
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@leing2021/pi-search
Advanced tools
Minimal Secure Evidence Gateway for Pi Coding Agent — search, web_search, web_fetch, research_search. Intent-based provider routing, quota fallback, dual-LLM research, 4-layer abuse prevention.
A minimal, secure evidence gateway for Pi Coding Agent.
pi-search gives agents four focused tools:
search — search the local repo with ripgrepweb_search — find web sources through routed providersweb_fetch — fetch and clean one web page safelyresearch_search — collect web evidence, with optional LLM verificationIt is designed to be simple, auditable, and safe by default.
pi install npm:@leing2021/pi-search
# Restart pi or run /reload
The package exposes its Pi extension through package.json:
{
"pi": {
"extensions": ["extensions/pi-search.ts"]
}
}
search({ query: "registerTool" })
web_search({ query: "React 19 features" })
web_fetch({ url: "https://react.dev/blog" })
research_search({ query: "SSRF protection in Node.js" })
| Tool | Purpose | Default behavior |
|---|---|---|
search | Local repo search | Uses ripgrep; blocks unsafe paths by default |
web_search | Web source discovery | Routes through SearXNG / Brave / Tavily / DuckDuckGo |
web_fetch | Safe page fetch | http(s), SSRF checks, redirect checks, HTML cleanup |
research_search | Evidence collection | LLM verification is off unless explicitly enabled |
All configuration is optional. Use only what you need.
# Web search providers
export BRAVE_SEARCH_API_KEY="brave_xxx"
export TAVILY_API_KEY="tvly_xxx"
export FIRECRAWL_API_KEY="fc_xxx"
# Optional private SearXNG provider
export PI_SEARCH_SEARXNG_URL="http://<private-searxng-host>:8888"
export PI_SEARCH_ALLOW_PRIVATE_SEARXNG="always"
# Optional provider override
export PI_SEARCH_WEB_PROVIDER="auto" # auto | brave | tavily | duckduckgo
# Optional research LLM verification
export PI_SEARCH_LLM_ENABLED="always" # never | ask | always
export PI_SEARCH_LLM_PROVIDER="openai" # openai | anthropic | local-openai
export PI_SEARCH_LLM_MODEL="gpt-4o-mini"
export PI_SEARCH_LLM_BASE_URL="https://api.openai.com/v1"
export PI_SEARCH_LLM_API_KEY_ENV="OPENAI_API_KEY"
export OPENAI_API_KEY="<OPENAI_API_KEY>"
# Optional local search boundary override
export PI_SEARCH_ALLOW_OUTSIDE_CWD="always"
When HTTPS_PROXY / HTTP_PROXY (any case) or ALL_PROXY (http(s):// only) is set,
pi-search installs an undici EnvHttpProxyAgent as the global fetch dispatcher
at extension load. This affects every fetch in the host process, matching
curl-style env-proxy semantics. Set NO_PROXY=localhost,127.0.0.1 to keep
loopback/LAN traffic direct.
pi-search uses intent-based routing instead of broad fan-out.
| Task | Primary path | Fallback |
|---|---|---|
| General web search | SearXNG if explicitly enabled, otherwise Brave | Tavily → DuckDuckGo |
| Page fetch | Local safe fetch | Firecrawl when configured / requested |
| Basic research | Search + safe fetch | Provider fallback |
| Deep research | Tavily-oriented evidence | Search + fetch fallback |
Private SearXNG is allowed only when both variables are set:
export PI_SEARCH_SEARXNG_URL="http://<private-searxng-host>:8888"
export PI_SEARCH_ALLOW_PRIVATE_SEARXNG="always"
pi-search is a process-level safety layer. It is not a Docker, VM, or OS sandbox.
It focuses on practical defaults:
execFile, not shell stringscwd unless explicitly allowed.env, .ssh, and private keys are blockedThe implementation lives in src/security.ts and is covered by the test suite.
Copy this into a new AI agent when you want it to install and configure pi-search:
Install and configure pi-search for Pi Coding Agent.
Installation:
pi install npm:@leing2021/pi-search
Then restart pi or run /reload.
Available tools:
- search({ query, path? })
- web_search({ query, provider?, count? })
- web_fetch({ url })
- research_search({ query, mode?, maxSources? })
Use these environment variables when needed:
WEB_SEARCH:
BRAVE_SEARCH_API_KEY="brave_xxx"
TAVILY_API_KEY="tvly_xxx"
FIRECRAWL_API_KEY="fc_xxx"
PI_SEARCH_WEB_PROVIDER="auto"
PRIVATE_SEARCH:
PI_SEARCH_SEARXNG_URL="http://<private-searxng-host>:8888"
PI_SEARCH_ALLOW_PRIVATE_SEARXNG="always"
RESEARCH_LLM:
PI_SEARCH_LLM_ENABLED="always"
PI_SEARCH_LLM_PROVIDER="openai"
PI_SEARCH_LLM_MODEL="gpt-4o-mini"
PI_SEARCH_LLM_BASE_URL="https://api.openai.com/v1"
PI_SEARCH_LLM_API_KEY_ENV="OPENAI_API_KEY"
OPENAI_API_KEY="<OPENAI_API_KEY>"
LOCAL_SEARCH:
PI_SEARCH_ALLOW_OUTSIDE_CWD="always"
Research LLM notes:
PI_SEARCH_LLM_API_KEY_ENV is the name of the environment variable that stores the API key. It is not the API key itself.PI_SEARCH_LLM_PROVIDER="local-openai"
PI_SEARCH_LLM_MODEL="<local-model-name>"
PI_SEARCH_LLM_BASE_URL="http://<local-llm-host>:11434/v1"
PI_SEARCH_LLM_API_KEY_ENV="LOCAL_LLM_API_KEY"
LOCAL_LLM_API_KEY="<LOCAL_LLM_API_KEY_OR_DUMMY>"
Other OpenAI-compatible provider examples:
# OpenRouter
PI_SEARCH_LLM_PROVIDER="openai"
PI_SEARCH_LLM_MODEL="openai/gpt-4o-mini"
PI_SEARCH_LLM_BASE_URL="https://openrouter.ai/api/v1"
PI_SEARCH_LLM_API_KEY_ENV="OPENROUTER_API_KEY"
OPENROUTER_API_KEY="<OPENROUTER_API_KEY>"
# DeepSeek
PI_SEARCH_LLM_PROVIDER="openai"
PI_SEARCH_LLM_MODEL="deepseek-chat"
PI_SEARCH_LLM_BASE_URL="https://api.deepseek.com/v1"
PI_SEARCH_LLM_API_KEY_ENV="DEEPSEEK_API_KEY"
DEEPSEEK_API_KEY="<DEEPSEEK_API_KEY>"
.
├── extensions/ # Pi extension entry
├── src/ # security, providers, research, text helpers
├── tests/ # node:test suite
├── package.json # package metadata and Pi extension manifest
├── README.md # English README
└── README_CN.md # Chinese README
npm test
It is intentionally small: search, fetch, evidence, safety.
MIT
FAQs
Minimal Secure Evidence Gateway for Pi Coding Agent — search, web_search, web_fetch, research_search. Intent-based provider routing, quota fallback, dual-LLM research, 4-layer abuse prevention.
We found that @leing2021/pi-search demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.