Pi extension and CLI for controlling visible interactive Pi sessions over a structured Unix-socket side channel.
LPM flags this version as an AI-agent control-surface risk. An automatic npm postinstall modifies Pi’s shared agent instructions. The fallback reaches an existing user-wide agent directory rather than a package-owned configuration file.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource matches reverse-shell style process and socket wiring.
tests/client-backpressure.test.tsView on unpkg · L2Package source references child process execution.
tests/client-backpressure.test.tsView on unpkg · L6Package source references dynamic require/import behavior.
bin/pi-bridge.jsView on unpkg · L6A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
extensions/event-history.tsView on unpkgThis report applies to @vanillagreen/pi-session-bridge@3.0.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L29Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L29A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
extensions/event-history.tsView on unpkgPackage source references child process execution.
tests/client-backpressure.test.tsView on unpkg · L6Source matches reverse-shell style process and socket wiring.
tests/client-backpressure.test.tsView on unpkg · L2Package source references dynamic require/import behavior.
bin/pi-bridge.jsView on unpkg · L6