All-in-one multi-agent orchestration for the Pi coding agent — parallel teammate dispatch, goals, plans, knowledge system, MCP/LSP/browser, and cockpit visualization in a single install
LPM flags this version as an AI-agent control-surface risk. Installing the package automatically modifies global Pi-agent configuration and installs Maestro workflows. These changes enable companion packages in an agent-wide control surface.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgInstall-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgPackage manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkgPackage source references a known benign dynamic code generation pattern.
optional/browser-bridge/background.jsView on unpkg · L197Package source references dynamic require/import behavior.
scripts/simulate-272k-stuck.mjsView on unpkg · L24Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/browser/manager.tsView on unpkgPackage source references weak cryptographic algorithms.
src/tools/browser/manager.tsView on unpkg · L1Source reaches cloud instance metadata or link-local credential endpoints.
src/mcpx-bridge.tsView on unpkg · L9Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/mcpx-bridge.tsView on unpkgPackage ships non-JavaScript build or shell helper files.
optional/skills/scholar-thesis-docx/scripts/audit_docx_ooxml.pyView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.pi/skills/team-swarm/scripts/test_aco.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/mcp/host-html-template.ts#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/gateway/pi-config-apply.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/smart-search.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/gateway/private-state-transaction.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/gateway/resident-service.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/gateway/services/exec-service.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/session/markdown-review.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/bash-bg.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/lsp/client.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/web-access/chrome-cookies.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/gateway/services/job-service.tsView on unpkgThis report applies to pi-maestro-flow@0.30.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Package manifest contains a dependency pinned to a remote tarball URL.
package.jsonView on unpkg · L12Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L13Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkg · L13Package source references weak cryptographic algorithms.
src/tools/browser/manager.tsView on unpkg · L1Package ships non-JavaScript build or shell helper files.
optional/skills/scholar-thesis-docx/scripts/audit_docx_ooxml.pyView on unpkgPackage hides binary, compressed, or executable-looking payloads in test/fixture/hidden paths.
.pi/skills/team-swarm/scripts/test_aco.pyView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
src/mcp/host-html-template.ts#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/gateway/pi-config-apply.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/smart-search.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/gateway/private-state-transaction.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/gateway/resident-service.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/gateway/services/exec-service.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/session/markdown-review.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/bash-bg.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/lsp/client.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/web-access/chrome-cookies.tsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
src/gateway/services/job-service.tsView on unpkgPackage source references a known benign dynamic code generation pattern.
optional/browser-bridge/background.jsView on unpkg · L197Package source references dynamic require/import behavior.
scripts/simulate-272k-stuck.mjsView on unpkg · L24Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/tools/browser/manager.tsView on unpkgSource reaches cloud instance metadata or link-local credential endpoints.
src/mcpx-bridge.tsView on unpkg · L9Source file is highly similar to a previously finalized malicious package; route for source-aware review.
src/mcpx-bridge.tsView on unpkg