{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/goose.json",
        "name": "goose",
        "score": 73.9,
        "shared": [
          "agent.harness",
          "agent.mcp-client"
        ],
        "slug": "goose"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/openai-codex.json",
        "name": "OpenAI Codex",
        "score": 73,
        "shared": [
          "agent.harness",
          "agent.mcp-client"
        ],
        "slug": "openai-codex"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/qwen-code.json",
        "name": "Qwen Code",
        "score": 72.4,
        "shared": [
          "agent.harness",
          "agent.mcp-client"
        ],
        "slug": "qwen-code"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/gemini-cli.json",
        "name": "Gemini CLI",
        "score": 72,
        "shared": [
          "agent.harness",
          "agent.mcp-client"
        ],
        "slug": "gemini-cli"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/openhands.json",
        "name": "OpenHands",
        "score": 70.8,
        "shared": [
          "agent.harness",
          "agent.mcp-client"
        ],
        "slug": "openhands"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/opencode.json",
        "name": "OpenCode",
        "score": 67.7,
        "shared": [
          "agent.harness",
          "agent.mcp-client"
        ],
        "slug": "opencode"
      }
    ],
    "tool": {
      "slug": "earendil-pi",
      "name": "Pi",
      "vendor": "Earendil",
      "vendorUrl": "https://pi.dev",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "Pi is an open-source terminal coding agent from Earendil, run on the owner's machine with any of 15 or more model providers. It has interactive, print, JSON and RPC modes, a TypeScript SDK and a built-in MCP client.",
      "url": "https://www.anchorterminal.com/tools/earendil-pi",
      "markdownUrl": "https://www.anchorterminal.com/tools/earendil-pi.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/earendil-pi.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/earendil-pi.json",
      "repo": "https://github.com/earendil-works/pi",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@earendil-works/pi-coding-agent"
        }
      ],
      "auth": "none",
      "authNotes": "No Pi account needed. Model providers are connected with `/login` (a subscription or an API key, stored in `~/.pi/agent/auth.json`) or with environment variables such as `ANTHROPIC_API_KEY`. MCP servers take headers, bearer tokens from the environment or OAuth, with tokens kept in `~/.pi/agent/mcp-auth.json`. Radius, the optional hosted gateway, needs its own sign-in or `RADIUS_API_KEY`.",
      "pricing": "free",
      "pricingNotes": "Free and MIT, with no paid edition of the harness. The owner pays the model provider. Radius, Earendil's optional hosted gateway, is an early alpha sold by prepaid credits, and no public price list was found (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the repository or the docs (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 113417,
        "npmWeekly": 5201697,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://pi.dev/docs/latest",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client"
      ],
      "tags": [
        "open-source",
        "local",
        "free",
        "no-card",
        "typescript",
        "mcp",
        "json-output",
        "rpc",
        "no-sandbox"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 68.4,
        "grade": "B",
        "agentReady": false,
        "rank": 180,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 76,
          "maintenance": 87,
          "payments": 60,
          "reliability": 75,
          "schema": 84,
          "security": 61,
          "transparency": 64
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 75,
            "points": 15,
            "reason": "Read as a local package. `@earendil-works/pi-coding-agent` 1.1.0 on npm with Node.js 22.19 or newer stated, install scripts for macOS, Linux and Windows, Nix and standalone binaries (20). A public CI workflow builds, checks and tests on every push to main and runs an MCP client conformance job. The run on the commit we cloned (ce950d7, 8 October 2026) passed, but eight of the last 15 runs on main, all on 7 and 8 October, failed (15). The repository API reports 308 open issues and pull requests against 113,417 stars. Issues from new contributors are closed automatically and reviewed daily by maintainers, per CONTRIBUTING.md, so the open count understates what is reported, and we couldn't sample reply times (16). A dated changelog with Breaking Changes sections and migration steps, but the Azure provider rename shipped as a breaking change in patch release 1.0.3 on 5 October 2026, four days after 1.0.0 (9). 1.1.0, with 1.0.0 dated 1 October 2026 (15)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 84,
            "points": 13.65,
            "reason": "Harness reading, as for the other harnesses. JSON Schemas for settings, models, keybindings and themes ship in the package, and the JSON event stream and every RPC command are documented record by record, but as Markdown and TypeScript types with no machine-readable spec for the RPC protocol (18). pi.dev/llms.txt returns 404. Each docs page answers `Accept: text/markdown` with Markdown, and the docs ship inside the npm package (8). The integration page has a table saying when to use interactive, print, JSON, RPC or the SDK, and the MCP page gives a typical use for each exposure setting (17). Enumerated modes, thinking levels and exposure values, typed settings with defaults (13). A Python RPC client, a typed TypeScript client and about 75 example extensions, with command errors and parse errors shown as records (13). A dated changelog in the repository and at pi.dev/changelog with an RSS feed (15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 76,
            "points": 12.35,
            "reason": "Harness reading of the framework line, scored on what an agent or pipeline driving it has to supply. Four default tools (read, bash, edit, write) and a short system prompt. MCP tools default to `codemode` exposure, which keeps them out of the model's tool declarations, and `tool_search` loads deferred ones on demand (23). Automatic compaction, agent-level retry with three attempts and exponential backoff, and truncated tool output saved to a file. We found no turn or step limit in the CLI or settings reference (13). `--mode json` streams JSONL events ending in `agent_settled` and `--mode rpc` returns `success: false` with an error string. Print mode exits nonzero on a failed response, JSON mode doesn't (16). Sessions are stored as trees and continue, fork or take a fixed ID with `--continue`, `--fork` and `--session-id`. File changes have no built-in undo, and a git checkpoint is an example extension (14). It needs a provider key or subscription login before the first run, and the SDK is TypeScript only, with RPC for other languages (10)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 61,
