{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "earendil-pi",
    "name": "Pi",
    "vendor": "Earendil",
    "vendorUrl": "https://pi.dev",
    "kind": "harness",
    "category": "agent-harnesses",
    "summary": "Pi is an open-source terminal coding agent from Earendil, run on the owner's machine with any of 15 or more model providers. It has interactive, print, JSON and RPC modes, a TypeScript SDK and a built-in MCP client.",
    "url": "https://www.anchorterminal.com/tools/earendil-pi",
    "markdownUrl": "https://www.anchorterminal.com/tools/earendil-pi.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/earendil-pi.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/earendil-pi.json",
    "repo": "https://github.com/earendil-works/pi",
    "license": "MIT",
    "transports": [],
    "packages": [
      {
        "registry": "npm",
        "name": "@earendil-works/pi-coding-agent"
      }
    ],
    "auth": "none",
    "authNotes": "No Pi account needed. Model providers are connected with `/login` (a subscription or an API key, stored in `~/.pi/agent/auth.json`) or with environment variables such as `ANTHROPIC_API_KEY`. MCP servers take headers, bearer tokens from the environment or OAuth, with tokens kept in `~/.pi/agent/mcp-auth.json`. Radius, the optional hosted gateway, needs its own sign-in or `RADIUS_API_KEY`.",
    "pricing": "free",
    "pricingNotes": "Free and MIT, with no paid edition of the harness. The owner pays the model provider. Radius, Earendil's optional hosted gateway, is an early alpha sold by prepaid credits, and no public price list was found (checked 2026-10-08).",
    "priceSummary": "Free · OSS",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the repository or the docs (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": 113417,
      "npmWeekly": 5201697,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://pi.dev/docs/latest",
    "capabilities": [
      "agent.harness",
      "agent.mcp-client"
    ],
    "tags": [
      "open-source",
      "local",
      "free",
      "no-card",
      "typescript",
      "mcp",
      "json-output",
      "rpc",
      "no-sandbox"
    ],
    "lastRelease": "2026-10-07",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 68.4,
      "grade": "B",
      "agentReady": false,
      "rank": 170,
      "ranked": true,
      "rankOf": 629,
      "categoryRank": 6,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 76,
        "maintenance": 87,
        "payments": 60,
        "reliability": 75,
        "schema": 84,
        "security": 61,
        "transparency": 64
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 75,
          "points": 15,
          "reason": "Read as a local package. `@earendil-works/pi-coding-agent` 1.1.0 on npm with Node.js 22.19 or newer stated, install scripts for macOS, Linux and Windows, Nix and standalone binaries (20). A public CI workflow builds, checks and tests on every push to main and runs an MCP client conformance job. The run on the commit we cloned (ce950d7, 8 October 2026) passed, but eight of the last 15 runs on main, all on 7 and 8 October, failed (15). The repository API reports 308 open issues and pull requests against 113,417 stars. Issues from new contributors are closed automatically and reviewed daily by maintainers, per CONTRIBUTING.md, so the open count understates what is reported, and we couldn't sample reply times (16). A dated changelog with Breaking Changes sections and migration steps, but the Azure provider rename shipped as a breaking change in patch release 1.0.3 on 5 October 2026, four days after 1.0.0 (9). 1.1.0, with 1.0.0 dated 1 October 2026 (15)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 84,
          "points": 13.65,
          "reason": "Harness reading, as for the other harnesses. JSON Schemas for settings, models, keybindings and themes ship in the package, and the JSON event stream and every RPC command are documented record by record, but as Markdown and TypeScript types with no machine-readable spec for the RPC protocol (18). pi.dev/llms.txt returns 404. Each docs page answers `Accept: text/markdown` with Markdown, and the docs ship inside the npm package (8). The integration page has a table saying when to use interactive, print, JSON, RPC or the SDK, and the MCP page gives a typical use for each exposure setting (17). Enumerated modes, thinking levels and exposure values, typed settings with defaults (13). A Python RPC client, a typed TypeScript client and about 75 example extensions, with command errors and parse errors shown as records (13). A dated changelog in the repository and at pi.dev/changelog with an RSS feed (15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 76,
          "points": 12.35,
