pi-extension-authoring

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides various shell commands intended for extension development and maintenance. This includes environment validation using bun and ripgrep (rg), platform management via the pi CLI, and testing routines.
  • [EXTERNAL_DOWNLOADS]: It provides instructions to install and update several global Node.js packages from the npm registry, such as @earendil-works/pi-coding-agent, pi-mcp-adapter, and pi-gitnexus. These packages are central to the 'Pi' extension ecosystem documented in the skill.
  • [DATA_EXPOSURE]: The skill identifies ~/.pi/agent/settings.json as a primary configuration surface. While this path contains agent-specific configuration data, its inclusion is directly relevant to the skill's stated purpose of managing the extension environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 05:09 PM
Security Audit — agent-trust-hub — pi-extension-authoring