GLM 5.2 and Qwen 3.5 provider for pi-coding-agent via a GigaChat-compatible API
LPM flags this version as an AI-agent control-surface risk. Installation changes the shared Pi agent's default provider and model without an opt-in check. This modifies a foreign agent control surface beyond the package's own extension files.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json automatically runs scripts/postinstall.mjs after installation.
package.jsonView on unpkg · L50Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe hook targets the shared Pi agent settings directory, defaulting to ~/.pi/agent.
scripts/postinstall.mjsView on unpkg · L7The hook unconditionally replaces the default provider and model with gigachat and Qwen3.5-397b.
scripts/postinstall.mjsView on unpkg · L23This report applies to @dev-sergeev/pi-gigachat@0.4.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L50Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L50package.json automatically runs scripts/postinstall.mjs after installation.
package.jsonView on unpkg · L50The hook targets the shared Pi agent settings directory, defaulting to ~/.pi/agent.
scripts/postinstall.mjsView on unpkg · L7The hook unconditionally replaces the default provider and model with gigachat and Qwen3.5-397b.
scripts/postinstall.mjsView on unpkg · L23