          "reason": "Harness reading of the framework line, scored on what an agent or pipeline driving it has to supply. Four default tools (read, bash, edit, write) and a short system prompt. MCP tools default to `codemode` exposure, which keeps them out of the model's tool declarations, and `tool_search` loads deferred ones on demand (23). Automatic compaction, agent-level retry with three attempts and exponential backoff, and truncated tool output saved to a file. We found no turn or step limit in the CLI or settings reference (13). `--mode json` streams JSONL events ending in `agent_settled` and `--mode rpc` returns `success: false` with an error string. Print mode exits nonzero on a failed response, JSON mode doesn't (16). Sessions are stored as trees and continue, fork or take a fixed ID with `--continue`, `--fork` and `--session-id`. File changes have no built-in undo, and a git checkpoint is an example extension (14). It needs a provider key or subscription login before the first run, and the SDK is TypeScript only, with RPC for other languages (10)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 61,
          "points": 10.68,
          "reason": "Harness reading of the framework checklist, used for the harnesses in this category. 30 for what leaves the machine by default, 20 for approvals and sandboxing, 15 for prompt-injection posture, 15 for audit and 20 for the security programme. An anonymous install and update ping to pi.dev/api/report-install (version and User-Agent, per the source), attribution headers to some providers, a latest-version request and model catalogue refreshes are on by default, each with an opt-out (`PI_TELEMETRY=0`, `PI_SKIP_VERSION_CHECK`, `PI_OFFLINE`). Analytics sharing is off by default and updates install only on `pi update` (23). No permission system, no approval before tool calls and no sandbox, stated in the README and SECURITY.md. Project trust gates a repository's `.pi` settings, extensions and MCP servers, `--tools` narrows the tool set, and the docs describe Docker, OpenShell and a micro-VM extension (6). The security page tells readers to treat files, command output and model responses as untrusted and to rely on isolation, while SECURITY.md puts prompt injection out of scope and context files such as AGENTS.md load whatever the trust decision (7). Sessions are JSONL files on disk with HTML export, MCP server logs go to `~/.pi/agent/mcp.log`, and the JSON stream records each tool call (11). SECURITY.md gives security@earendil.com and GitHub private reporting, four advisories with CVEs were published with fixes, npm releases carry provenance from trusted publishing, and a scheduled workflow runs `npm audit`. No security.txt and no bounty found (14)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 60,
          "points": 7.5,
          "reason": "No payment protocol in the repository or docs (0). Read with the self-hosted rule. Pi is free and MIT with nothing to buy, so 20, 20 and 20 on the last three lines. Model costs go to whichever provider the owner configures. Radius, Earendil's optional hosted gateway, is an early alpha sold by prepaid credits, and we found no public price list for it."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 87,
          "points": 7.61,
          "reason": "v1.1.0 on 7 October 2026, one day before this check (30). 33 tagged releases since 10 July 2026 (20). Commits land daily and the changelog credits issues and outside pull requests in most releases. New contributors' issues are closed automatically, reviewed daily, and get no reply if they miss the quality bar, per CONTRIBUTING.md. Reply times weren't sampled because the GitHub API rate limit was reached (16). npm, the pi.dev installer, Nix and standalone binaries track each release, and npm publishes through GitHub Actions trusted publishing (14). Direct dependencies are pinned, a scheduled workflow runs `npm audit`, and CI passed on the commit we cloned after eight failures in the previous 14 runs (7)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 64,
          "points": 5.6,
          "note": "editorial 64, provenance 63",
