pi-extension-authoring

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install and update core ecosystem packages and SDKs from the official Pi agent registries, including @earendil-works/pi-coding-agent, pi-mcp-adapter, and pi-gitnexus.
  • [COMMAND_EXECUTION]: Utilizes standard development tools such as npm and bun for package management and rg for log analysis. It also uses the platform-specific pi CLI for extension validation and smoke-testing.
  • [INDIRECT_PROMPT_INJECTION]: Provides documentation and code patterns for utilizing extension hooks (before_agent_start) that allow developers to inject custom system prompts and messages.
  • Ingestion points: SKILL.md (contains implementation guidelines for session hooks).
  • Boundary markers: Absent (instructions are for technical implementation by developers).
  • Capability inventory: Shell commands for package installation, environment diagnostics (which, npm list), and agent execution (pi -p).
  • Sanitization: Absent (the documentation focuses on session state persistence and timing safety rather than content validation).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — pi-extension-authoring