pi-agent
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The instructions describe the installation of the Pi Agent and its ecosystem via npm and a remote installation script from the product's official domain at
https://pi.dev/install.sh. - [REMOTE_CODE_EXECUTION]: Documentation provides examples of executing remote scripts using
curl | shand installing packages vianpmto set up the developer environment. These operations target the vendor's official infrastructure. - [DYNAMIC_EXECUTION]: The skill documents features allowing for dynamic code execution, such as the
workflowScriptglobal in thepi-subagentspackage for JavaScript-based orchestration and a!commandsyntax in configuration files for dynamic secret resolution. These are presented as intended functional features for automation. - [INDIRECT_PROMPT_INJECTION]: The skill documentation highlights a significant attack surface as the agent is designed to process external and untrusted data.
- Ingestion points: Data enters the agent's context through web search results, PDF extraction, and code repository fetching tools (e.g.,
web_search,fetch_content). - Boundary markers: The harness employs structured message markers and XML-style formatting to help the model distinguish between system instructions, tool definitions, and external data.
- Capability inventory: The agent possesses extensive capabilities including shell command execution (
bash), file system modification (write,edit), and network connectivity. - Sanitization: The documentation explicitly warns users that prompt injection from repository files is a known risk and provides guidance on isolation strategies using containers or VMs for untrusted work.
- [COMMAND_EXECUTION]: The agent is designed to execute local shell commands via a dedicated
bashtool to perform development tasks such as linting, testing, and implementation. - [SAFE]: The skill includes a 'Project Trust' mechanism that prevents the automatic loading of project-local settings, extensions, or skills until the user has explicitly granted permission for the specific directory.
Audit Metadata