
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
pi-bash-image
Advanced tools
pi extension that lets bash return images inline.
Normally, seeing an image takes 2 calls:
bashreadThis adds a __PI_IMAGE__ helper so bash can return the image in the same result.
It reuses pi’s public read tool for image handling, so image processing matches pi’s read behavior.
pi install npm:pi-bash-image
# image in same result
agent-browser screenshot page.png && __PI_IMAGE__ page.png
# text + image together
agent-browser snapshot -i | __PI_IMAGE__ page.png
# multiple images
__PI_IMAGE__ before.png after.png
__PI_IMAGE__ shell helper into bashread would return for that imageMIT
FAQs
Inject images into bash tool results
We found that pi-bash-image demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.