            "points": 10.68,
            "reason": "Harness reading of the framework checklist, used for the harnesses in this category. 30 for what leaves the machine by default, 20 for approvals and sandboxing, 15 for prompt-injection posture, 15 for audit and 20 for the security programme. An anonymous install and update ping to pi.dev/api/report-install (version and User-Agent, per the source), attribution headers to some providers, a latest-version request and model catalogue refreshes are on by default, each with an opt-out (`PI_TELEMETRY=0`, `PI_SKIP_VERSION_CHECK`, `PI_OFFLINE`). Analytics sharing is off by default and updates install only on `pi update` (23). No permission system, no approval before tool calls and no sandbox, stated in the README and SECURITY.md. Project trust gates a repository's `.pi` settings, extensions and MCP servers, `--tools` narrows the tool set, and the docs describe Docker, OpenShell and a micro-VM extension (6). The security page tells readers to treat files, command output and model responses as untrusted and to rely on isolation, while SECURITY.md puts prompt injection out of scope and context files such as AGENTS.md load whatever the trust decision (7). Sessions are JSONL files on disk with HTML export, MCP server logs go to `~/.pi/agent/mcp.log`, and the JSON stream records each tool call (11). SECURITY.md gives security@earendil.com and GitHub private reporting, four advisories with CVEs were published with fixes, npm releases carry provenance from trusted publishing, and a scheduled workflow runs `npm audit`. No security.txt and no bounty found (14)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 60,
            "points": 7.5,
            "reason": "No payment protocol in the repository or docs (0). Read with the self-hosted rule. Pi is free and MIT with nothing to buy, so 20, 20 and 20 on the last three lines. Model costs go to whichever provider the owner configures. Radius, Earendil's optional hosted gateway, is an early alpha sold by prepaid credits, and we found no public price list for it."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 87,
            "points": 7.61,
            "reason": "v1.1.0 on 7 October 2026, one day before this check (30). 33 tagged releases since 10 July 2026 (20). Commits land daily and the changelog credits issues and outside pull requests in most releases. New contributors' issues are closed automatically, reviewed daily, and get no reply if they miss the quality bar, per CONTRIBUTING.md. Reply times weren't sampled because the GitHub API rate limit was reached (16). npm, the pi.dev installer, Nix and standalone binaries track each release, and npm publishes through GitHub Actions trusted publishing (14). Direct dependencies are pinned, a scheduled workflow runs `npm audit`, and CI passed on the commit we cloned after eight failures in the previous 14 runs (7)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 64,
            "points": 5.6,
            "note": "editorial 64, provenance 63",
            "reason": "MIT (30). No privacy policy for pi.dev or the CLI was found (pi.dev/privacy and earendil.com/privacy return 404). The docs say where sessions and credentials are stored and what `/share` and `/bug` upload. The Radius alpha terms of 1 September 2026 name Earendil Works Co. and refer to a Privacy Notice we couldn't locate (10). Breaking changes are listed per release with migration steps, with no deprecation policy or notice period found (8). Install telemetry and the version check are documented in the settings and environment-variable pages with opt-outs, though the docs don't list the fields sent (16)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Harness reading of the framework line, scored on what an agent or pipeline driving it has to supply. Four default tools (read, bash, edit, write) and a short system prompt. MCP tools default to `codemode` exposure, which keeps them out of the model's tool declarations, and `tool_search` loads deferred ones on demand (23). Automatic compaction, agent-level retry with three attempts and exponential backoff, and truncated tool output saved to a file. We found no turn or step limit in the CLI or settings reference (13). `--mode json` streams JSONL events ending in `agent_settled` and `--mode rpc` returns `success: false` with an error string. Print mode exits nonzero on a failed response, JSON mode doesn't (16). Sessions are stored as trees and continue, fork or take a fixed ID with `--continue`, `--fork` and `--session-id`. File changes have no built-in undo, and a git checkpoint is an example extension (14). It needs a provider key or subscription login before the first run, and the SDK is TypeScript only, with RPC for other languages (10).",
            "maintenance": "v1.1.0 on 7 October 2026, one day before this check (30). 33 tagged releases since 10 July 2026 (20). Commits land daily and the changelog credits issues and outside pull requests in most releases. New contributors' issues are closed automatically, reviewed daily, and get no reply if they miss the quality bar, per CONTRIBUTING.md. Reply times weren't sampled because the GitHub API rate limit was reached (16). npm, the pi.dev installer, Nix and standalone binaries track each release, and npm publishes through GitHub Actions trusted publishing (14). Direct dependencies are pinned, a scheduled workflow runs `npm audit`, and CI passed on the commit we cloned after eight failures in the previous 14 runs (7).",
            "payments": "No payment protocol in the repository or docs (0). Read with the self-hosted rule. Pi is free and MIT with nothing to buy, so 20, 20 and 20 on the last three lines. Model costs go to whichever provider the owner configures. Radius, Earendil's optional hosted gateway, is an early alpha sold by prepaid credits, and we found no public price list for it.",
