opensec-pi-subagents
OpenSec Subagents for Pi: specialized agents in separate sessions that inherit the parent's model and thinking level. Bun build, for Pi-Bolt.
Package details
Install opensec-pi-subagents from npm and Pi will load the resources declared by the package manifest.
$ pi install npm:opensec-pi-subagents- Package
opensec-pi-subagents- Version
0.20.0- Published
- Oct 4, 2026
- Downloads
- 373/mo · 104/wk
- Author
- kushalkhemka
- License
- Apache-2.0
- Types
- extension
- Size
- 789 KB
- Dependencies
- 0 dependencies · 3 peers
Pi manifest JSON
{
"image": "https://github.com/tintinweb/pi-subagents/raw/master/media/screenshot.png",
"video": "https://github.com/tintinweb/pi-subagents/raw/master/media/demo.mp4",
"extensions": [
"./dist-bun/index.js"
]
}Security note
Pi packages can execute code and influence agent behavior. Review the source before installing third-party packages.
README
opensec-pi-subagents is OpenSec's build of @tintinweb/pi-subagents for
Pi-Bolt, Pi compiled ahead of time on Bun.
- It adds parent model and thinking-level inheritance, cached agent discovery, and the fixes listed below.
- It ships as a prebuilt bundle with no runtime dependencies.
Install
pi-bolt install npm:opensec-pi-subagents
- The Pi-Bolt installer offers to install it for you.
- After installing, restart Pi-Bolt or run
/reload. - Update it with
pi-bolt update --extensions, and remove it withpi-bolt remove npm:opensec-pi-subagents.
Requirements
- Pi-Bolt 0.6 or later (Pi 1.0), or Pi 0.84 or later run by Bun 1.3 or later.
- This build runs on Bun only. For Pi on Node, use
@tintinweb/pi-subagents. - Install one subagents extension at a time. This package and
@tintinweb/pi-subagentsregister the same tools. If two such extensions are loaded, the one Pi loads first stays active and the other disables itself with a warning.
Features
- Background agents by default, with optional foreground runs, steering, result retrieval and session resume.
- Built-in
ExploreandPlanagents for read-only work, a general-purpose agent, and custom agent definitions. - Parallel and staged workflows through
SubagentWorkflow(agent(),parallel(),pipeline()). - An
/agentsview for live conversations, settings, workflows and scheduled jobs. - Optional nested delegation, persistent memory, skill preloading and Git worktree isolation.
- Agents inherit the parent session's model and thinking level unless their definition or the call overrides them.
Usage
Ask Pi to delegate work, for example: "Use an Explore agent to find the authentication code, then report the relevant
files." Pi calls the Agent tool:
Agent({ subagent_type: "Explore", prompt: "Find authentication code", description: "Find auth files" })
Tools
| Tool | What it does |
|---|---|
Agent |
Starts an agent. A background run returns an ID and notifies the main session when it finishes; set run_in_background: false when the next step must wait for its result. Also accepts session-scoped cron, interval and one-shot schedules. |
get_subagent_result |
Returns the full result of an agent. |
steer_subagent |
Redirects a running agent. |
SubagentWorkflow |
Runs repeatable multi-agent work (agent(), parallel(), pipeline()). |
Commands
| Command | What it does |
|---|---|
/agents |
Inspect and manage agents: live conversations, settings, workflows and scheduled jobs. |
@<agent> <message> |
With agent mentions enabled, sends a message to that agent, for example @explore check the RPC path. A finished agent can be resumed. |
Custom agents
Put agent definitions in .pi/agents/<name>.md in a project, or in the global Pi agents directory.
Configuration
| Setting | Default | Meaning |
|---|---|---|
Background concurrency (/agents → Settings) |
10 |
How many background agents run at once. |
Further reading: workflows, RPC events, and the example workflows.
Notes
- Interval schedules must be at least
1m; intervals and relative delays are capped at3650d. - Worktree isolation is optional. On completion, an isolated agent's changes are committed to its branch.
- Review
/agents → Settingsbefore enabling delegation or isolation for agents that can write.
Security
Subagents run with your user account's privileges and the tools they are granted, like Pi itself.
Workflow scripts run with full host access. The VM they run in keeps them deterministic; it is not a sandbox. Run only scripts you trust.
See SECURITY.md for the security model and how to report a vulnerability.
How this build is packaged
The package holds two files and no runtime dependencies:
dist-bun/index.jsis a small ESM entry that Pi loads.dist-bun/core.cjsis the extension itself, as readable CommonJS that Bun loads natively.
Pi's loader never has to transpile the extension. It adds tens of milliseconds to a launch instead of hundreds, and
avoids a transpile of several seconds on the first launch after an install. Tools, commands, settings and file
locations are those of @tintinweb/pi-subagents.
Changes from upstream
Based on @tintinweb/pi-subagents 0.19:
- Inheritance and caching:
- Agents inherit the parent's model and thinking level.
- Agent discovery and configuration are cached and revalidated by file metadata.
- Schedules:
- Schedules longer than about 24.8 days no longer fire every millisecond; long delays run on chained timers.
- A fire is skipped while the job's previous agent is still running.
- Validating a cron expression no longer leaves a timer running, so
pi -pexits. - A corrupt schedule file is kept as
<file>.corruptinstead of being overwritten. - A canceled session switch no longer stops the scheduler.
- Worktrees:
- Isolated agents no longer lose their work when the preservation commit or a
git statusfails. Their worktree is kept and its path reported. - Quitting waits up to 15 s for stopped worktree agents to save their changes.
- Isolated agents no longer lose their work when the preservation commit or a
- Stopping agents:
- A stop issued before an agent's session exists is honoured.
- A foreground resume can be stopped.
get_subagent_resultwithwait: truewaits while a worktree is being created.
- Pi 1.0:
@agentmentions start the conversation clone again.- Transcripts no longer repeat the system prompt.
ext:tool narrowing is enforced on deferred tool-to-tool calls too.
- Workflows:
- Code in
metais rejected before it runs. - Caches and
log()output are bounded. - Children of a finished run are stopped.
- Script paths must be regular files.
- Schema patterns with nested quantifiers are refused.
- Errors name the script line.
- Code in
- Output: terminal control sequences in agent output, gate output and logs are stripped before rendering.
The full history is in CHANGELOG.md.
License
Copyright 2026 OpenSec. Licensed under the Apache License, Version 2.0.
Based on @tintinweb/pi-subagents by tintinweb (MIT). The bundle includes
croner (MIT). Their notices are in NOTICE.
