
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
pi-compound-engineering
Advanced tools
Pi-native Compound Engineering package for iterative development workflows
A Pi-native Compound Engineering package for iterative development workflows in Pi.
pi install /absolute/path/to/pi-compound-engineering
pi install /absolute/path/to/pi-compound-engineering -l
pi install npm:pi-compound-engineering
ce-help — explain which workflow step to usece-status — inspect repo-local workflow statece-next — get a recommendation for the next workflow stepce-worktree — create and manage git worktrees for isolated feature developmentce-brainstorm — create requirements artifacts in docs/brainstorms/ce-plan — create implementation plans in docs/plans/ce-work — execute plan-driven work in Phase 1 modece-review — review changes with structured findingsce-compound — capture reusable learnings in docs/solutions/skills/ — workflow semanticsextensions/ce-core/ — runtime tools for artifact handling, questions, and subagentsThis package uses repo-local workflow artifacts:
docs/brainstorms/docs/plans/docs/solutions/.context/compound-engineering/Phase 1 intentionally ships a basic but working CE loop:
ce-work and ce-reviewce-core runtime tools for artifact handling, structured questions, and serial subagentsIt does not yet include richer review autofix flows, worktree orchestration, session-history integrations, or ce-next style navigation.
pattern_extractor extension tool: extract recurring patterns from artifacts and categorize themextract (keyword-based pattern detection) and categorize (group patterns by type) operationsce-compound SKILL.md to use pattern_extractor for smarter solution generationsession_history extension tool: record, query, and list CE skill execution history.context/compound-engineering/history/ as lightweight JSON filesce-status and ce-next to leverage session history for smarter recommendationsplan_diff extension tool: compare and patch plan units for incremental plan updatescompare (detect added/removed/modified/unchanged units) and patch (apply changes) operationsce-plan SKILL.md with incremental update workflow using plan_diffbrainstorm_dialog extension tool: manage multi-round brainstorm conversations with start/refine/summarize operationsce-brainstorm SKILL.md with iterative refinement workflow using brainstorm_dialog.context/compound-engineering/dialogs/task_splitter extension tool: file-based dependency analysis with union-find algorithmce-work to use task_splitter for intelligent parallel vs serial execution decisionssession_checkpoint extension tool: save, load, and list plan execution checkpoints for resume-from-checkpoint behaviorce-work to use session_checkpoint for automatic resume on interrupted plan execution.context/compound-engineering/checkpoints/ as lightweight JSON filesparallel_subagent extension tool: run multiple independent skill-based tasks concurrently with Promise.allSettledce-work to recommend parallel execution for independent implementation unitsreview_router extension tool: analyzes diff metadata (file types, change size, paths) and recommends reviewer personasce-review skill to use review_router for automatic reviewer routingfindings-schema.md with autofix tracking fieldsreviewer-selection.md with richer persona definitions and review_router integrationhandoff.md with autofix loop supportworktree_manager extension tool: git worktree lifecycle (create, detect, merge, cleanup) with dependency injectionce-worktree skill: standalone worktree management using worktree_managerce-work to detect and recommend worktree isolationworkflow_state extension tool: scans artifact directories and returns structured workflow statece-next skill: uses workflow_state to recommend the single best next skillce-status to reference workflow_state tooltest.yml (push/PR to main) and publish.yml (tag-triggered npm publish)setup-node with registry-url and permissions: contents: readbrainstorm → plan → work → review → compound producing real artifactsreferences/ directories to ce-help and ce-status for structural consistencyartifact_helper run-type ensureDir to create the parent directory, not the run path itselfindex.ts exports to only expose public API functionsbun.lock to version controlce-brainstorm, ce-plan, ce-work, ce-review, ce-compound, ce-help, ce-statusce-core extension with artifact_helper, ask_user_question, and subagent toolshttps://github.com/leing2021/pi-compound-engineeringhttps://www.npmjs.com/package/pi-compound-engineeringbun test
npm publish --dry-run
test.yml runs bun test on every push and pull request to main.
publish.yml runs bun test then npm publish when a version tag (v*) is pushed.
package.jsonREADME.md Changeloggit commit -m "chore: bump to x.y.z"git tag vx.y.zgit push origin main --tagsSet NPM_TOKEN in GitHub repo settings → Secrets → Actions.
FAQs
Compound Engineering for Pi: brainstorm, plan, work, review, and compound.
The npm package pi-compound-engineering receives a total of 79 weekly downloads. As such, pi-compound-engineering popularity was classified as not popular.
We found that pi-compound-engineering demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.