@panzenbaby/pi-secure-extension
A Pi extension that performs security audits on other extensions before install or update. Uses the currently selected AI model to analyze extension source code against configurable audit rules.
Install
pi install npm:@panzenbaby/pi-secure-extension
Installs from npm into ~/.pi/agent/.
Add -l for project-local (.pi/). Manage with pi list / pi update / pi remove.
What this package can reach
Detected automatically from the source at
version 0.1.3.
This describes access, not safety — you decide whether it's appropriate for what
the package claims to do.
- Behavior — Changes how the agent thinks Modifies the system prompt, injects messages, or rewrites conversation context.
- Commands — Runs shell commands Spawns processes on your machine.
- Files — Reads files outside your project Touches paths beyond the working directory, such as your home folder.
- Keystrokes — Reads raw terminal input Hooks ui.onTerminalInput, so it sees what you type. Legitimate for shortcut handling; the same access a keylogger needs.
- UI — Draws its own interface Renders widgets, footers, dialogs or full-screen views.
What it actually did when run
observedLoaded in a sandbox with no network, a read-only filesystem and a recording stand-in for pi's API. This is what it called — not what the source suggests it might.
APIs called execexec.stdout.splitexec.stdout.split.mapexec.stdout.split.map.filterexec.stdout.split.map.filter.mapexec.stdout.split.map.filter.map.mapexec.stdout.split.map.filter.map.map.filterregisterCommandregisterMessageRendererui.notifyui.selectui.setStatusui.setWorkingMessage
6 calls the source scan did not predict
exec.stdout.split · exec.stdout.split.map · exec.stdout.split.map.filter · exec.stdout.split.map.filter.map · exec.stdout.split.map.filter.map.map · exec.stdout.split.map.filter.map.map.filter
Reached through a value the scan could not follow — passed as an argument, stored on another object, or returned by a helper.
Run against version 0.1.3 on 2026-08-02.
Registration-time behaviour under default settings; other configurations may differ.
Reviews
0 publishedSign in with GitHub to write a review, reply, or vote.
No reviews yet — be the first.
More in Guards & policy
- @yevhen.b/pi-preflight — Tool-call approvals and policy rules for Pi.
- pi-thegreataxios-staples — Personal staple extension for pi coding-agent — protected paths
- @tangle-network/tcloud-agent — Agent run-loop primitive over Tangle sandbox transports — runs an AgentProfile against a b…
- @yoseph_23/implannotator — Approval-gated frontend implementation for Pi, combining Implannotator design guidance wit…