pi-extension-creator

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents and provides examples for using the pi.exec and bash tools to interact with the host system. This is an intended feature for the development of coding extensions. * Evidence: Found in SKILL.md and references/api-surface.md as standard API calls.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides templates and patterns for building extensions that process untrusted data, which creates a potential attack surface for indirect prompt injection. * Ingestion points: assets/examples/subagent-workflow.md uses the $@ placeholder for user input in prompt templates. references/api-surface.md describes the pi.on("input", ...) event handler. * Boundary markers: Not explicitly enforced in the provided templates; developers are encouraged to use UI confirmation prompts for risky actions. * Capability inventory: Extensions have access to pi.exec, pi.registerTool, and file system operations. * Sanitization: The skill documentation recommends implementing policy modules (policy.ts) to classify and block dangerous commands.
  • [SAFE]: The project includes a dedicated Python initialization script that implements security controls to prevent path traversal and symlink-based attacks during project setup. * Evidence: scripts/init_pi_extension.py contains the is_link and copy_template functions which verify that no symlinks or junctions are traversed and that the target directory does not overlap with the source.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:21 PM
Security Audit — agent-trust-hub — pi-extension-creator