@oh-my-pi/pi-coding-agent
Coding agent CLI with read, bash, edit, write tools and session management
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:highlight.js | AI (phantom-deps): Used via config/build tooling, not a direct import; benign. | ai | |
| phantom-deps | phantom-dep:ndjson | AI (phantom-deps): Used via config/build tooling, not a direct import; benign. | ai | |
| source-diff | net-exec-file:src/vendor/photon/index.js | AI (source-diff): Generated wasm-bindgen glue code, not a dropper/loader. | ai | |
| source-diff | obfuscated-file:src/vendor/photon/photon_rs_bg.wasm.b64.js | AI (source-diff): wasm-bindgen base64-embedded binary for photon image lib, not obfuscation. | ai | |
| source-diff | encoded-string-file:dist/cli.js | AI (source-diff): Bundled agent CLI; strings are prompt/tool-call templates, no observed exfil behavior. | ai | |
| dependencies | unvetted-dep:@oh-my-pi/pi-catalog | AI (dependencies): First-party monorepo sibling package pinned to same version. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-autocomplete | AI (phantom-deps): oclif plugin declared in config; stable pattern for this CLI framework. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Feature expansion (browser automation, docs) explains large new file count, no malicious content found. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps match browser-automation/HTML-parsing feature set of the agent. | ai | |
| dependencies | unvetted-dep:@oh-my-pi/pi-mnemopi | AI (dependencies): Own scoped sibling package pinned to same version. | ai | |
| dependencies | unvetted-dep:handlebars | AI (dependencies): Established templating lib; benign for this agent. | ai | |
| provenance | publisher-changed | AI (provenance): Manual→GitHub Actions CI/CD with SLSA attestation; legitimate maintainer/CI transition. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/api | AI (phantom-deps): Used via config/instrumentation wiring, common for OTel setup. | ai | |
| source-diff | net-exec-file:dist/cli.js | AI (source-diff): Bundled CLI with legitimate network/module-loading code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/cli.js | AI (source-diff): Bun bundler output for the package's own CLI binary, not obfuscation. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): photon_rs_bg.wasm is the well-known photon image-processing WASM binary. | ai | |
| phantom-deps | phantom-dep:@openai/agents | AI (phantom-deps): Same phantom-dep heuristic false positive pattern. | ai | |
| phantom-deps | phantom-dep:marked | AI (phantom-deps): Same phantom-dep heuristic false positive pattern. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): new Function() used for browser page.evaluate() in a browser automation tool is expected and documented. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Guard checks for dev-only file; no-op in published package. | ai | |
| semgrep | semgrep:etc-passwd-access | AI (semgrep): The match is inside a blocklist/denylist regex array in bash.ts — defensive code, not credential harvesting. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Standard Proxy get-trap pattern; not obfuscation. | ai | |
| phantom-deps | phantom-dep:@types/turndown | AI (phantom-deps): Type-only dev dependency loaded by framework convention. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Phantom dep heuristic false positive; zod referenced in config files is common for type validation. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decoding image data into a blob store is a normal image-handling pattern. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): env enumeration is filtered by SECRET_ENV_PATTERNS for a secrets-scanning feature; expected behavior. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): All raw IPs are localhost/127.0.0.1 defaults for local Ollama service; not exfiltration. | ai | |
| semgrep | semgrep:dll-hijacking-commands | AI (semgrep): rundll32 url.dll,FileProtocolHandler is the standard Windows shell URL-open idiom; not a hijack vector. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Spreading process.env into a git subprocess environment is standard practice for CLI tools. | ai | |
| phantom-deps | phantom-dep:handlebars | AI (phantom-deps): Phantom dep heuristic false positive; handlebars referenced in config without direct import is plausible. | ai |
Versions (showing 100 of 155)
| Version | Deps | Published |
|---|---|---|
| 17.0.9 | 42 / 2 | |
| 17.0.2 | 42 / 2 | |
| 16.4.3 | 37 / 1 | |
| 16.3.13 | 36 / 1 | |
| 16.3.8 | 36 / 1 | |
| 15.10.2 | 31 / 1 | |
| 15.5.10 | 24 / 1 | |
| 15.0.1 | 25 / 1 | |
| 15.0.0 | 25 / 1 | |
| 13.16.4 | 17 / 1 | |
| 13.16.3 | 17 / 1 | |
| 13.16.2 | 17 / 1 | |
| 13.16.1 | 17 / 1 | |
| 13.16.0 | 17 / 1 | |
| 13.15.3 | 17 / 1 | |
| 13.15.2 | 17 / 1 | |
| 13.14.2 | 15 / 1 | |
| 13.14.0 | 15 / 1 | |
| 13.13.2 | 15 / 1 | |
| 13.13.0 | 15 / 1 | |
| 13.12.10 | 15 / 1 | |
| 13.12.9 | 15 / 1 | |
| 13.12.8 | 15 / 1 | |
| 13.12.7 | 15 / 1 | |
| 13.12.6 | 15 / 1 | |
| 13.12.5 | 15 / 1 | |
| 13.12.4 | 15 / 1 | |
| 13.12.3 | 15 / 1 | |
| 13.12.0 | 15 / 1 | |
| 13.11.1 | 15 / 1 | |
| 13.11.0 | 15 / 1 | |
| 13.10.1 | 15 / 1 | |
| 13.10.0 | 15 / 1 | |
| 13.9.16 | 15 / 1 | |
| 13.9.15 | 15 / 1 | |
| 13.9.14 | 15 / 1 | |
| 13.9.13 | 15 / 1 | |
| 13.9.12 | 15 / 1 | |
| 13.9.11 | 15 / 1 | |
| 13.9.6 | 15 / 1 | |
| 13.9.5 | 15 / 1 | |
| 13.9.4 | 15 / 1 | |
| 13.9.3 | 15 / 1 | |
| 13.9.2 | 15 / 1 | |
| 13.9.1 | 15 / 1 | |
| 13.8.0 | 15 / 1 | |
| 13.7.6 | 15 / 1 | |
| 13.7.5 | 15 / 1 | |
| 13.7.4 | 15 / 1 | |
| 13.7.3 | 15 / 1 | |
| 13.7.1 | 15 / 1 | |
| 13.7.0 | 15 / 1 | |
| 13.6.2 | 15 / 1 | |
| 13.6.1 | 15 / 1 | |
| 13.6.0 | 15 / 1 | |
| 13.5.8 | 15 / 1 | |
| 13.5.7 | 15 / 1 | |
| 13.5.6 | 15 / 1 | |
| 13.5.5 | 15 / 1 | |
| 13.5.4 | 15 / 1 | |
| 13.5.3 | 15 / 1 | |
| 13.5.2 | 15 / 1 | |
| 13.5.1 | 15 / 1 | |
| 13.5.0 | 15 / 1 | |
| 13.4.1 | 15 / 1 | |
| 13.4.0 | 15 / 1 | |
| 13.3.14 | 15 / 1 | |
| 13.3.13 | 15 / 1 | |
| 13.3.12 | 15 / 1 | |
| 13.3.10 | 15 / 1 | |
| 13.3.9 | 15 / 1 | |
| 13.3.8 | 15 / 1 | |
| 13.3.7 | 22 / 3 | |