            "reliability": "Read as a local package. `@earendil-works/pi-coding-agent` 1.1.0 on npm with Node.js 22.19 or newer stated, install scripts for macOS, Linux and Windows, Nix and standalone binaries (20). A public CI workflow builds, checks and tests on every push to main and runs an MCP client conformance job. The run on the commit we cloned (ce950d7, 8 October 2026) passed, but eight of the last 15 runs on main, all on 7 and 8 October, failed (15). The repository API reports 308 open issues and pull requests against 113,417 stars. Issues from new contributors are closed automatically and reviewed daily by maintainers, per CONTRIBUTING.md, so the open count understates what is reported, and we couldn't sample reply times (16). A dated changelog with Breaking Changes sections and migration steps, but the Azure provider rename shipped as a breaking change in patch release 1.0.3 on 5 October 2026, four days after 1.0.0 (9). 1.1.0, with 1.0.0 dated 1 October 2026 (15).",
            "schema": "Harness reading, as for the other harnesses. JSON Schemas for settings, models, keybindings and themes ship in the package, and the JSON event stream and every RPC command are documented record by record, but as Markdown and TypeScript types with no machine-readable spec for the RPC protocol (18). pi.dev/llms.txt returns 404. Each docs page answers `Accept: text/markdown` with Markdown, and the docs ship inside the npm package (8). The integration page has a table saying when to use interactive, print, JSON, RPC or the SDK, and the MCP page gives a typical use for each exposure setting (17). Enumerated modes, thinking levels and exposure values, typed settings with defaults (13). A Python RPC client, a typed TypeScript client and about 75 example extensions, with command errors and parse errors shown as records (13). A dated changelog in the repository and at pi.dev/changelog with an RSS feed (15).",
            "security": "Harness reading of the framework checklist, used for the harnesses in this category. 30 for what leaves the machine by default, 20 for approvals and sandboxing, 15 for prompt-injection posture, 15 for audit and 20 for the security programme. An anonymous install and update ping to pi.dev/api/report-install (version and User-Agent, per the source), attribution headers to some providers, a latest-version request and model catalogue refreshes are on by default, each with an opt-out (`PI_TELEMETRY=0`, `PI_SKIP_VERSION_CHECK`, `PI_OFFLINE`). Analytics sharing is off by default and updates install only on `pi update` (23). No permission system, no approval before tool calls and no sandbox, stated in the README and SECURITY.md. Project trust gates a repository's `.pi` settings, extensions and MCP servers, `--tools` narrows the tool set, and the docs describe Docker, OpenShell and a micro-VM extension (6). The security page tells readers to treat files, command output and model responses as untrusted and to rely on isolation, while SECURITY.md puts prompt injection out of scope and context files such as AGENTS.md load whatever the trust decision (7). Sessions are JSONL files on disk with HTML export, MCP server logs go to `~/.pi/agent/mcp.log`, and the JSON stream records each tool call (11). SECURITY.md gives security@earendil.com and GitHub private reporting, four advisories with CVEs were published with fixes, npm releases carry provenance from trusted publishing, and a scheduled workflow runs `npm audit`. No security.txt and no bounty found (14).",
            "transparency": "MIT (30). No privacy policy for pi.dev or the CLI was found (pi.dev/privacy and earendil.com/privacy return 404). The docs say where sessions and credentials are stored and what `/share` and `/bug` upload. The Radius alpha terms of 1 September 2026 name Earendil Works Co. and refer to a Privacy Notice we couldn't locate (10). Breaking changes are listed per release with migration steps, with no deprecation policy or notice period found (8). Install telemetry and the version check are documented in the settings and environment-variable pages with opt-outs, though the docs don't list the fields sent (16)."
          },
          "sources": [
            {
              "what": "repository README",
              "url": "https://github.com/earendil-works/pi",
              "seen": "2026-10-08"
            },
            {
              "what": "security policy",
              "url": "https://github.com/earendil-works/pi/blob/main/SECURITY.md",
              "seen": "2026-10-08"
            },
            {
              "what": "contribution rules and issue gate",
              "url": "https://github.com/earendil-works/pi/blob/main/CONTRIBUTING.md",
              "seen": "2026-10-08"
            },
            {
              "what": "changelog",
              "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/CHANGELOG.md",
              "seen": "2026-10-08"
            },
            {
              "what": "security and project trust (docs)",
              "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/security.md",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP servers (docs)",
              "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/mcp.md",
              "seen": "2026-10-08"
            },
            {
              "what": "command line (docs)",
              "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/cli.md",
              "seen": "2026-10-08"
            },
            {
              "what": "CLI integration, JSON and RPC modes (docs)",
              "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/cli-integration.md",
              "seen": "2026-10-08"
            },
            {
              "what": "RPC protocol (docs)",
              "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/rpc.md",
              "seen": "2026-10-08"
            },
            {
              "what": "settings, telemetry and retry (docs)",
              "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/settings.md",
              "seen": "2026-10-08"
            },
            {
              "what": "environment variables (docs)",
              "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/environment-variables.md",
              "seen": "2026-10-08"
            },
            {
              "what": "sessions, share and bug report (docs)",
              "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/sessions.md",
              "seen": "2026-10-08"
            },
            {
              "what": "isolation methods (docs)",
              "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/containerization.md",
              "seen": "2026-10-08"
            },
            {
              "what": "install ping in the source",
              "url": "https://github.com/earendil-works/pi/blob/main/packages/coding-agent/src/modes/interactive/interactive-mode.ts",
