Manage agentic work across repositories with durable workbases
LPM treats this as warn-only first-party agent extension lifecycle risk. A postinstall hook places an Agency extension in the user's Pi agent extension directory. In a validated Agency workbase, that extension augments Pi's system prompt with local instructions.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage source references dynamic require/import behavior.
src/utils/interactive-loader.tsView on unpkg · L3A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
fixtures/protocol/error.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/services/ReviewService.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
pi-extensions/agency.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/services/TaskService.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/services/VersionControlService.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/utils/chooser.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/utils/process.tsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L71Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L71A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
fixtures/protocol/error.jsonView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/services/ReviewService.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
pi-extensions/agency.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/services/TaskService.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/services/VersionControlService.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/utils/chooser.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/utils/process.tsView on unpkgPackage source references dynamic require/import behavior.
src/utils/interactive-loader.tsView on unpkg · L3