          "reason": "MIT (30). No privacy policy for pi.dev or the CLI was found (pi.dev/privacy and earendil.com/privacy return 404). The docs say where sessions and credentials are stored and what `/share` and `/bug` upload. The Radius alpha terms of 1 September 2026 name Earendil Works Co. and refer to a Privacy Notice we couldn't locate (10). Breaking changes are listed per release with migration steps, with no deprecation policy or notice period found (8). Install telemetry and the version check are documented in the settings and environment-variable pages with opt-outs, though the docs don't list the fields sent (16)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Harness reading of the framework line, scored on what an agent or pipeline driving it has to supply. Four default tools (read, bash, edit, write) and a short system prompt. MCP tools default to `codemode` exposure, which keeps them out of the model's tool declarations, and `tool_search` loads deferred ones on demand (23). Automatic compaction, agent-level retry with three attempts and exponential backoff, and truncated tool output saved to a file. We found no turn or step limit in the CLI or settings reference (13). `--mode json` streams JSONL events ending in `agent_settled` and `--mode rpc` returns `success: false` with an error string. Print mode exits nonzero on a failed response, JSON mode doesn't (16). Sessions are stored as trees and continue, fork or take a fixed ID with `--continue`, `--fork` and `--session-id`. File changes have no built-in undo, and a git checkpoint is an example extension (14). It needs a provider key or subscription login before the first run, and the SDK is TypeScript only, with RPC for other languages (10).",
          "maintenance": "v1.1.0 on 7 October 2026, one day before this check (30). 33 tagged releases since 10 July 2026 (20). Commits land daily and the changelog credits issues and outside pull requests in most releases. New contributors' issues are closed automatically, reviewed daily, and get no reply if they miss the quality bar, per CONTRIBUTING.md. Reply times weren't sampled because the GitHub API rate limit was reached (16). npm, the pi.dev installer, Nix and standalone binaries track each release, and npm publishes through GitHub Actions trusted publishing (14). Direct dependencies are pinned, a scheduled workflow runs `npm audit`, and CI passed on the commit we cloned after eight failures in the previous 14 runs (7).",
          "payments": "No payment protocol in the repository or docs (0). Read with the self-hosted rule. Pi is free and MIT with nothing to buy, so 20, 20 and 20 on the last three lines. Model costs go to whichever provider the owner configures. Radius, Earendil's optional hosted gateway, is an early alpha sold by prepaid credits, and we found no public price list for it.",
          "reliability": "Read as a local package. `@earendil-works/pi-coding-agent` 1.1.0 on npm with Node.js 22.19 or newer stated, install scripts for macOS, Linux and Windows, Nix and standalone binaries (20). A public CI workflow builds, checks and tests on every push to main and runs an MCP client conformance job. The run on the commit we cloned (ce950d7, 8 October 2026) passed, but eight of the last 15 runs on main, all on 7 and 8 October, failed (15). The repository API reports 308 open issues and pull requests against 113,417 stars. Issues from new contributors are closed automatically and reviewed daily by maintainers, per CONTRIBUTING.md, so the open count understates what is reported, and we couldn't sample reply times (16). A dated changelog with Breaking Changes sections and migration steps, but the Azure provider rename shipped as a breaking change in patch release 1.0.3 on 5 October 2026, four days after 1.0.0 (9). 1.1.0, with 1.0.0 dated 1 October 2026 (15).",
          "schema": "Harness reading, as for the other harnesses. JSON Schemas for settings, models, keybindings and themes ship in the package, and the JSON event stream and every RPC command are documented record by record, but as Markdown and TypeScript types with no machine-readable spec for the RPC protocol (18). pi.dev/llms.txt returns 404. Each docs page answers `Accept: text/markdown` with Markdown, and the docs ship inside the npm package (8). The integration page has a table saying when to use interactive, print, JSON, RPC or the SDK, and the MCP page gives a typical use for each exposure setting (17). Enumerated modes, thinking levels and exposure values, typed settings with defaults (13). A Python RPC client, a typed TypeScript client and about 75 example extensions, with command errors and parse errors shown as records (13). A dated changelog in the repository and at pi.dev/changelog with an RSS feed (15).",
