
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@0xrsydn/pstack-pi
Advanced tools
Port of pstack (Lauren Tan's Cursor plugin) to pi: poteto-mode workflows, principle skills, and subagent fan-out with per-role models.
A pi port of pstack, Lauren Tan's Cursor plugin. Original content is MIT-licensed (see LICENSE); this port keeps its structure and wording and adapts Cursor-specific mechanics to pi.
Acknowledgment: all skills, workflows, and prose originate from Lauren Tan's pstack. This repository only ports them to pi.
pi install npm:@0xrsydn/pstack-pi
skills/ — all 45 original workflow and principle skills (poteto-mode, swarm, arena, interrogate, how, why, reflect, the principle-* set, etc.), rewritten where they referenced Cursor-specific mechanics.agents/ — subagent definitions discovered by the bundled extension: poteto-agent, comment-sicko, and general-purpose (replaces Cursor's built-in generalPurpose task agent).extensions/subagent/ — pi's example subagent tool, extended for pstack:
model override (with pstack's inherit-parent / auto aliases), so one parallel call can mix models.readonly flag (restricts to read,grep,find,ls).agents/ directory from inside the package. User (~/.pi/agent/agents/) and project (.pi/agents/) definitions win over bundled ones.tasks[]), and chain modes are unchanged otherwise.pi install npm:@0xrsydn/pstack-pi # from npm (recommended, version-pinned)
pi install git:github.com/0xrsydn/pstack-pi # or from git
After installing, confirm resources load with pi list.
Run the setup-pstack skill ("/skill:setup-pstack", or ask the agent to configure pstack models). It:
pi --list-models.~/.pi/agent/pstack-models.md.The parent agent reads that file before spawning and passes each role's value as the model field of its subagent task entry. Delete a line to fall back to that skill's inline default; delete the file to fall back everywhere. There is no requirement to run setup — defaults described inline in the skills apply, but they reference placeholder model names from the upstream plugin until you write real ones.
| Cursor mechanic | pi equivalent |
|---|---|
Task tool, subagent_type | subagent tool, agent field |
generalPurpose built-in agent | bundled general-purpose agent |
Task-level model slug | task-level model field (provider/model-id form) |
run_in_background, cloud workers | parallel tasks[] calls run concurrently with isolated contexts; all local |
environment: "cloud" / cloud VMs | removed; lanes run in worktrees on this machine |
~/.cursor/rules/pstack-models.mdc | ~/.pi/agent/pstack-models.md (plain markdown, read before spawns) |
~/.cursor/skills/ paths | ~/.pi/agent/skills/; project .cursor/skills/ → .pi/skills/ |
Session transcripts under ~/.cursor/projects/<slug>/agent-transcripts/ | ~/.pi/agent/sessions/<dashed-repo-path>/*.jsonl |
Cursor's built-in create-skill / babysit skills | generic authoring guidance; pstack's own playbooks cover these requests |
deslop, control-ui/control-cli (cursor-team-kit) references | degraded gracefully: steps drop the plugin dependency or drive the surface directly |
| Bugbot review-bot comments | generalized to any bot reviewer comments |
Slash commands like /bro, /why | /skill:bro, /skill:why (enable skill commands in settings) |
Not ported:
automations/benny/) and the grokbot automation-webhook skill — no pi equivalent background-runner target.docs/guide/ — read it upstream; most prose still applies apart from setup details.why) expect you to have equivalent data sources reachable through other tools.pi binary on PATH (subagent tool).FAQs
Port of pstack (Lauren Tan's Cursor plugin) to pi: poteto-mode workflows, principle skills, and subagent fan-out with per-role models.
The npm package @0xrsydn/pstack-pi receives a total of 37 weekly downloads. As such, @0xrsydn/pstack-pi popularity was classified as not popular.
We found that @0xrsydn/pstack-pi demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.