .mcp.json. If those env vars aren't set, PAPI will fall back to local file storage (md mode) and emit a stderr warning that your cycles aren't visible on the dashboard. To get on the dashboard, sign up at getpapi.ai and use the config it gives you.
Elastic License 2.0 — free to use, self-host, and modify. Commercial hosting requires a license.
FAQs
PAPI MCP server — AI-powered sprint planning, build execution, and strategy review for software projects
The npm package @papi-ai/server receives a total of 902 weekly downloads. As such, @papi-ai/server popularity was classified as not popular.
We found that @papi-ai/server demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.