pi-coding-agent

Warn

Audited by Snyk on Mar 19, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill auto-discovers and loads untrusted third-party packages and content (e.g., "pi install git:github.com/user/repo", "pi install https://github.com/user/repo", plus auto-discovered skills/extensions/prompts from ~/.pi/agent/skills, .pi/skills/, and concatenated AGENTS.md files in parent directories) which are ingested at runtime and can be executed (packages "run with full system access" and skills/extensions can change agent behavior), enabling indirect prompt injection.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 19, 2026, 02:30 PM
Issues
1
Security Audit — snyk — pi-coding-agent