RRa PayRa Pay AI is the first AI native payment primitive for AI Agents that uses CLI as its distribution layer and a MCP server for AI Agent automation while keeping humans in control. Ra Pay AI's terminal architecture delivers superior privacy, AI token costs and reduced prompt injection attack surface compared to browser GUI based AI Agent payment applications. Yes, we just solved AI Payments using the terminal as our distribution layer. We did it first. For every computer on earth. Use Ra Pay AI to keep an eye on your payment privacy and your AI token costs. Join us. npm install -g @rapay/cli
mcp-so:ra-pay_Ra Pay AI
View sourceFirst Seen
Feb 18, 2026
Last Scanned
Feb 18, 2026
Findings
3
Score
92/100
Findings (3)
Detects -y, --yes, or --auto-approve flags in MCP/skill install commands that bypass user confirmation
"-y" Remove the -y/--yes auto-confirm flag from MCP server launch arguments. This flag bypasses user confirmation prompts and allows unattended execution of potentially dangerous operations.
Likely FP if the matched text is an isolated flag (-y or --yes) in documentation describing command-line options, not in an actual MCP config.
Detects global installation of packages which affects the host system
npm install -g @ Replace npm install -g with a local install (npm install --save-dev) or use npx with a pinned version. Global installs modify the system and risk supply chain attacks.
Likely FP if the global install is for a well-known CLI tool (e.g., typescript, eslint) in setup documentation, though the supply chain risk remains real.
Detects MCP server configs using npx to run packages without version pinning
"command": "npx" Pin the npx package in the MCP config to an exact version (e.g., @scope/server@1.2.3). Unpinned npx commands can silently fetch a compromised package version.
Likely FP if the MCP config is a local development setup example, though unpinned npx in production configs is a real supply chain risk.