              "seen": "2026-10-08"
            },
            {
              "what": "CI workflow",
              "url": "https://github.com/earendil-works/pi/blob/main/.github/workflows/ci.yml",
              "seen": "2026-10-08"
            },
            {
              "what": "CI runs on main",
              "url": "https://api.github.com/repos/earendil-works/pi/actions/workflows/ci.yml/runs?branch=main",
              "seen": "2026-10-08"
            },
            {
              "what": "repository statistics",
              "url": "https://api.github.com/repos/earendil-works/pi",
              "seen": "2026-10-08"
            },
            {
              "what": "security advisories",
              "url": "https://github.com/earendil-works/pi/security/advisories",
              "seen": "2026-10-08"
            },
            {
              "what": "npm latest, engines and provenance",
              "url": "https://registry.npmjs.org/@earendil-works/pi-coding-agent/latest",
              "seen": "2026-10-08"
            },
            {
              "what": "npm weekly downloads",
              "url": "https://api.npmjs.org/downloads/point/last-week/@earendil-works/pi-coding-agent",
              "seen": "2026-10-08"
            },
            {
              "what": "product site",
              "url": "https://pi.dev/",
              "seen": "2026-10-08"
            },
            {
              "what": "changelog page",
              "url": "https://pi.dev/changelog",
              "seen": "2026-10-08"
            },
            {
              "what": "docs page served as Markdown",
              "url": "https://pi.dev/docs/latest/mcp",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt (404)",
              "url": "https://pi.dev/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "llms.txt (404)",
              "url": "https://pi.dev/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "Radius overview",
              "url": "https://radius.earendil.com/",
              "seen": "2026-10-08"
            },
            {
              "what": "Radius alpha terms",
              "url": "https://radius.earendil.com/terms",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP for pi.dev",
              "url": "https://rdap.org/domain/pi.dev",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: issue and pull request reply times, and separate open issue and pull request counts. The GitHub API rate limit was reached, so only the combined count of 308 was read",
            "unchecked: why eight of the last 15 CI runs on main failed. The run logs weren't read",
            "The Privacy Notice the Radius alpha terms refer to wasn't found, and no privacy policy for pi.dev or the CLI was found",
            "The legal entity is unclear. The pi.dev footer reads Earendil Inc. and the Radius terms name Earendil Works Co.",
            "No public price list for Radius credits was found. Radius is optional and wasn't graded",
            "The date of Pi's first release wasn't established. The changelog starts at 0.10.0 on 25 November 2025 and the repository was created on 9 August 2025",
            "The scout said MCP wasn't mentioned in the README. Pi has had a built-in MCP client since 0.99.0 on 29 September 2026, documented in docs/mcp.md"
          ]
        },
        "negative": -4,
        "negativeNotes": [
          "2026-06-08. GHSA-jfgx-wxx8-mp94 (CVE-2026-54328, high). Temporary extension installs used predictable paths under the system temp directory, so another local user on a shared Linux host could plant extension code that Pi then loaded. Fixed in 0.78.1. Fixed, published and four months old, -2. https://github.com/earendil-works/pi/security/advisories/GHSA-jfgx-wxx8-mp94",
          "2026-06-08. GHSA-mqxh-6gq7-558m (CVE-2026-54325, medium). Before 0.79.0 Pi loaded a repository's `.pi` settings and extensions without asking, so starting it in a cloned repository could run that repository's code. Fixed in 0.79.0 with project trust. Fixed and published, -2. https://github.com/earendil-works/pi/security/advisories/GHSA-mqxh-6gq7-558m",
          "2026-06-08. GHSA-7v5m-pr3q-6453 (CVE-2026-54326, low, XSS in HTML session exports) and GHSA-r95r-rj6r-c39x (CVE-2026-54327, low, a race in `auth.json` permissions). Both fixed in 0.78.1. Recorded without a deduction. https://github.com/earendil-works/pi/security/advisories"
        ],
        "verdict": "Four default tools, a JSONL event stream, an RPC mode and MCP tools kept out of the model's declarations by default keep context small and scripting simple. Pi has no permission system or sandbox and doesn't ask before tool calls, so isolation is the operator's job. Version 1.0.0 is dated 1 October 2026.",
        "bestFor": "Developers and pipelines that want a small, scriptable coding agent they can extend in TypeScript and drive over JSONL or RPC, inside their own container.",
        "strengths": [
          "Four default tools (read, bash, edit, write), with MCP tools reachable through codemode scripts and not declared to the model by default",
          "`--mode json` streams JSONL events and `--mode rpc` takes JSONL commands, both documented record by record, with a Python client example",
          "Built-in MCP client for stdio and streamable HTTP servers with OAuth, per-tool exposure settings and a conformance job in CI",
          "Project trust stops a repository's `.pi` settings, extensions and MCP servers loading until approved, and non-interactive modes skip them by default",
          "npm releases carry SLSA provenance from GitHub Actions trusted publishing, and the installer pins transitive dependencies"
        ],
        "weaknesses": [
          "No permission system or sandbox. Tool calls run with the user's rights and without an approval prompt",
          "An anonymous install and update ping to pi.dev and a latest-version request are on by default",
          "Four advisories published on 8 June 2026, one rated high and one medium, all fixed by 0.79.0",
          "No privacy policy for pi.dev or the CLI found, and pi.dev has no security.txt",
          "Eight of the last 15 CI runs on main failed on 7 and 8 October 2026, and a breaking provider rename shipped in patch release 1.0.3"
        ],
        "agentNotes": [
          "Run Pi inside a container or VM for unattended work. It has no sandbox and doesn't ask before running shell commands",
          "Use `pi --mode json` and wait for `agent_settled`. A failed response doesn't set a nonzero exit code in JSON mode",