          "security": "Harness reading of the framework checklist, used for the harnesses in this category. 30 for what leaves the machine by default, 20 for approvals and sandboxing, 15 for prompt-injection posture, 15 for audit and 20 for the security programme. An anonymous install and update ping to pi.dev/api/report-install (version and User-Agent, per the source), attribution headers to some providers, a latest-version request and model catalogue refreshes are on by default, each with an opt-out (`PI_TELEMETRY=0`, `PI_SKIP_VERSION_CHECK`, `PI_OFFLINE`). Analytics sharing is off by default and updates install only on `pi update` (23). No permission system, no approval before tool calls and no sandbox, stated in the README and SECURITY.md. Project trust gates a repository's `.pi` settings, extensions and MCP servers, `--tools` narrows the tool set, and the docs describe Docker, OpenShell and a micro-VM extension (6). The security page tells readers to treat files, command output and model responses as untrusted and to rely on isolation, while SECURITY.md puts prompt injection out of scope and context files such as AGENTS.md load whatever the trust decision (7). Sessions are JSONL files on disk with HTML export, MCP server logs go to `~/.pi/agent/mcp.log`, and the JSON stream records each tool call (11). SECURITY.md gives security@earendil.com and GitHub private reporting, four advisories with CVEs were published with fixes, npm releases carry provenance from trusted publishing, and a scheduled workflow runs `npm audit`. No security.txt and no bounty found (14).",
          "transparency": "MIT (30). No privacy policy for pi.dev or the CLI was found (pi.dev/privacy and earendil.com/privacy return 404). The docs say where sessions and credentials are stored and what `/share` and `/bug` upload. The Radius alpha terms of 1 September 2026 name Earendil Works Co. and refer to a Privacy Notice we couldn't locate (10). Breaking changes are listed per release with migration steps, with no deprecation policy or notice period found (8). Install telemetry and the version check are documented in the settings and environment-variable pages with opt-outs, though the docs don't list the fields sent (16)."
        },
        "sources": [
          {
            "what": "repository README",
            "url": "https://github.com/earendil-works/pi",
            "seen": "2026-10-08"
          },
          {
            "what": "security policy",
            "url": "https://github.com/earendil-works/pi/blob/main/SECURITY.md",
            "seen": "2026-10-08"
          },
          {
            "what": "contribution rules and issue gate",
            "url": "https://github.com/earendil-works/pi/blob/main/CONTRIBUTING.md",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog",
            "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/CHANGELOG.md",
            "seen": "2026-10-08"
          },
          {
            "what": "security and project trust (docs)",
            "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/security.md",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP servers (docs)",
            "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/mcp.md",
            "seen": "2026-10-08"
          },
          {
            "what": "command line (docs)",
            "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/cli.md",
            "seen": "2026-10-08"
          },
          {
            "what": "CLI integration, JSON and RPC modes (docs)",
            "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/cli-integration.md",
            "seen": "2026-10-08"
          },
          {
            "what": "RPC protocol (docs)",
            "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/rpc.md",
            "seen": "2026-10-08"
          },
          {
            "what": "settings, telemetry and retry (docs)",
            "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/settings.md",
            "seen": "2026-10-08"
          },
          {
            "what": "environment variables (docs)",
            "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/environment-variables.md",
            "seen": "2026-10-08"
          },
          {
            "what": "sessions, share and bug report (docs)",
            "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/sessions.md",
            "seen": "2026-10-08"
          },
          {
            "what": "isolation methods (docs)",
            "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/containerization.md",
            "seen": "2026-10-08"
          },
          {
            "what": "install ping in the source",
            "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/src/modes/interactive/interactive-mode.ts",
            "seen": "2026-10-08"
          },
          {
            "what": "CI workflow",
            "url": "https://github.com/earendil-works/pi/blob/main/.github/workflows/ci.yml",
            "seen": "2026-10-08"
          },
          {
            "what": "CI runs on main",
            "url": "https://api.github.com/repos/earendil-works/pi/actions/workflows/ci.yml/runs?branch=main",
            "seen": "2026-10-08"
          },
          {
            "what": "repository statistics",
