pi-ai-slop-review
Evidence-backed review of AI-assisted TypeScript, JavaScript, and Python changes for Pi
Package details
Install pi-ai-slop-review from npm and Pi will load the resources declared by the package manifest.
$ pi install npm:pi-ai-slop-review- Package
pi-ai-slop-review- Version
1.2.2- Published
- Aug 4, 2026
- Downloads
- 422/mo · 37/wk
- Author
- vinbitz
- License
- Apache-2.0
- Types
- extension
- Size
- 688.4 KB
- Dependencies
- 1 dependency · 3 peers
Pi manifest JSON
{
"extensions": [
"index.ts"
]
}Security note
Pi packages can execute code and influence agent behavior. Review the source before installing third-party packages.
README
Pi AI-Slop Review
A conservative, read-only Pi extension for evidence-backed review of TypeScript, JavaScript, and Python changes.
Requirements
Requires Node.js 22.7 or newer because the package's TypeScript entry points use Node's type stripping and type transformation runtime flags. Node 24 is tested.
The Pi TUI, TypeBox, and optional critic API integrations are declared as optional peer modules. The package entrypoint can be inspected or imported without those host peers; the Pi integration loads its UI/schema peers only when the extension factory runs, and critic support reports a clear missing-peer error only when /slop_critics is invoked.
pi install npm:pi-ai-slop-review
Try it for one session without installing:
pi -e npm:pi-ai-slop-review
A version-tagged Git installation is also supported:
pi install git:github.com/Vinax89/pi-ai-slop-review@v1.2.1
Pi packages execute code with the user's privileges. Review the source and docs/security.md before installation.
Use
/slop-reviewreviews files changed through trackededit,write, orctx_editcalls in the current Pi session./slop-review src/a.ts src/b.tsreviews explicit project-relative files./slop-auditexplicitly runs repository-wide review of up to 10,000 supported files by default; native TypeScript scans use programs bounded to 250 files and 4 MiB of root source, the repository graph reportspartialinstead of exceeding that budget, and Python helpers run in up to two bounded batches concurrently.- Every review or audit runs in a reusable isolated child process with a 192 MiB old-generation limit; streamed content hashes identify unchanged requests without a second result copy, garbage collection runs only under heap pressure, and recycled processes reuse Node's native compile cache. Results report
complete,partial, orabstained; process failure or memory-limit exit becomesabstainedinstead of terminating Pi. A weighted-severity Markdown report with evidence, possible remediation, and suggested verification is written to private extension state. /slop-findingsopens the TUI finding picker; a finding ID prefix opens it directly./slop-triagesummarizes evidence, counterevidence, uncertainty, and human-review guidance; findings are never treated as proof that code is removable./slop-timelineshows content-hash-valid mutations and verification freshness./slop-claims <text>checks deterministic completion claims against configured evidence./slop-context <symbol-or-path>queries callers, tests, specifications, and public-surface context.- The
slop_intenttool builds an evidence-cited decision trace plus paper-derived dimensions (relevance, factuality, density, repetition, templatedness, coherence, and tone). It accepts an optional artifact/task/audience review profile; unknown dimensions remain unknown, the LLM interprets the evidence, and a human makes the final determination. slop_intentcan compute bounded local text/code forensics whenincludeForensicsis enabled (default): a model-free document-bigram perplexity proxy, sentence/line burstiness, argument dependency, falsifiable-claim and jargon rates, section interchangeability, repetition and boilerplate rates, logic-density rates, and a local stylometric fingerprint.calibrateProjectSignalsaccepts caller-supplied source-hash-linked history for descriptive density drift; it does not read Git history or label automation.slop_provenanceverifies bounded project-local artifact hashes and Ed25519-signed provenance manifests against configured trust keys, then checks explicitly linked cross-modal descriptors for missing links, timestamp mismatches, and caption inconsistencies. Trusted provenance supports origin assertions but does not prove authorship or synthetic generation.slop_clustersanalyzes caller-supplied offline publishing or repository events for synchronized shared hashes/templates and reports domain-level repetition patterns. It performs no network collection, account termination, or automatic downranking.- Full vendor C2PA profile coverage, SynthID detection, generator-specific neural classifiers, and platform-scale S-CTS coordination remain unsupported until explicit media-ingestion, detector, reference-corpus, and network-evidence contracts exist.