          "Split the JSONL stream on LF only. Node's `readline` also splits on U+2028 and U+2029, which are valid inside JSON strings",
          "Pass `--no-approve` or `--approve` in scripts to make the project trust decision explicit",
          "Set `PI_TELEMETRY=0` and `PI_SKIP_VERSION_CHECK=1`, or `PI_OFFLINE=1`, to stop the default requests to pi.dev"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 68.4
          }
        ],
        "editorialScores": {
          "ergonomics": 76,
          "maintenance": 87,
          "payments": 60,
          "reliability": 75,
          "schema": 84,
          "security": 61,
          "transparency": 64
        },
        "provenanceScore": 63
      },
      "connect": {
        "install": "curl -fsSL https://pi.dev/install.sh | sh   # or: npm install -g --ignore-scripts @earendil-works/pi-coding-agent",
        "headless": {
          "command": "pi --mode json --no-session --no-approve \"$TASK\"",
          "env": {
            "PI_SKIP_VERSION_CHECK": "1",
            "PI_TELEMETRY": "0"
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/earendil-pi"
      },
      "notable": [
        "The README says Pi has no built-in permission system for filesystem, process, network or credential access and runs with the rights of the user who launched it (https://github.com/earendil-works/pi)",
        "1.0.0 is dated 1 October 2026 and 1.1.0 followed on 7 October 2026, after 0.x releases going back to at least November 2025 (https://github.com/earendil-works/pi/blob/main/packages/coding-agent/CHANGELOG.md)",
        "A built-in MCP client for stdio and streamable HTTP servers arrived in 0.99.0 on 29 September 2026. MCP tools default to `codemode` exposure and aren't declared to the model (https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/mcp.md)",
        "Project trust gates a repository's `.pi` settings, extensions and MCP servers. Print, JSON and RPC modes skip them unless `--approve` is passed or the default is changed (https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/security.md)",
        "Four advisories with CVEs were published on 8 June 2026, one high and one medium, all fixed by 0.79.0 (https://github.com/earendil-works/pi/security/advisories)",
        "An anonymous install and update ping to pi.dev is on by default and is turned off with `PI_TELEMETRY=0` or `enableInstallTelemetry` (https://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/settings.md)",
        "Issues and pull requests from new contributors are closed automatically and reviewed daily by maintainers (https://github.com/earendil-works/pi/blob/main/CONTRIBUTING.md)",
        "The repository was badlogic/pi-mono, and the old path redirects to earendil-works/pi (https://github.com/earendil-works/pi)"
      ],
      "area": "frameworks",
      "details": [
        {
          "label": "Interfaces",
          "value": "Terminal UI, print mode (`--print`), JSON mode (`--mode json`, JSONL events), RPC mode (`--mode rpc`, JSONL commands on stdin), TypeScript SDK, extensions, skills, prompt templates and Pi packages"
        },
        {
          "label": "Built-in tools",
          "value": "read, bash, edit and write by default. powershell on Windows, grep, find and ls available. codemode (JavaScript in a QuickJS sandbox that calls the other tools) and tool_search are off until enabled or an MCP server needs them"
        },
        {
          "label": "Approvals",
          "value": "None for tool calls. Project trust asks before loading a repository's `.pi` settings, extensions, skills and MCP servers, and `--tools`, `--exclude-tools` and `--no-tools` narrow the tool set"
        },
        {
          "label": "Sandbox",
          "value": "None. The docs describe plain Docker, Docker Sandboxes, OpenShell and a Gondolin micro-VM extension"
        },
        {
          "label": "MCP client",
          "value": "stdio and streamable HTTP, no SSE. OAuth with dynamic registration, a registered client or a Client ID Metadata Document. Exposure per server or tool is codemode (default), deferred, direct or hidden"
        },
        {
          "label": "Models",
          "value": "15 or more providers per pi.dev, among them Anthropic, OpenAI, Google, Azure, Bedrock, Mistral, Groq, xAI, OpenRouter, Ollama and llama.cpp, by API key or subscription login, plus custom providers in `models.json`"
        },
        {
          "label": "Sessions",
          "value": "JSONL trees under `~/.pi/agent/sessions/`, with `--continue`, `--fork`, `--session-id` and `--no-session`, automatic compaction, HTML export, and `/share` to a private GitHub gist or a Radius artifact"
        },
        {
          "label": "Telemetry",
          "value": "Anonymous install and update ping to pi.dev, provider attribution headers and a latest-version request on by default, with `PI_TELEMETRY=0`, `PI_SKIP_VERSION_CHECK` and `PI_OFFLINE` as opt-outs. Analytics sharing is off by default"
        },
        {
          "label": "Runtime",
          "value": "Node.js 22.19 or newer. Installers for macOS, Linux and Windows, npm, Nix and standalone binaries"
        },
        {
          "label": "Releases in 90 days",
          "value": "33 tags since 10 July 2026, with 1.0.0 on 1 October and 1.1.0 on 7 October 2026"
        },
        {
          "label": "Advisories",
          "value": "Four published on 8 June 2026 (CVE-2026-54325 to CVE-2026-54328), fixed in 0.78.1 and 0.79.0"
        }
      ],
      "provenance": {
        "legalEntity": "Earendil Inc.",
        "domain": "pi.dev",
        "domainRegistered": "2024-01-30",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "",
        "statusPage": "",
        "changelog": "https://pi.dev/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The pi.dev and earendil.com footers read Earendil Inc. The Radius alpha terms of 1 September 2026 name Earendil Works Co., and the README calls the company Earendil Works.",
          "We found no terms or privacy page for pi.dev or the CLI. pi.dev/terms, pi.dev/privacy and earendil.com/privacy return 404. Terms exist only for Radius, at radius.earendil.com/terms.",
          "pi.dev/.well-known/security.txt and earendil.com/.well-known/security.txt return 404. SECURITY.md gives security@earendil.com and GitHub private reporting.",
          "RDAP for pi.dev gives a registration date of 2024-01-30 with Cloudflare as registrar. The README says the domain was donated by exe.dev.",
          "The repository moved from badlogic/pi-mono to earendil-works/pi, and the npm package from @mariozechner/pi-coding-agent to @earendil-works/pi-coding-agent at 0.74.0, per the advisories."
