pi-workspace-extensions

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the mise task runner to manage workspace extensions. It provides specific shell commands to list the catalog (mise run extensions -- --target <path>) and install selected packages (mise run extensions -- --install <packages>). These operations are confined to the workspace directory structures .pi/skills/pi-workspace or .agents/skills/pi-workspace.
  • [EXTERNAL_DOWNLOADS]: The installation process involves the pi install CLI or mise tasks, which fetch extension packages (such as pi-subagents, context-mode, and pi-lens) from the associated ecosystem. These downloads are restricted to a local project scope (-l) rather than a global user scope.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 09:26 AM