            "url": "https://api.github.com/repos/earendil-works/pi",
            "seen": "2026-10-08"
          },
          {
            "what": "security advisories",
            "url": "https://github.com/earendil-works/pi/security/advisories",
            "seen": "2026-10-08"
          },
          {
            "what": "npm latest, engines and provenance",
            "url": "https://registry.npmjs.org/@earendil-works/pi-coding-agent/latest",
            "seen": "2026-10-08"
          },
          {
            "what": "npm weekly downloads",
            "url": "https://api.npmjs.org/downloads/point/last-week/@earendil-works/pi-coding-agent",
            "seen": "2026-10-08"
          },
          {
            "what": "product site",
            "url": "https://pi.dev/",
            "seen": "2026-10-08"
          },
          {
            "what": "changelog page",
            "url": "https://pi.dev/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "docs page served as Markdown",
            "url": "https://pi.dev/docs/latest/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt (404)",
            "url": "https://pi.dev/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "llms.txt (404)",
            "url": "https://pi.dev/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "Radius overview",
            "url": "https://radius.earendil.com/",
            "seen": "2026-10-08"
          },
          {
            "what": "Radius alpha terms",
            "url": "https://radius.earendil.com/terms",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for pi.dev",
            "url": "https://rdap.org/domain/pi.dev",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: issue and pull request reply times, and separate open issue and pull request counts. The GitHub API rate limit was reached, so only the combined count of 308 was read",
          "unchecked: why eight of the last 15 CI runs on main failed. The run logs weren't read",
          "The Privacy Notice the Radius alpha terms refer to wasn't found, and no privacy policy for pi.dev or the CLI was found",
          "The legal entity is unclear. The pi.dev footer reads Earendil Inc. and the Radius terms name Earendil Works Co.",
          "No public price list for Radius credits was found. Radius is optional and wasn't graded",
          "The date of Pi's first release wasn't established. The changelog starts at 0.10.0 on 25 November 2025 and the repository was created on 9 August 2025",
          "The scout said MCP wasn't mentioned in the README. Pi has had a built-in MCP client since 0.99.0 on 29 September 2026, documented in docs/mcp.md"
        ]
      },
      "negative": -4,
      "negativeNotes": [
        "2026-06-08. GHSA-jfgx-wxx8-mp94 (CVE-2026-54328, high). Temporary extension installs used predictable paths under the system temp directory, so another local user on a shared Linux host could plant extension code that Pi then loaded. Fixed in 0.78.1. Fixed, published and four months old, -2. https://github.com/earendil-works/pi/security/advisories/GHSA-jfgx-wxx8-mp94",
        "2026-06-08. GHSA-mqxh-6gq7-558m (CVE-2026-54325, medium). Before 0.79.0 Pi loaded a repository's `.pi` settings and extensions without asking, so starting it in a cloned repository could run that repository's code. Fixed in 0.79.0 with project trust. Fixed and published, -2. https://github.com/earendil-works/pi/security/advisories/GHSA-mqxh-6gq7-558m",
        "2026-06-08. GHSA-7v5m-pr3q-6453 (CVE-2026-54326, low, XSS in HTML session exports) and GHSA-r95r-rj6r-c39x (CVE-2026-54327, low, a race in `auth.json` permissions). Both fixed in 0.78.1. Recorded without a deduction. https://github.com/earendil-works/pi/security/advisories"
      ],
      "verdict": "Four default tools, a JSONL event stream, an RPC mode and MCP tools kept out of the model's declarations by default keep context small and scripting simple. Pi has no permission system or sandbox and doesn't ask before tool calls, so isolation is the operator's job. Version 1.0.0 is dated 1 October 2026.",
      "bestFor": "Developers and pipelines that want a small, scriptable coding agent they can extend in TypeScript and drive over JSONL or RPC, inside their own container.",
      "strengths": [
        "Four default tools (read, bash, edit, write), with MCP tools reachable through codemode scripts and not declared to the model by default",
        "`--mode json` streams JSONL events and `--mode rpc` takes JSONL commands, both documented record by record, with a Python client example",
        "Built-in MCP client for stdio and streamable HTTP servers with OAuth, per-tool exposure settings and a conformance job in CI",