        ],
        "score": 63,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Earendil Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "pi.dev, registered 2024-01-30 (2 years)",
            "points": 7,
            "max": 15,
            "state": "part"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "no hosted endpoint",
            "points": 0,
            "max": 0,
            "state": "na"
          },
          {
            "check": "Terms of service",
            "value": "nothing hosted, so the MIT licence stands in",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Privacy policy",
            "value": "nothing hosted, not scored",
            "points": 0,
            "max": 0,
            "state": "na"
          },
          {
            "check": "Status page",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/earendil-pi.json",
      "live": {
        "slug": "earendil-pi",
        "versions": [
          {
            "registry": "github",
            "name": "earendil-works/pi",
            "version": "v1.1.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:09:44.573412777Z"
          },
          {
            "registry": "npm",
            "name": "@earendil-works/pi-coding-agent",
            "version": "1.1.0",
            "seenAt": "2026-10-08T16:09:41.369786574Z"
          }
        ],
        "githubStars": 113482,
        "npmWeekly": 5201697,
        "securityTxt": {
          "url": "https://pi.dev/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:42.51766104Z"
        },
        "pages": [
          {
            "url": "https://pi.dev/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:53.741589246Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "82f9cb8bddf7"
          }
        ],
        "updatedAt": "2026-10-08T18:22:53.741589246Z"
      }
    },
    "verify": {
      "accepts": "a page on pi.dev or one of its subdomains, or the README of github.com/earendil-works/pi",
      "badgeUrl": "https://www.anchorterminal.com/badges/earendil-pi.svg",
      "body": {
        "slug": "earendil-pi",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/earendil-pi",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/earendil-pi\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/earendil-pi.svg\" alt=\"Pi on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Pi on Anchor Terminal](https://www.anchorterminal.com/badges/earendil-pi.svg)](https://www.anchorterminal.com/tools/earendil-pi)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/earendil-pi\"\u003ePi on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/earendil-pi",
    "json": "https://www.anchorterminal.com/tools/earendil-pi.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/earendil-pi.md",
    "slim": "https://www.anchorterminal.com/tools/earendil-pi.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 68.4/100 · rank #180 of 722 · #6 in Agent harnesses · not agent-ready · confidence medium**\n\n\n## Assessment\n\nFour default tools, a JSONL event stream, an RPC mode and MCP tools kept out of the model's declarations by default keep context small and scripting simple. Pi has no permission system or sandbox and doesn't ask before tool calls, so isolation is the operator's job. Version 1.0.0 is dated 1 October 2026.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Earendil (https://pi.dev) |\n| Kind | Agent harness |\n| Category | Agent harnesses (https://www.anchorterminal.com/categories/agent-harnesses) |\n| Auth | None · No Pi account needed. Model providers are connected with `/login` (a subscription or an API key, stored in `~/.pi/agent/auth.json`) or with environment variables such as `ANTHROPIC_API_KEY`. MCP servers take headers, bearer tokens from the environment or OAuth, with tokens kept in `~/.pi/agent/mcp-auth.json`. Radius, the optional hosted gateway, needs its own sign-in or `RADIUS_API_KEY`. |\n| Pricing | Free (Free · OSS) · Free and MIT, with no paid edition of the harness. The owner pays the model provider. Radius, Earendil's optional hosted gateway, is an early alpha sold by prepaid credits, and no public price list was found (checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the repository or the docs (checked 2026-10-08). |\n| Licence | MIT |\n| Packages | npm: `@earendil-works/pi-coding-agent` |\n| Source | https://github.com/earendil-works/pi |\n| Docs | https://pi.dev/docs/latest |\n| llms.txt | not found |\n| Last release | 2026-10-07 |\n| GitHub stars | 113,417 (as of 2026-10-08) |\n| npm downloads / week | 5,201,697 |\n| Interfaces | Terminal UI, print mode (`--print`), JSON mode (`--mode json`, JSONL events), RPC mode (`--mode rpc`, JSONL commands on stdin), TypeScript SDK, extensions, skills, prompt templates and Pi packages |\n| Built-in tools | read, bash, edit and write by default. powershell on Windows, grep, find and ls available. codemode (JavaScript in a QuickJS sandbox that calls the other tools) and tool_search are off until enabled or an MCP server needs them |\n| Approvals | None for tool calls. Project trust asks before loading a repository's `.pi` settings, extensions, skills and MCP servers, and `--tools`, `--exclude-tools` and `--no-tools` narrow the tool set |\n| Sandbox | None. The docs describe plain Docker, Docker Sandboxes, OpenShell and a Gondolin micro-VM extension |\n| MCP client | stdio and streamable HTTP, no SSE. OAuth with dynamic registration, a registered client or a Client ID Metadata Document. Exposure per server or tool is codemode (default), deferred, direct or hidden |\n| Models | 15 or more providers per pi.dev, among them Anthropic, OpenAI, Google, Azure, Bedrock, Mistral, Groq, xAI, OpenRouter, Ollama and llama.cpp, by API key or subscription login, plus custom providers in `models.json` |\n| Sessions | JSONL trees under `~/.pi/agent/sessions/`, with `--continue`, `--fork`, `--session-id` and `--no-session`, automatic compaction, HTML export, and `/share` to a private GitHub gist or a Radius artifact |\n| Telemetry | Anonymous install and update ping to pi.dev, provider attribution headers and a latest-version request on by default, with `PI_TELEMETRY=0`, `PI_SKIP_VERSION_CHECK` and `PI_OFFLINE` as opt-outs. Analytics sharing is off by default |\n| Runtime | Node.js 22.19 or newer. Installers for macOS, Linux and Windows, npm, Nix and standalone binaries |\n| Releases in 90 days | 33 tags since 10 July 2026, with 1.0.0 on 1 October and 1.1.0 on 7 October 2026 |\n| Advisories | Four published on 8 June 2026 (CVE-2026-54325 to CVE-2026-54328), fixed in 0.78.1 and 0.79.0 |\n| Capabilities | agent.harness, agent.mcp-client |\n| Tags | open-source, local, free, no-card, typescript, mcp, json-output, rpc, no-sandbox |\n| JSON | https://www.anchorterminal.com/api/v1/tools/earendil-pi.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 75 | 15.0 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 84 | 13.7 |\n| Agent ergonomics | 13% | 16.2 | 76 | 12.3 |\n| Security \u0026 auth | 14% | 17.5 | 61 | 10.7 |\n| Payments \u0026 pricing | 10% | 12.5 | 60 | 7.