Back to skill

Security audit

Pi Coding Agent

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only guide for Pi Coding Agent; it does not ship executable payloads, but Pi itself can run commands, use credentials, store sessions, and share data when configured.

Install this skill only if you want guidance for Pi Coding Agent. Before following its commands, audit the external npm package and any Pi Packages or Extensions you install, protect API keys and auth.json, review session contents before using /share, and use controls like --no-tools, --no-extensions, --no-skills, PI_OFFLINE, and PI_TELEMETRY=0 when you need tighter boundaries.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · references/extensions.md (reported line 69)May include surrounding context.

md
pi.registerFlag("my-flag", { description })
  pi.registerProvider("provider-name", { baseUrl, apiKey, api, models })
  pi.on("event_name", async (event, ctx) => {...})
  pi.sendMessage(text)                    // send message to agent
  pi.sendImage(text, { type:"image", data, mimeType })
  pi.appendEntry({ type, data })          // persist extension state
  pi.setThinkingLevel("high")

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description is written as a broad, general-purpose programming assistant with no clear activation boundaries or task constraints. In agent ecosystems that auto-load or suggest skills from natural-language descriptions, this can cause over-triggering, making the skill influence unrelated tasks and expanding the trusted instruction surface unnecessarily.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The Use Cases section is extremely expansive ('installation, configuration, model switching, extension development, session management, RPC/SDK integration, and more'), which effectively positions the skill as relevant to almost any Pi-related engineering task. This increases the chance of unnecessary invocation and prompt-surface takeover, especially because the skill also references powerful extensibility and package-installation features that can affect system behavior.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/ai.md (reported line 46)May include surrounding context.

md
{
  "providers": {
    "my-provider": {
      "baseURL": "https://api.example.com/v1",
      "apiKey": "${MY_API_KEY}",
      "models": ["model-a", "model-b"]
    }

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file describes including file contents in prompts via the @ prefix and earlier lists built-in tools such as bash, edit, and write, but it does not provide any user warning that file contents may be transmitted to a model/provider or that tools may modify the local system. For markdown files, SQP-2 applies when the description omits warnings about behaviors that could affect user data, privacy, or system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The /share command is documented only as uploading to GitHub Gist for sharing, without a prominent warning that session content may contain source code, secrets, tokens, internal paths, or proprietary data. In a coding-agent context, users may invoke this command on sensitive sessions and unintentionally exfiltrate confidential information to a third-party service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document instructs users to place provider credentials in environment variables and ~/.pi/agent/auth.json but gives no guidance on sensitivity, least-privilege handling, avoiding source control, rotation, or secure storage. In an AI coding assistant context that may inspect files, run tools, and operate in developer environments, weak credential-handling guidance increases the likelihood of accidental exposure and downstream account compromise.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly permits auth.json entries to be shell commands prefixed with !, which will be executed to obtain API keys. Because this configuration file may be edited, synced, templated, or influenced by untrusted content, it creates a command-execution path in a sensitive authentication workflow and can lead to local code execution, credential theft, or persistence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file documents safety-relevant operations including executing shell commands and exporting files, but it does not include any caution about command side effects, filesystem writes, or the risk of running untrusted input. Under the markdown criteria for SQP-2, descriptions should warn users when behavior can affect system integrity or user data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation advertises a /share command that uploads session content to GitHub Gist but provides no warning that prompts, code, secrets, file paths, or other sensitive conversation data may be exposed externally. In an AI coding assistant context, sessions commonly contain proprietary source code and credentials, so omission of a clear privacy warning materially increases the risk of accidental data disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown documents !command and !!command as shortcuts to execute bash commands, including one variant that also sends output to the LLM. This describes a safety-relevant behavior affecting system integrity and potentially privacy, but the file provides no caution or warning to users about command effects or data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file documents two debugging commands that write captured ANSI output and debug logs to /tmp/tui-ansi.log and ~/.pi/agent/pi-debug.log. Because debug logs may contain sensitive terminal content or user data, the skill description should explicitly warn users before recommending these logging actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents enableInstallTelemetry: true as a main setting but does not warn that telemetry may transmit usage or system-related data. For markdown files, safety-relevant behaviors affecting privacy should be accompanied by a clear warning or disclosure.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
2% confidence
Finding

This markdown file documents provider authentication methods and configuration examples, but it does not describe skill activation phrases or invocation conditions. Because SQP-1 applies only to vague triggers, there is no concrete ambiguous trigger language to flag in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file describes the on-disk JSONL session format, including saved message content, summaries, and bash execution output, but does not include any user warning about local persistence of potentially sensitive conversation and system data. For a markdown file, omission of a privacy/data-handling warning for stored session contents matches the missing user warnings category.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file states that sessions are auto-saved under ~/.pi/agent/sessions/ but does not warn users that conversation history is persisted locally by default. Because coding-assistant sessions often include source code, tokens, commands, and internal paths, users may unintentionally leave sensitive artifacts on disk, especially on shared or managed systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.