Personal pi coding agent toolkit: /todos extension + /cache_export interactive cache dashboard.
LPM flags this version as an AI-agent control-surface risk. Installing the package replaces the user's global Pi agent instructions with package-controlled content. This affects future agent behavior outside the installed project.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe manifest automatically runs an install hook.
package.jsonView on unpkg · L37Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install-agents.mjsView on unpkg · L1The install hook overwrites the user's global Pi agent instruction file.
scripts/install-agents.mjsView on unpkg · L8The replacement content is bundled as a global AGENTS.md file.
global/AGENTS.mdView on unpkg · L1This report applies to @maxiaochao/pi-toolkit@0.1.8.
See version security history for other recorded verdicts.
Evidence last updated: .
The manifest automatically runs an install hook.
package.jsonView on unpkg · L37Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L40The replacement content is bundled as a global AGENTS.md file.
global/AGENTS.mdView on unpkg · L1Source creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install-agents.mjsView on unpkg · L1The install hook overwrites the user's global Pi agent instruction file.
scripts/install-agents.mjsView on unpkg · L8