
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
@hewliyang/pi-codex-image
Advanced tools
Pi extension that exposes OpenAI's hosted image_generation tool to any model, authenticated via the openai-codex (ChatGPT Plus/Pro) OAuth credential.
A pi extension exposing OpenAI's hosted image_generation tool to any model, authenticated via the openai-codex (ChatGPT Plus/Pro) OAuth credential.
pi install npm:@hewliyang/pi-codex-image
You must be logged in via Codex OAuth:
pi /login # pick "ChatGPT Plus/Pro (Codex)"
generate_image tool — agent-callable image generation/editing. Args: prompt, input_image_paths, size, quality, background, save_path./imggen slash command — user-initiated generation: /imggen <prompt>, /imggen edit, /imggen redo, /imggen help.generate-image skill — teaches the agent when/how to call the tool, with prompt recipes and a chroma-key removal script.MIT
FAQs
Pi extension that exposes OpenAI's hosted image_generation tool to any model, authenticated via the openai-codex (ChatGPT Plus/Pro) OAuth credential.
The npm package @hewliyang/pi-codex-image receives a total of 4 weekly downloads. As such, @hewliyang/pi-codex-image popularity was classified as not popular.
We found that @hewliyang/pi-codex-image demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.