
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@leing2021/pi-goal
Advanced tools
Pi extension for autonomous goal-driven execution. Set a goal and pi works across turns until finish_goal, turn limit, or interruption.

Pi extension for autonomous goal-driven execution.
Set a goal, and pi works on it across multiple turns — resuming across sessions — until the model calls finish_goal, the turn limit is reached, or you interrupt.
# Test without installing
pi -e ./goal/index.ts
# Inside pi, set a goal
/goal "Write a hello-world TypeScript CLI"
# Symlink into the global extensions directory
mkdir -p ~/.pi/agent/extensions/goal
ln -s "$(pwd)/goal" ~/.pi/agent/extensions/goal/
Then in any pi session: /reload to load, or restart pi.
| Command | Description |
|---|---|
/goal "objective" | Set a new goal and start working |
/goal status | Show current goal status |
/goal stop | Stop and clear the current goal |
| Tool | Description |
|---|---|
finish_goal | Mark the goal as completed with a summary |
/goal "build a feature" sets an active goalfinish_goal with a summaryfinish_goal → completed10 default, 20 in super-pi mode) → paused/goal stopIf 02-plan and 03-work skills are detected, the extension enables super-pi mode:
20 (instead of 10)02-plan → 03-work → 04-reviewnpm install
npm test # run all tests
npm run typecheck
goal/
├── index.ts # Extension factory — registers commands, tools, handlers
├── types.ts # GoalEntry, GoalStatus types
├── state.ts # Pure functions: createGoal, clearGoal, restoreGoalFromEntries
├── commands.ts # Command handler: stop / status / create goal
├── loop.ts # shouldContinueLoop, buildFollowUpMessage
├── prompt.ts # buildGoalSystemPrompt, buildSuperPiGuidance
└── super-pi.ts # detectSuperPi
tests/ # One test file per source module
| Issue | Cause | Fix |
|---|---|---|
Extension not loaded after /reload | Symlink target moved or broken | Re-run the ln -s command from the repo root |
| Goal resets after restart | /reload clears in-memory state | State is recovered from session branch on next session_start — this is expected |
| pi asks for API key | No provider configured | Run pi --login or pi --provider <name> --api-key <key> |
pi-goal is a lightweight, standalone extension. Whether you need it depends on your existing setup:
You likely don't need pi-goal. Super-pi already provides a complete goal-driven workflow:
| Feature | pi-goal | super-pi |
|---|---|---|
| Goal-driven execution | /goal command | Built-in 5-step loop |
| Cross-session resume | ✅ Turn-based | ✅ Unit-based checkpoint |
| Multi-turn autonomy | 10 / 20 turns | Full pipeline with TDD gates |
| Stop conditions | Manual / turn limit | TDD gates + 5-axis review |
| Planning & review | ❌ | ✅ brainstorm → plan → review → learn |
Super-pi's 03-work skill already provides checkpoint resume at the implementation-unit level, which is more granular than pi-goal's turn-based approach. Its 06-next skill recommends the next step automatically.
Principle: don't install what you already have.
# Symlink into the global extensions directory
mkdir -p ~/.pi/agent/extensions/goal
ln -s "$(pwd)/goal" ~/.pi/agent/extensions/goal/
Then in any pi session: /reload to load, or restart pi.
rm ~/.pi/agent/extensions/goal
MIT
FAQs
Pi extension for autonomous goal-driven execution. Set a goal and pi works across turns until finish_goal, turn limit, or interruption.
We found that @leing2021/pi-goal demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.