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 87 | 7.6 |\n| Transparency \u0026 trust (editorial 64, provenance 63) | 7% | 8.8 | 64 | 5.6 |\n| Negative events | up to −15 | up to −15 | 2026-06-08. GHSA-jfgx-wxx8-mp94 (CVE-2026-54328, high). Temporary extension installs used predictable paths under the system temp directory, so another local user on a shared Linux host could plant extension code that Pi then loaded. Fixed in 0.78.1. Fixed, published and four months old, -2. https://github.com/earendil-works/pi/security/advisories/GHSA-jfgx-wxx8-mp94 2026-06-08. GHSA-mqxh-6gq7-558m (CVE-2026-54325, medium). Before 0.79.0 Pi loaded a repository's `.pi` settings and extensions without asking, so starting it in a cloned repository could run that repository's code. Fixed in 0.79.0 with project trust. Fixed and published, -2. https://github.com/earendil-works/pi/security/advisories/GHSA-mqxh-6gq7-558m 2026-06-08. GHSA-7v5m-pr3q-6453 (CVE-2026-54326, low, XSS in HTML session exports) and GHSA-r95r-rj6r-c39x (CVE-2026-54327, low, a race in `auth.json` permissions). Both fixed in 0.78.1. Recorded without a deduction. https://github.com/earendil-works/pi/security/advisories  | -4 |\n| **Total** | | | | **68.4 → B** |\n\n### Why each score\n\n- Reliability 75: Read as a local package. `@earendil-works/pi-coding-agent` 1.1.0 on npm with Node.js 22.19 or newer stated, install scripts for macOS, Linux and Windows, Nix and standalone binaries (20). A public CI workflow builds, checks and tests on every push to main and runs an MCP client conformance job. The run on the commit we cloned (ce950d7, 8 October 2026) passed, but eight of the last 15 runs on main, all on 7 and 8 October, failed (15). The repository API reports 308 open issues and pull requests against 113,417 stars. Issues from new contributors are closed automatically and reviewed daily by maintainers, per CONTRIBUTING.md, so the open count understates what is reported, and we couldn't sample reply times (16). A dated changelog with Breaking Changes sections and migration steps, but the Azure provider rename shipped as a breaking change in patch release 1.0.3 on 5 October 2026, four days after 1.0.0 (9). 1.1.0, with 1.0.0 dated 1 October 2026 (15).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 84: Harness reading, as for the other harnesses. JSON Schemas for settings, models, keybindings and themes ship in the package, and the JSON event stream and every RPC command are documented record by record, but as Markdown and TypeScript types with no machine-readable spec for the RPC protocol (18). pi.dev/llms.txt returns 404. Each docs page answers `Accept: text/markdown` with Markdown, and the docs ship inside the npm package (8). The integration page has a table saying when to use interactive, print, JSON, RPC or the SDK, and the MCP page gives a typical use for each exposure setting (17). Enumerated modes, thinking levels and exposure values, typed settings with defaults (13). A Python RPC client, a typed TypeScript client and about 75 example extensions, with command errors and parse errors shown as records (13). A dated changelog in the repository and at pi.dev/changelog with an RSS feed (15).\n- Agent ergonomics 76: Harness reading of the framework line, scored on what an agent or pipeline driving it has to supply. Four default tools (read, bash, edit, write) and a short system prompt. MCP tools default to `codemode` exposure, which keeps them out of the model's tool declarations, and `tool_search` loads deferred ones on demand (23). Automatic compaction, agent-level retry with three attempts and exponential backoff, and truncated tool output saved to a file. We found no turn or step limit in the CLI or settings reference (13). `--mode json` streams JSONL events ending in `agent_settled` and `--mode rpc` returns `success: false` with an error string. Print mode exits nonzero on a failed response, JSON mode doesn't (16). Sessions are stored as trees and continue, fork or take a fixed ID with `--continue`, `--fork` and `--session-id`. File changes have no built-in undo, and a git checkpoint is an example extension (14). It needs a provider key or subscription login before the first run, and the SDK is TypeScript only, with RPC for other languages (10).\n- Security \u0026 auth 61: Harness reading of the framework checklist, used for the harnesses in this category. 30 for what leaves the machine by default, 20 for approvals and sandboxing, 15 for prompt-injection posture, 15 for audit and 20 for the security programme. An anonymous install and update ping to pi.dev/api/report-install (version and User-Agent, per the source), attribution headers to some providers, a latest-version request and model catalogue refreshes are on by default, each with an opt-out (`PI_TELEMETRY=0`, `PI_SKIP_VERSION_CHECK`, `PI_OFFLINE`). Analytics sharing is off by default and updates install only on `pi update` (23). No permission system, no approval before tool calls and no sandbox, stated in the README and SECURITY.md. Project trust gates a repository's `.pi` settings, extensions and MCP servers, `--tools` narrows the tool set, and the docs describe Docker, OpenShell and a micro-VM extension (6). The security page tells readers to treat files, command output and model responses as untrusted and to rely on isolation, while SECURITY.md puts prompt injection out of scope and context files such as AGENTS.md load whatever the trust decision (7). Sessions are JSONL files on disk with HTML export, MCP server logs go to `~/.pi/agent/mcp.log`, and the JSON stream records each tool call (11). SECURITY.md gives security@earendil.com and GitHub private reporting, four advisories with CVEs were published with fixes, npm releases carry provenance from trusted publishing, and a scheduled workflow runs `npm audit`. No security.txt and no bounty found (14).\n- Payments \u0026 pricing 60: No payment protocol in the repository or docs (0). Read with the self-hosted rule. Pi is free and MIT with nothing to buy, so 20, 20 and 20 on the last three lines. Model costs go to whichever provider the owner configures. Radius, Earendil's optional hosted gateway, is an early alpha sold by prepaid credits, and we found no public price list for it.\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 87: v1.1.0 on 7 October 2026, one day before this check (30). 33 tagged releases since 10 July 2026 (20). Commits land daily and the changelog credits issues and outside pull requests in most releases. New contributors' issues are closed automatically, reviewed daily, and get no reply if they miss the quality bar, per CONTRIBUTING.md. Reply times weren't sampled because the GitHub API rate limit was reached (16). npm, the pi.dev installer, Nix and standalone binaries track each release, and npm publishes through GitHub Actions trusted publishing (14). Direct dependencies are pinned, a scheduled workflow runs `npm audit`, and CI passed on the commit we cloned after eight failures in the previous 14 runs (7).