Pi extension for explicit non-blocking background shell tasks, log tails, and completion wakeups.
LPM flags this version as an AI-agent control-surface risk. The automatic install hook modifies Pi's shared system instructions. Its fallback reaches the existing user-wide agent directory without an explicit setup action or consent gate.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json automatically runs the instruction-writing helper during postinstall.
package.jsonView on unpkg · L20Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe helper targets Pi's shared APPEND_SYSTEM.md rather than an extension-owned file.
scripts/append-system.mjsView on unpkg · L59The helper falls back to the existing user-wide Pi agent directory without requesting consent.
scripts/append-system.mjsView on unpkg · L100Installation reads package instructions and writes them into the shared system instruction file.
scripts/append-system.mjsView on unpkg · L70The inserted instructions direct the agent to change its shell tool usage.
instructions.mdView on unpkg · L3This report applies to @vanillagreen/pi-background-tasks@2.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Installation reads package instructions and writes them into the shared system instruction file.
scripts/append-system.mjsView on unpkg · L130Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L21Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L21package.json automatically runs the instruction-writing helper during postinstall.
package.jsonView on unpkg · L20The helper targets Pi's shared APPEND_SYSTEM.md rather than an extension-owned file.
scripts/append-system.mjsView on unpkg · L59Installation reads package instructions and writes them into the shared system instruction file.
scripts/append-system.mjsView on unpkg · L70The helper falls back to the existing user-wide Pi agent directory without requesting consent.
scripts/append-system.mjsView on unpkg · L100Installation reads package instructions and writes them into the shared system instruction file.
scripts/append-system.mjsView on unpkg · L130The inserted instructions direct the agent to change its shell tool usage.
instructions.mdView on unpkg · L3