Loading npm security reports…
Declarative, user-definable permission modes for the pi coding agent: OS-level sandboxing (bubblewrap / sandbox-exec), an allow/ask/deny policy engine, real bash AST gating (tree-sitter), tool hiding, and skill/custom-tool gating.
Static analysis flagged 7 finding(s) at 72.0% confidence. This version is warn-only unless an AI or security-team review confirms malicious behavior.
Package defines install-time lifecycle scripts.
Source writes installer persistence such as shell profile or service configuration.
src/paths.test.tsView on unpkg · L51Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L45Source writes installer persistence such as shell profile or service configuration.
src/paths.test.tsView on unpkg · L51