pi-extension-creator
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documents and provides examples for using the pi.exec and bash tools to interact with the host system. This is an intended feature for the development of coding extensions. * Evidence: Found in SKILL.md and references/api-surface.md as standard API calls.
- [INDIRECT_PROMPT_INJECTION]: The skill provides templates and patterns for building extensions that process untrusted data, which creates a potential attack surface for indirect prompt injection. * Ingestion points: assets/examples/subagent-workflow.md uses the $@ placeholder for user input in prompt templates. references/api-surface.md describes the pi.on("input", ...) event handler. * Boundary markers: Not explicitly enforced in the provided templates; developers are encouraged to use UI confirmation prompts for risky actions. * Capability inventory: Extensions have access to pi.exec, pi.registerTool, and file system operations. * Sanitization: The skill documentation recommends implementing policy modules (policy.ts) to classify and block dangerous commands.
- [SAFE]: The project includes a dedicated Python initialization script that implements security controls to prevent path traversal and symlink-based attacks during project setup. * Evidence: scripts/init_pi_extension.py contains the is_link and copy_template functions which verify that no symlinks or junctions are traversed and that the target directory does not overlap with the source.
Audit Metadata