cali-product-business-models
Warn
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Several reference files (e.g.,
safe-change.md,codequality-review.md, andtodo.md) instruct users to download and install tools from third-party GitHub repositories and NPM packages. Mentioned sources includegithub.com/PriNova/pi-agent-codebase-workflows,github.com/cursor/plugins, and NPM packages like@juicesharp/rpiv-todoand@plannotator/pi-extension, which are not from verified trusted organizations. - [COMMAND_EXECUTION]: The documentation provides shell commands for installing these external dependencies, such as
pi install git:github.com/cursor/pluginsandnpx skills add Prinova/pi-agent-codebase-workflows -a <cli> -g. The use of the-g(global) flag indicates that these installations modify the global system environment.
Audit Metadata