GLM 5.2 and Qwen 3.5 provider for pi-coding-agent via a GigaChat-compatible API
LPM treats this as warn-only first-party agent extension lifecycle risk. The npm postinstall hook changes the Pi agent’s default provider and model. This is a package-owned Pi setup action; no confirmed malicious behavior was identified.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe postinstall hook runs automatically and reads the user’s Pi agent settings path.
package.jsonView on unpkg · L45The hook writes a default provider and model to Pi settings, which is a first-party package-owned agent setup.
scripts/postinstall.mjsView on unpkg · L7The package registers its provider and command through Pi’s extension entrypoint.
dist/auth.jsView on unpkg · L5This report applies to @dev-sergeev/pi-gigachat@0.5.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L50Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L50The postinstall hook runs automatically and reads the user’s Pi agent settings path.
package.jsonView on unpkg · L45The hook writes a default provider and model to Pi settings, which is a first-party package-owned agent setup.
scripts/postinstall.mjsView on unpkg · L7The package registers its provider and command through Pi’s extension entrypoint.
dist/auth.jsView on unpkg · L5