pi-package-authoring
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references an external repository at https://github.com/badlogic/pi-mono for project grounding and documentation. This reference is consistent with the skill's primary purpose of providing guidelines for the pi-mono framework.
- [INDIRECT_PROMPT_INJECTION]: The skill describes workflows involving the ingestion and validation of external
package.jsonmanifests and documentation files. While this creates an ingestion surface for potentially untrusted data, the skill does not perform any unsafe operations or command execution using this data, and it explicitly highlights security considerations for third-party packages.
Audit Metadata