ai-agentrapay-agentra declares 6 capabilities across 6 tools, with 3 critical issues.
43/100 exposureElevated
Manifest retrieved 2026-09-14 from tools/list on https://api.agentrapay.ai/mcp, published in the official MCP registry as ai.agentrapay/agentra 1.0.0. Not verified by a maintainer.
Issues
These describe what this server's manifest declares. A product can provide controls that MCP has no
way to express — token revocation, an admin console, audit logs — and this page cannot see them. The absence of a
declaration is not evidence that a control is absent.
critical · no-revocation · All 6 tools
6 of 6 tools declare no way for the customer to switch them off once granted. This applies to every tool because MCP has no field in which to declare a revocation mechanism; the product may provide one outside MCP that a manifest cannot show.
critical · irreversible-uncapped · 2 of 6 tools
2 tools are classified as irreversible and declare no limit.
critical · uncapped-spend · 1 of 6 tools
1 tool is classified as moving money and declares no dollar limit. A cap on the number of payments does not bound their amount.
high · no-expiry · All 6 tools
6 of 6 tools declare no expiry. This applies to every tool because MCP has no field in which to declare an expiry; the product may provide one outside MCP that a manifest cannot show.
high · no-audit-trail · All 6 tools
6 of 6 tools declare no record of their actions that the customer can read. This applies to every tool because MCP has no field in which to declare an audit requirement; the product may provide one outside MCP that a manifest cannot show.
high · uncapped-write · 1 of 6 tools
1 tool can modify data and declares no limit.
low · uncapped-read · 3 of 6 tools
3 tools can read data and declare no limit.
Declared capabilities
How each tool was read. declared means the server's own annotation said so — self-reported and
unverified. inferred is from the tool's name. assumed means nothing indicated either way.
Tool
Read as
Basis
agentra_create_wallet
write
inferred
agentra_verify_identity
read
inferred
agentra_check_reputation
read
declared
agentra_authorize_payment
pay
inferred
agentra_set_mandate
delete
declared
agentra_get_wallet
read
declared
Answering this question about your own agent? Media Yard LLC runs a
fixed-scope Agent Permission Audit: the same reading applied to your agent surface, delivered as a dated
artifact you can hand to a customer's security review. See what it includes and costs, or write to
support@leashkit.com.
Buying one does not change this page, its score or its place in the index — see Independence.
Maintain this server? If this page misreads your manifest, or your server has changed,
submit its current tools/list response and it will be re-scored and dated.
Corrections are published alongside the original, not in place of it.