pi-agent

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The instructions describe the installation of the Pi Agent and its ecosystem via npm and a remote installation script from the product's official domain at https://pi.dev/install.sh.
  • [REMOTE_CODE_EXECUTION]: Documentation provides examples of executing remote scripts using curl | sh and installing packages via npm to set up the developer environment. These operations target the vendor's official infrastructure.
  • [DYNAMIC_EXECUTION]: The skill documents features allowing for dynamic code execution, such as the workflowScript global in the pi-subagents package for JavaScript-based orchestration and a !command syntax in configuration files for dynamic secret resolution. These are presented as intended functional features for automation.
  • [INDIRECT_PROMPT_INJECTION]: The skill documentation highlights a significant attack surface as the agent is designed to process external and untrusted data.
  • Ingestion points: Data enters the agent's context through web search results, PDF extraction, and code repository fetching tools (e.g., web_search, fetch_content).
  • Boundary markers: The harness employs structured message markers and XML-style formatting to help the model distinguish between system instructions, tool definitions, and external data.
  • Capability inventory: The agent possesses extensive capabilities including shell command execution (bash), file system modification (write, edit), and network connectivity.
  • Sanitization: The documentation explicitly warns users that prompt injection from repository files is a known risk and provides guidance on isolation strategies using containers or VMs for untrusted work.
  • [COMMAND_EXECUTION]: The agent is designed to execute local shell commands via a dedicated bash tool to perform development tasks such as linting, testing, and implementation.
  • [SAFE]: The skill includes a 'Project Trust' mechanism that prevents the automatic loading of project-local settings, extensions, or skills until the user has explicitly granted permission for the specific directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — pi-agent