pi-coding-agent

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [SAFE]: The skill consists entirely of technical documentation and user guides for the Pi Coding Agent software. It contains no executable scripts or malicious logic.- [EXTERNAL_DOWNLOADS]: The documentation describes standard software installation via the npm registry and a package management feature that allows users to fetch extensions from GitHub and remote URLs.- [COMMAND_EXECUTION]: The reference material details features that enable shell command execution, such as the !command syntax in configuration files for dynamic API key resolution and the agent's ability to run bash commands as part of its core developer toolset.- [REMOTE_CODE_EXECUTION]: The skill explains the tool's extensibility through TypeScript modules and Pi Packages, which involve loading and executing code locally for customization.- [DATA_EXFILTRATION]: The documentation mentions a feature for sharing session data by uploading it to GitHub Gists, documented as a legitimate collaboration tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 04:17 AM
Security Audit — agent-trust-hub — pi-coding-agent