
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
pi-agentsmd
Advanced tools
Teach Pi and other coding agents how your repository works with one command.
pi-agentsmd analyzes your project and creates a tailored AGENTS.md with the commands, conventions, and contribution guidance agents need to make better changes from their first turn.
/init to generate guidance at the repository root.--force.Install from npm:
pi install npm:pi-agentsmd
Install project-locally:
pi install -l npm:pi-agentsmd
During local development from this monorepo:
pi install /path/to/pi-mono/packages/pi-agentsmd
Run the /init command inside a repository:
/init
Pi will inspect executable configuration and repository documentation, then include only verified guidance that is useful for the project. This can cover:
The generated file refers to authoritative project documents instead of duplicating them. The model is instructed not to run project commands or install dependencies during generation.
If AGENTS.md already exists, use --force to reconcile it:
/init --force
Force mode preserves accurate project guidance while correcting stale or duplicate information.
The /init command sends a structured prompt to the active AI model. The model uses its file tools to inspect the repository and generate an AGENTS.md file tailored to the project. The package itself does not write the file — it delegates entirely to the model.
Requirements:
npm install
npm run check
npm run pack:dry-run
Contributions are welcome. See CONTRIBUTING.md for development workflow and pull request guidelines.
MIT. See LICENSE.
Includes a prompt derived from OpenAI Codex, licensed under the Apache License 2.0. See THIRD-PARTY-NOTICES.
FAQs
Generate AGENTS.md contributor guides for Pi repositories.
We found that pi-agentsmd demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.