| 13.3.6 | 22 / 3 | |
| 13.3.5 | 22 / 3 | |
| 13.3.4 | 22 / 3 | |
| 13.3.3 | 22 / 3 | |
| 13.3.2 | 22 / 3 | |
| 13.3.1 | 22 / 3 | |
| 13.3.0 | 22 / 3 | |
| 13.2.1 | 22 / 3 | |
| 13.2.0 | 22 / 3 | |
| 13.1.2 | 22 / 3 | |
| 13.1.1 | 22 / 3 | |
| 13.1.0 | 22 / 3 | |
| 13.0.2 | 22 / 3 | |
| 13.0.1 | 22 / 3 | |
| 13.0.0 | 22 / 3 | |
| 12.19.3 | 22 / 3 | |
| 12.19.2 | 22 / 3 | |
| 12.19.0 | 22 / 3 | |
| 12.18.3 | 22 / 3 | |
| 12.18.1 | 22 / 3 | |
| 12.18.0 | 22 / 3 | |
| 12.17.2 | 22 / 3 | |
| 12.17.0 | 22 / 3 | |
| 12.16.0 | 22 / 3 | |
| 12.15.1 | 22 / 3 | |
| 12.15.0 | 22 / 3 | |
| 12.14.2 | 22 / 3 |
v17.0.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v17.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v16.4.3
2 findingsModified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads. Artifact: bundled (bun) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v16.3.13
2 findingsModified file contains 27 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads. Artifact: bundled (bun) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v16.3.8
4 findingsThis version was published by a different npm account than previous versions on 2026-07-05. This could indicate a legitimate maintainer transition or an account compromise.
[Reject — re-review on republish] (prior reject: AI (source-diff): 17.4MB obfuscated bundle introduced alongside publisher change; high-confidence malicious indicator.) Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (bun) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
[Reject — re-review on republish] (prior reject: AI (source-diff): Network + dynamic code execution in newly added obfuscated file is a dropper/loader hallmark.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (bun) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.16.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.16.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.16.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.16.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.15.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.15.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.14.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.14.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.13.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.13.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.12.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.12.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.12.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.12.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.12.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.12.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.12.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.12.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.12.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.11.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.11.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.10.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.10.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.9.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.9.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.9.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.9.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.9.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.9.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.9.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.9.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.9.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.9.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.9.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.9.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.7.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.7.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.7.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.7.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.7.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.6.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.6.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.5.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.5.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.5.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.5.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.5.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.5.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.5.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.5.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.4.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.3.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.3.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.3.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.3.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.3.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.3.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.3.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.3.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.3.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.3.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.3.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.3.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.1.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v13.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.19.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.19.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.19.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.18.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.18.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.18.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.17.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.17.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.15.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.15.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v12.14.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.