Personal pi coding agent toolkit: /todos, /btw, /cache_export and apply_patch extensions, browser automation, and bundled theme/skills.
LPM flags this version as an AI-agent control-surface risk. Installation replaces global Pi agent instructions with package-supplied behavioral rules. Existing user instructions are overwritten without consent.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgPackage source references child process execution.
packages/cache-export/tests/e2e-browser.mjsView on unpkg · L12Source file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/cache-export/tests/e2e-browser.mjsView on unpkgPackage source references shell execution.
skills/web-browser/scripts/start.jsView on unpkg · L61A single source file combines environment access, network access, and code or shell execution; review context before blocking.
skills/chrome-cdp/scripts/cdp.mjsView on unpkg · L12Source file is highly similar to a previously finalized malicious package; route for source-aware review.
skills/chrome-cdp/scripts/cdp.mjsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install-agents.mjsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
packages/worktree/bin/pi-worktree-completion.bashView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
packages/worktree/tests/run-tests.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
packages/worktree/bin/pi-worktreeView on unpkgThis report applies to @maxiaochao/pi-toolkit@0.9.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L64Package ships non-JavaScript build or shell helper files.
packages/worktree/bin/pi-worktree-completion.bashView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
packages/worktree/tests/run-tests.shView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
packages/worktree/bin/pi-worktreeView on unpkgPackage source references child process execution.
packages/cache-export/tests/e2e-browser.mjsView on unpkg · L12Source file is highly similar to a previously finalized malicious package; route for source-aware review.
packages/cache-export/tests/e2e-browser.mjsView on unpkgPackage source references shell execution.
skills/web-browser/scripts/start.jsView on unpkg · L61A single source file combines environment access, network access, and code or shell execution; review context before blocking.
skills/chrome-cdp/scripts/cdp.mjsView on unpkg · L12Source file is highly similar to a previously finalized malicious package; route for source-aware review.
skills/chrome-cdp/scripts/cdp.mjsView on unpkgSource creates an unconsented AI-agent control surface through install-time mutation or a default unauthenticated remote skill channel.
scripts/install-agents.mjsView on unpkg · L1