All-in-one multi-agent orchestration for the Pi coding agent — parallel teammate dispatch, goals, plans, knowledge system, MCP/LSP/browser, and cockpit visualization in a single install
LPM treats this as warn-only first-party agent extension lifecycle risk. The automatic postinstall hook modifies Pi agent configuration and installs Maestro workflows, then registers companion packages in Pi settings. This is first-party package-owned agent setup and warrants a warning under the review policy.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgPackage source references child process execution.
scripts/install-workflows.mjsView on unpkg · L5Package source references a known benign dynamic code generation pattern.
optional/browser-bridge/background.jsView on unpkg · L72Package source references dynamic require/import behavior.
scripts/simulate-272k-stuck.mjsView on unpkg · L24Package source references weak cryptographic algorithms.
src/tools/browser/manager.tsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/mcpx-bridge.tsView on unpkg · L15Source reaches cloud instance metadata or link-local credential endpoints.
src/mcpx-bridge.tsView on unpkg · L15Package ships non-JavaScript build or shell helper files.
optional/skills/scholar-thesis-docx/scripts/audit_docx_ooxml.pyView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.pi/skills/team-swarm/scripts/test_aco.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/mcp/host-html-template.ts#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/session/markdown-review.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/lsp/client.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/settings/explore-settings-provider.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/settings/hooks-settings-provider.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/settings/vision-delegation-provider.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/providers/prompt-cache-policy.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/computer-use/platform/linux.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/lsp-tool.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/web-access/credential-source.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/mcp/utils.tsView on unpkgThis report applies to pi-maestro-flow@0.23.0.
See version security history for other recorded verdicts.
Evidence last updated: .
This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/mcpx-bridge.tsView on unpkgPackage defines install-time lifecycle scripts.
package.jsonView on unpkg · L10Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L10Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgPackage source references weak cryptographic algorithms.
src/tools/browser/manager.tsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
optional/skills/scholar-thesis-docx/scripts/audit_docx_ooxml.pyView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.pi/skills/team-swarm/scripts/test_aco.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/mcp/host-html-template.ts#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/session/markdown-review.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/lsp/client.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/settings/explore-settings-provider.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/settings/hooks-settings-provider.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/settings/vision-delegation-provider.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/providers/prompt-cache-policy.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/computer-use/platform/linux.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/lsp-tool.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/web-access/credential-source.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/mcp/utils.tsView on unpkgPackage source references child process execution.
scripts/install-workflows.mjsView on unpkg · L5Package source references a known benign dynamic code generation pattern.
optional/browser-bridge/background.jsView on unpkg · L72Package source references dynamic require/import behavior.
scripts/simulate-272k-stuck.mjsView on unpkg · L24A single source file combines environment access, network access, and code or shell execution; review context before blocking.
src/mcpx-bridge.tsView on unpkg · L15Source reaches cloud instance metadata or link-local credential endpoints.
src/mcpx-bridge.tsView on unpkg · L15This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
src/mcpx-bridge.tsView on unpkg