C1 Identity & least privilege
Minimal 0.00 / 1.00
Pi runs as the user who launched it and makes no attempt to narrow that authority. Every shell command the model runs receives a full copy of the user's environment, including provider API keys and any cloud or GitHub tokens set there, and the file tools accept any absolute or home-relative path. There is no authorization layer that checks a request before it runs, so a hijacked session can use everything the user can: SSH keys, cloud credentials, gh auth, and the stored Pi credentials themselves.
C2 Approval gates
Minimal 0.00 / 1.00
Pi does not ask before running tools. Shell commands, file writes and edits execute as soon as the model emits them; the project's security doc says so directly. An extension hook can block tool calls, and an example permission-gate extension exists, but nothing ships enabled. There is no checkpoint or undo for file changes, so a bad command (for example rm -rf or a force-push with the user's credentials) is not recoverable by Pi.
C3 Tool & action scoping
Minimal 0.13 / 1.00
The default tool set is read, bash, edit and write. Bash takes an arbitrary command string, and the file tools resolve any absolute or ~ path without confining it to the project folder. Validation is limited to typed schemas and a bounds check on the optional bash timeout. Users can restrict tools with --tools or --no-tools, but out of the box the model has general-purpose shell and whole-machine file write.
C4 Code-execution isolation
Minimal 0.00 / 1.00
Model-generated commands run directly on the host as the user, in a bash subprocess that inherits the full environment. Pi ships no sandbox; its security doc calls the lack of a built-in sandbox expected behaviour and recommends running the whole process in a container or VM. A sandbox exists only as example extension code that users must copy and install. Anything a command does (including running repo scripts, package installs and MCP stdio servers) reaches the user's whole machine and network.
C5 Untrusted input blast radius
Minimal 0.00 / 1.00
Pi reads repository files, command output, instruction files from every ancestor folder, and (when configured) MCP results straight into the model's context with no provenance tracking or taint handling. Once hijacked, the same session can read secrets from the environment or disk and send them out through the shell, and can also delete or push, all without a human in the loop. Nothing in the code limits what a hijacked session can do.
C6 Memory, context & configuration integrity
Minimal 0.25 / 1.00
Pi has a real project-trust gate: project settings, MCP servers, extensions, skills, prompts and system-prompt files under .pi only load after an explicit trust decision, and non-interactive modes default to not loading them. Instruction files (AGENTS.md, CLAUDE.md) from the working folder and every parent still load silently into the system prompt, and the project sessionDir setting is read before trust. Because the model can write anywhere the user can, a hijacked session can grant trust in ~/.pi/agent/trust.json, drop an extension into ~/.pi/agent/extensions, or plant files in an already-trusted project, which then load in every later session.
C7 Third-party extensions
Minimal 0.13 / 1.00
Nothing third-party is enabled out of the box, and project-supplied packages and MCP servers only load after the project-trust prompt. Once added, extensions run in the Pi process with all its credentials, packages install from npm or git without integrity checks (pinned only if the user gives an exact version), npm installs run lifecycle scripts, and missing configured packages are installed automatically after the generic trust prompt. MCP stdio servers inherit the full environment by default.
C8 Secrets & sensitive-data protection
Minimal 0.20 / 1.00
Provider credentials are stored in plaintext ~/.pi/agent/auth.json with owner-only permissions, and the whole user environment, including API keys, is passed to every shell command and MCP stdio server. Redaction exists only for the user-initiated bug report. Install telemetry is on by default but sends only the version; analytics are opt-in. Session transcripts can contain any secret the model reads and are written unencrypted.
C9 Audit & traceability
Minimal 0.45 / 1.00
Every message, tool call and tool result is appended to a JSONL session file under ~/.pi/agent/sessions as it happens, giving a replayable local trajectory. It is outside the project folder by default, but the agent's own shell can edit it, and a repository's .pi/settings.json can relocate it before trust is decided. There is no actor attribution beyond message roles, no approval records (there are no approvals), and no tamper evidence or export.
C10 Limits & kill switch
Minimal 0.00 / 1.00
There are no limits on turns, wall-clock time or spend, and the bash tool has no default timeout. Stopping works: abort cancels the agent run and kills the shell's process group with SIGKILL, and shutdown signals kill tracked children. But a runaway session can loop and spend indefinitely until a human intervenes.