packages / panzenbaby-pi-secure-extension
extension Guards & policy

@panzenbaby/pi-secure-extension

A Pi extension that performs security audits on other extensions before install or update. Uses the currently selected AI model to analyze extension source code against configurable audit rules.

No reviews yet

Install

$ pi install npm:@panzenbaby/pi-secure-extension

Installs from npm into ~/.pi/agent/. Add -l for project-local (.pi/). Manage with pi list / pi update / pi remove.

What this package can reach

Detected automatically from the source at version 0.1.3. This describes access, not safety — you decide whether it's appropriate for what the package claims to do.

  • 🤖
    Behavior — Changes how the agent thinks Modifies the system prompt, injects messages, or rewrites conversation context.
  • Commands — Runs shell commands Spawns processes on your machine.
  • 📁
    Files — Reads files outside your project Touches paths beyond the working directory, such as your home folder.
  • Keystrokes — Reads raw terminal input Hooks ui.onTerminalInput, so it sees what you type. Legitimate for shortcut handling; the same access a keylogger needs.
  • UI — Draws its own interface Renders widgets, footers, dialogs or full-screen views.

What it actually did when run

observed

Loaded in a sandbox with no network, a read-only filesystem and a recording stand-in for pi's API. This is what it called — not what the source suggests it might.

APIs called execexec.stdout.splitexec.stdout.split.mapexec.stdout.split.map.filterexec.stdout.split.map.filter.mapexec.stdout.split.map.filter.map.mapexec.stdout.split.map.filter.map.map.filterregisterCommandregisterMessageRendererui.notifyui.selectui.setStatusui.setWorkingMessage

6 calls the source scan did not predict

exec.stdout.split · exec.stdout.split.map · exec.stdout.split.map.filter · exec.stdout.split.map.filter.map · exec.stdout.split.map.filter.map.map · exec.stdout.split.map.filter.map.map.filter

Reached through a value the scan could not follow — passed as an argument, stored on another object, or returned by a helper.

Run against version 0.1.3 on 2026-08-02. Registration-time behaviour under default settings; other configurations may differ.

Review before you install. pi packages run with your full system permissions. Check the source, pin versions, and prefer authors you trust.

Reviews

0 published

Sign in with GitHub to write a review, reply, or vote.

No reviews yet — be the first.

More in Guards & policy