/slop-suppress,/slop-unsuppress, and/slop-feedbackmanage reasoned local policy evidence./slop-rulesreports policy decisions and calibrated rule health./slop-export markdown|json|sarif [path]exports the latest evidence; omitted paths use private extension state./slop-diagnosticsand/slop-configexplain runtime, trust, provider, and configuration state./slop-labcreates, validates, explicitly applies, or rolls back patch proposals. Validation uses exact configured commands in separate baseline/candidate Git worktrees inside Bubblewrap with no host-root mount, a separate network namespace, cleared environment, private HOME, and private/tmp./slop-experimentruns bounded pure-expression property, metamorphic, shadow, mutation, invariant, regression-generation, equality-saturation, and CEGIS checks./slop-formalruns explicitly enabled SMT expression equivalence or Alive2-compatible LLVM translation validation through exact configured, network-isolated commands./slop-retrieveranks local graph context without uploading source./slop-criticsis an opt-in remote advisory panel whose non-abstaining responses must cite existing deterministic evidence IDs.- The
slop_review,slop_context,slop_intent,slop_provenance,slop_clusters,slop_propose,slop_verify,slop_experiment,slop_formal,slop_retrieve, andslop_criticstools expose the same capabilities to the agent. Agent tools never apply patches to the real checkout.
The scanner federates a TypeScript Program/TypeChecker, an isolated Python stdlib AST helper, explicitly trusted language servers, SARIF 2.1, ESLint/Ruff/Pyright/Knip reports, LCOV/coverage.py reports, and local dependency provenance. It reports:
- unresolved modules
- simple pass-through wrapper candidates
- empty or log-only catch clauses
- catch clauses returning safe-looking fallbacks
Python wrapper findings remain observation-only because repository-wide dynamic references are not proven. Python imports guarded by TYPE_CHECKING, ImportError, or platform conditions are excluded. External analyzer fixes are retained only as evidence.
Optional global configuration lives at ~/.pi/agent/ai-slop/config.json. A project may provide .pi/ai-slop.json, but Pi ignores it until the project is explicitly trusted. Example:
{
"schemaVersion": 1,
"execution": {
"trusted": true,
"lspServers": { "typescript": ["typescript-language-server", "--stdio"] }
},
"providers": {
"sarif": ["reports/results.sarif"],
"analyzerReports": [{ "kind": "eslint", "path": "reports/eslint.json" }],
"coverageReports": [{ "kind": "lcov", "path": "coverage/lcov.info" }]
}
}
The extension never installs a missing language server or scanner. LSP startup requires both Pi project trust and execution.trusted. Registry requests require network.enabled plus an allowlisted registry (npm, pypi, or openssf).
The extension keeps a branch-aware assurance ledger in Pi session entries and stores review baselines outside the repository under ~/.pi/agent/ai-slop/state/. Verification is authoritative only when configured, and becomes stale when relevant content hashes change. Project-local .pi/ai-slop.json configuration is ignored until Pi explicitly trusts the project.
An incremental SQLite context graph under ~/.pi/agent/ai-slop/graph/ records TypeScript and Python symbols, resolved calls/imports, public exports, framework registrations, package entry points, tests, coverage links, Markdown requirements, and specification links. It supplies public-surface changes, architecture-policy conflicts, exact-body clone observations, and test-impact evidence without storing source bodies.
The extension never modifies reviewed code during review, installs dependencies, imports project modules, infers AI authorship from style, or automatically removes findings. Source application requires a verified laboratory run plus an explicit user /slop-lab apply confirmation and fresh source hashes; R3, file-deleting, and configured critical-path proposals are blocked. Network access, remote critics, formal engines, and project tool execution are disabled by default. Experimental results state their finite domains, semantics, assumptions, timeouts, and abstentions; equality saturation is advisory, and only an exhausted declared domain—not sampled success or solver unknown—can verify a bounded expression experiment.
Development and validation
npm install
npm run build
npm test
npm run evaluate
npm run benchmark
npm audit --omit=dev
npm run validate
Generated evaluation and performance evidence is written under artifacts/. The evidence library is in library/.