pi-package-authoring

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an external repository at https://github.com/badlogic/pi-mono for project grounding and documentation. This reference is consistent with the skill's primary purpose of providing guidelines for the pi-mono framework.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes workflows involving the ingestion and validation of external package.json manifests and documentation files. While this creates an ingestion surface for potentially untrusted data, the skill does not perform any unsafe operations or command execution using this data, and it explicitly highlights security considerations for third-party packages.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:38 PM
Security Audit — agent-trust-hub — pi-package-authoring