        "Project trust stops a repository's `.pi` settings, extensions and MCP servers loading until approved, and non-interactive modes skip them by default",
        "npm releases carry SLSA provenance from GitHub Actions trusted publishing, and the installer pins transitive dependencies"
      ],
      "weaknesses": [
        "No permission system or sandbox. Tool calls run with the user's rights and without an approval prompt",
        "An anonymous install and update ping to pi.dev and a latest-version request are on by default",
        "Four advisories published on 8 June 2026, one rated high and one medium, all fixed by 0.79.0",
        "No privacy policy for pi.dev or the CLI found, and pi.dev has no security.txt",
        "Eight of the last 15 CI runs on main failed on 7 and 8 October 2026, and a breaking provider rename shipped in patch release 1.0.3"
      ],
      "agentNotes": [
        "Run Pi inside a container or VM for unattended work. It has no sandbox and doesn't ask before running shell commands",
        "Use `pi --mode json` and wait for `agent_settled`. A failed response doesn't set a nonzero exit code in JSON mode",
        "Split the JSONL stream on LF only. Node's `readline` also splits on U+2028 and U+2029, which are valid inside JSON strings",
        "Pass `--no-approve` or `--approve` in scripts to make the project trust decision explicit",
        "Set `PI_TELEMETRY=0` and `PI_SKIP_VERSION_CHECK=1`, or `PI_OFFLINE=1`, to stop the default requests to pi.dev"
      ],
      "metrics": {
        "kind": "local",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 68.4
        }
      ],
      "editorialScores": {
        "ergonomics": 76,
        "maintenance": 87,
        "payments": 60,
        "reliability": 75,
        "schema": 84,
        "security": 61,
        "transparency": 64
      },
      "provenanceScore": 63
    },
    "connect": {
      "install": "curl -fsSL https://pi.dev/install.sh | sh   # or: npm install -g --ignore-scripts @earendil-works/pi-coding-agent",
      "headless": {
        "command": "pi --mode json --no-session --no-approve \"$TASK\"",
        "env": {
          "PI_SKIP_VERSION_CHECK": "1",
          "PI_TELEMETRY": "0"
        }
      }
    },
    "letme": {
      "capability": "https://letme.dev/agent.harness",
      "tool": "https://letme.dev/earendil-pi"
    },
    "notable": [
      "The README says Pi has no built-in permission system for filesystem, process, network or credential access and runs with the rights of the user who launched it (https://github.com/earendil-works/pi)",
      "1.0.0 is dated 1 October 2026 and 1.1.0 followed on 7 October 2026, after 0.x releases going back to at least November 2025 (https://github.com/earendil-works/pi/blob/main/packages/coding-agent/CHANGELOG.md)",
      "A built-in MCP client for stdio and streamable HTTP servers arrived in 0.99.0 on 29 September 2026. MCP tools default to `codemode` exposure and aren't declared to the model (https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/mcp.md)",
      "Project trust gates a repository's `.pi` settings, extensions and MCP servers. Print, JSON and RPC modes skip them unless `--approve` is passed or the default is changed (https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/security.md)",
      "Four advisories with CVEs were published on 8 June 2026, one high and one medium, all fixed by 0.79.0 (https://github.com/earendil-works/pi/security/advisories)",
      "An anonymous install and update ping to pi.dev is on by default and is turned off with `PI_TELEMETRY=0` or `enableInstallTelemetry` (https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/settings.md)",
      "Issues and pull requests from new contributors are closed automatically and reviewed daily by maintainers (https://github.com/earendil-works/pi/blob/main/CONTRIBUTING.md)",
      "The repository was badlogic/pi-mono, and the old path redirects to earendil-works/pi (https://github.com/earendil-works/pi)"
    ],
    "area": "frameworks",
    "details": [
      {
        "label": "Interfaces",
        "value": "Terminal UI, print mode (`--print`), JSON mode (`--mode json`, JSONL events), RPC mode (`--mode rpc`, JSONL commands on stdin), TypeScript SDK, extensions, skills, prompt templates and Pi packages"
      },
      {
        "label": "Built-in tools",
        "value": "read, bash, edit and write by default. powershell on Windows, grep, find and ls available. codemode (JavaScript in a QuickJS sandbox that calls the other tools) and tool_search are off until enabled or an MCP server needs them"
      },
      {
        "label": "Approvals",
        "value": "None for tool calls. Project trust asks before loading a repository's `.pi` settings, extensions, skills and MCP servers, and `--tools`, `--exclude-tools` and `--no-tools` narrow the tool set"
