GigaChat provider extension for pi-coding-agent
No confirmed malicious attack surface is established. The extension sends chat data and credentials only when used as the configured GigaChat provider.
The AI recommended clean, but the final policy action is warn. This report does not record a matching static-policy override reason.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
extension.jsView on unpkg · L52The runtime posts the converted conversation and supplied bearer token to a GigaChat completion endpoint.
extension.jsView on unpkg · L702OAuth exchanges send user-supplied credentials to the declared GigaChat authentication endpoint.
extension.jsView on unpkg · L172A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkgThe package registers a Pi provider extension, which the Pi host can load.
package.jsonView on unpkg · L55This report applies to @dev-sergeev/pi-gigachat@0.2.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
extension.jsView on unpkg · L52OAuth exchanges send user-supplied credentials to the declared GigaChat authentication endpoint.
extension.jsView on unpkg · L172The runtime posts the converted conversation and supplied bearer token to a GigaChat completion endpoint.
extension.jsView on unpkg · L702The package registers a Pi provider extension, which the Pi host can load.
package.jsonView on unpkg · L55A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
package.jsonView on unpkg