@xaccefy/pi-xpi
XPI — offensive security tools for Pi Agent. Casefile tracking, web search, library docs, exploit technique search, and todo tracking.
Package details
Install @xaccefy/pi-xpi from npm and Pi will load the resources declared by the package manifest.
$ pi install npm:@xaccefy/pi-xpi- Package
@xaccefy/pi-xpi- Version
0.9.4- Published
- Aug 16, 2026
- Downloads
- 3,778/mo · 629/wk
- Author
- xaccefy
- License
- MIT
- Types
- extension, skill
- Size
- 695.3 KB
- Dependencies
- 4 dependencies · 4 peers
Pi manifest JSON
{
"extensions": [
"./packages/pi-casefile/src/index.ts",
"./packages/pi-webxp/src/index.ts",
"./packages/pi-xtodo/index.ts"
],
"skills": [
"./skills"
],
"subagents": {
"agents": [
"./agents"
]
}
}Security note
Pi packages can execute code and influence agent behavior. Review the source before installing third-party packages.
README
XPI
Security tooling for the Pi agent — casefile tracking, web search, exploit-technique intelligence, code search, and todos.
What it is
XPI turns the Pi agent into a security researcher: a case ledger with enforced gates, real exploit-technique grounding, web lookup, fast code search, and a pipeline that keeps findings honest.
- Casefile — hypothesis → investigating → confirmed → reported, with gates at every step
- Machine-owned PoC gates — zero exit is necessary but never proof: direct-response findings require nonce-bound body evidence plus a DNS-pinned, conclusive
target_onlyreplay against an operator-approved control; reflection-capable requests can add a harness-generated target-only canary; only the main agent may make the semantic decision and commit phase 2 - Exploit chains —
ChainSuggestsurfaces combinations the model missed - Coverage matrix — machine-checkable "we tested everything" claims
- Code search — structural AST search (ast-grep) for sinks and call chains, plus built-in grep/find for text
Install
Works on Pi Agent and its fork OMP (@oh-my-pi/pi-coding-agent). One manifest serves both: OMP reads the same pi extension field, the Agent Plugins plugin.json for skills, and the task tool spawns the specialist agents.
./install.sh # auto-detects pi or omp in PATH
./install.sh --pi # force Pi (installs pi-subagents + optional ast-grep structural search)
./install.sh --pi --no-subagents # minimal Pi install; use /xp lite because swarm dispatch is unavailable
./install.sh --omp # force OMP (copies agents/*.md to ~/.omp/agent/agents)
Or install the npm package per host:
pi install npm:@xaccefy/pi-xpi # Pi
omp install npm:@xaccefy/pi-xpi # OMP
Set PREVIEW_IS_API_KEY for exploit_search (see docs/guide.md).
Quick start
/xp # toggle bounded swarm XP mode on/off
/xp lite # explicit single-agent security workflow
/xp swarm # bounded multi-agent pipeline
Use /xp for the default bounded swarm workflow, or /xp lite for CTFs, focused reviews, and one-target work where dispatch is unnecessary. On Pi, swarm dispatches only auditor, tracer, skeptic, and chain via pi-subagents; on OMP it uses the native task tool with the same four agent names. Validation, patching, reporting, and ConfirmFinding stay with the main agent.
Full tool reference, configuration, and pipeline docs: docs/guide.md.
Packages
| Package | npm |
|---|---|
| Umbrella | @xaccefy/pi-xpi |
| Case ledger | @xaccefy/pi-casefile |
| Web lookup + exploit search | @xaccefy/pi-webxp |
| Todos | @xaccefy/pi-xtodo |
Develop
bun install
bun test --isolate
bun run typecheck