pi-vuln-scanner
Scan locally installed pi packages for vulnerabilities and supply-chain risk. Advisory-only by default, with startup warnings and clear removal hints.
Install
pi install npm:pi-vuln-scanner
Commands
/pi-scan
/pi-scan-report
/pi-scan-config
/pi-scan-clear-cache
Privacy-first
The scanner does not send local source code to third-party services. OSV lookups use npm package names and versions only when network scanning is enabled.