pi extension

pi-vuln-scanner

Scan locally installed pi packages for vulnerabilities and supply-chain risk. Advisory-only by default, with startup warnings and clear removal hints.

Install

pi install npm:pi-vuln-scanner

Commands

/pi-scan
/pi-scan-report
/pi-scan-config
/pi-scan-clear-cache

Privacy-first

The scanner does not send local source code to third-party services. OSV lookups use npm package names and versions only when network scanning is enabled.

Source: github.com/isashi/pi-vuln-scanner