      },
      {
        "label": "Sandbox",
        "value": "None. The docs describe plain Docker, Docker Sandboxes, OpenShell and a Gondolin micro-VM extension"
      },
      {
        "label": "MCP client",
        "value": "stdio and streamable HTTP, no SSE. OAuth with dynamic registration, a registered client or a Client ID Metadata Document. Exposure per server or tool is codemode (default), deferred, direct or hidden"
      },
      {
        "label": "Models",
        "value": "15 or more providers per pi.dev, among them Anthropic, OpenAI, Google, Azure, Bedrock, Mistral, Groq, xAI, OpenRouter, Ollama and llama.cpp, by API key or subscription login, plus custom providers in `models.json`"
      },
      {
        "label": "Sessions",
        "value": "JSONL trees under `~/.pi/agent/sessions/`, with `--continue`, `--fork`, `--session-id` and `--no-session`, automatic compaction, HTML export, and `/share` to a private GitHub gist or a Radius artifact"
      },
      {
        "label": "Telemetry",
        "value": "Anonymous install and update ping to pi.dev, provider attribution headers and a latest-version request on by default, with `PI_TELEMETRY=0`, `PI_SKIP_VERSION_CHECK` and `PI_OFFLINE` as opt-outs. Analytics sharing is off by default"
      },
      {
        "label": "Runtime",
        "value": "Node.js 22.19 or newer. Installers for macOS, Linux and Windows, npm, Nix and standalone binaries"
      },
      {
        "label": "Releases in 90 days",
        "value": "33 tags since 10 July 2026, with 1.0.0 on 1 October and 1.1.0 on 7 October 2026"
      },
      {
        "label": "Advisories",
        "value": "Four published on 8 June 2026 (CVE-2026-54325 to CVE-2026-54328), fixed in 0.78.1 and 0.79.0"
      }
    ],
    "provenance": {
      "legalEntity": "Earendil Inc.",
      "domain": "pi.dev",
      "domainRegistered": "2024-01-30",
      "endpointOnVendorDomain": null,
      "terms": "",
      "privacy": "",
      "statusPage": "",
      "changelog": "https://pi.dev/changelog",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The pi.dev and earendil.com footers read Earendil Inc. The Radius alpha terms of 1 September 2026 name Earendil Works Co., and the README calls the company Earendil Works.",
        "We found no terms or privacy page for pi.dev or the CLI. pi.dev/terms, pi.dev/privacy and earendil.com/privacy return 404. Terms exist only for Radius, at radius.earendil.com/terms.",
        "pi.dev/.well-known/security.txt and earendil.com/.well-known/security.txt return 404. SECURITY.md gives security@earendil.com and GitHub private reporting.",
        "RDAP for pi.dev gives a registration date of 2024-01-30 with Cloudflare as registrar. The README says the domain was donated by exe.dev.",
        "The repository moved from badlogic/pi-mono to earendil-works/pi, and the npm package from @mariozechner/pi-coding-agent to @earendil-works/pi-coding-agent at 0.74.0, per the advisories."
      ],
      "score": 63,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Earendil Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "pi.dev, registered 2024-01-30 (2 years)",
          "points": 7,
          "max": 15,
          "state": "part"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "no hosted endpoint",
          "points": 0,
          "max": 0,
          "state": "na"
        },
        {
          "check": "Terms of service",
          "value": "nothing hosted, so the MIT licence stands in",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Privacy policy",
          "value": "nothing hosted, not scored",
          "points": 0,
          "max": 0,
          "state": "na"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/earendil-pi.json",
    "live": {
      "slug": "earendil-pi",
      "versions": [
        {
          "registry": "github",
          "name": "earendil-works/pi",
          "version": "v1.1.0",
          "released": "2026-10-07",
          "seenAt": "2026-10-08T16:09:44.573412777Z"
        },
        {
          "registry": "npm",
          "name": "@earendil-works/pi-coding-agent",
          "version": "1.1.0",
          "seenAt": "2026-10-08T16:09:41.369786574Z"
        }
      ],
      "githubStars": 113482,
      "npmWeekly": 5201697,
      "securityTxt": {
        "url": "https://pi.dev/.well-known/security.txt",
        "state": "none",
        "checkedAt": "2026-10-08T15:38:42.51766104Z"
      },
      "pages": [
        {
          "url": "https://pi.dev/changelog",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:22:53.741589246Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "82f9cb8bddf7"
        }
      ],
      "updatedAt": "2026-10-08T18:22:53.741589246Z"
    }
  }
}
