pi-customization

Pass

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill documents features for overriding or appending to the system prompt via project-local files (.pi/SYSTEM.md, APPEND_SYSTEM.md). This allows instructions stored within a repository to influence the agent's core behavior. Ingestion points: Project-specific configuration files including .pi/SYSTEM.md, APPEND_SYSTEM.md, and prompt templates in .pi/prompts/. Boundary markers: The instructions do not specify any delimiters or safety warnings to prevent the agent from obeying embedded instructions in these files. Capability inventory: The Pi coding agent (the target of these configurations) typically operates with terminal and filesystem access. Sanitization: No sanitization or validation of the content of these system prompt overrides is described.
  • [EXTERNAL_DOWNLOADS]: The skill references technical documentation and the verified source tree of the badlogic/pi-mono GitHub repository for grounding and behavioral verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 13, 2026, 09:26 PM