\n- Transparency \u0026 trust 64: MIT (30). No privacy policy for pi.dev or the CLI was found (pi.dev/privacy and earendil.com/privacy return 404). The docs say where sessions and credentials are stored and what `/share` and `/bug` upload. The Radius alpha terms of 1 September 2026 name Earendil Works Co. and refer to a Privacy Notice we couldn't locate (10). Breaking changes are listed per release with migration steps, with no deprecation policy or notice period found (8). Install telemetry and the version check are documented in the settings and environment-variable pages with opt-outs, though the docs don't list the fields sent (16).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (20 items): https://www.anchorterminal.com/fixes/earendil-pi.md (JSON https://www.anchorterminal.com/fixes/earendil-pi.json)\n\n### What we couldn't check\n\n- unchecked: issue and pull request reply times, and separate open issue and pull request counts. The GitHub API rate limit was reached, so only the combined count of 308 was read\n- unchecked: why eight of the last 15 CI runs on main failed. The run logs weren't read\n- The Privacy Notice the Radius alpha terms refer to wasn't found, and no privacy policy for pi.dev or the CLI was found\n- The legal entity is unclear. The pi.dev footer reads Earendil Inc. and the Radius terms name Earendil Works Co.\n- No public price list for Radius credits was found. Radius is optional and wasn't graded\n- The date of Pi's first release wasn't established. The changelog starts at 0.10.0 on 25 November 2025 and the repository was created on 9 August 2025\n- The scout said MCP wasn't mentioned in the README. Pi has had a built-in MCP client since 0.99.0 on 29 September 2026, documented in docs/mcp.md\n\n### Sources\n\n- repository README: \u003chttps://github.com/earendil-works/pi\u003e (seen 2026-10-08)\n- security policy: \u003chttps://github.com/earendil-works/pi/blob/main/SECURITY.md\u003e (seen 2026-10-08)\n- contribution rules and issue gate: \u003chttps://github.com/earendil-works/pi/blob/main/CONTRIBUTING.md\u003e (seen 2026-10-08)\n- changelog: \u003chttps://github.com/earendil-works/pi/blob/main/packages/coding-agent/CHANGELOG.md\u003e (seen 2026-10-08)\n- security and project trust (docs): \u003chttps://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/security.md\u003e (seen 2026-10-08)\n- MCP servers (docs): \u003chttps://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/mcp.md\u003e (seen 2026-10-08)\n- command line (docs): \u003chttps://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/cli.md\u003e (seen 2026-10-08)\n- CLI integration, JSON and RPC modes (docs): \u003chttps://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/cli-integration.md\u003e (seen 2026-10-08)\n- RPC protocol (docs): \u003chttps://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/rpc.md\u003e (seen 2026-10-08)\n- settings, telemetry and retry (docs): \u003chttps://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/settings.md\u003e (seen 2026-10-08)\n- environment variables (docs): \u003chttps://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/environment-variables.md\u003e (seen 2026-10-08)\n- sessions, share and bug report (docs): \u003chttps://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/sessions.md\u003e (seen 2026-10-08)\n- isolation methods (docs): \u003chttps://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/containerization.md\u003e (seen 2026-10-08)\n- install ping in the source: \u003chttps://github.com/earendil-works/pi/blob/main/packages/coding-agent/src/modes/interactive/interactive-mode.ts\u003e (seen 2026-10-08)\n- CI workflow: \u003chttps://github.com/earendil-works/pi/blob/main/.github/workflows/ci.yml\u003e (seen 2026-10-08)\n- CI runs on main: \u003chttps://api.github.com/repos/earendil-works/pi/actions/workflows/ci.yml/runs?branch=main\u003e (seen 2026-10-08)\n- repository statistics: \u003chttps://api.github.com/repos/earendil-works/pi\u003e (seen 2026-10-08)\n- security advisories: \u003chttps://github.com/earendil-works/pi/security/advisories\u003e (seen 2026-10-08)\n- npm latest, engines and provenance: \u003chttps://registry.npmjs.org/@earendil-works/pi-coding-agent/latest\u003e (seen 2026-10-08)\n- npm weekly downloads: \u003chttps://api.npmjs.org/downloads/point/last-week/@earendil-works/pi-coding-agent\u003e (seen 2026-10-08)\n- product site: \u003chttps://pi.dev/\u003e (seen 2026-10-08)\n- changelog page: \u003chttps://pi.dev/changelog\u003e (seen 2026-10-08)\n- docs page served as Markdown: \u003chttps://pi.dev/docs/latest/mcp\u003e (seen 2026-10-08)\n- security.txt (404): \u003chttps://pi.dev/.well-known/security.txt\u003e (seen 2026-10-08)\n- llms.txt (404): \u003chttps://pi.dev/llms.txt\u003e (seen 2026-10-08)\n- Radius overview: \u003chttps://radius.earendil.com/\u003e (seen 2026-10-08)\n- Radius alpha terms: \u003chttps://radius.earendil.com/terms\u003e (seen 2026-10-08)\n- RDAP for pi.dev: \u003chttps://rdap.org/domain/pi.dev\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 63/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Earendil Inc. | 20/20 |\n| Domain age | pi.dev, registered 2024-01-30 (2 years) | 7/15 |\n| Endpoint on the vendor's domain | no hosted endpoint | n/a |\n| Terms of service | nothing hosted, so the MIT licence stands in | 10/10 |\n| Privacy policy | nothing hosted, not scored | n/a |\n| Status page | not found | 0/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe pi.dev and earendil.com footers read Earendil Inc. The Radius alpha terms of 1 September 2026 name Earendil Works Co., and the README calls the company Earendil Works.\n\nWe found no terms or privacy page for pi.dev or the CLI. pi.dev/terms, pi.dev/privacy and earendil.com/privacy return 404. Terms exist only for Radius, at radius.earendil.com/terms.\n\npi.dev/.well-known/security.txt and earendil.com/.well-known/security.txt return 404. SECURITY.md gives security@earendil.com and GitHub private reporting.\n\nRDAP for pi.dev gives a registration date of 2024-01-30 with Cloudflare as registrar. The README says the domain was donated by exe.dev.\n\nThe repository moved from badlogic/pi-mono to earendil-works/pi, and the npm package from @mariozechner/pi-coding-agent to @earendil-works/pi-coding-agent at 0.74.0, per the advisories.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service**. Nothing is hosted by the vendor, so there are no terms of service to read. The MIT licence stands in and the check scores in full.\n\n\n**Privacy policy**. Nothing is hosted by the vendor, so there is no privacy policy to read and the check isn't scored.\n\n\n## Live (updated 2026-10-08 18:22 UTC)\n\n- github `earendil-works/pi` v1.1.0, released 2026-10-07\n- npm `@earendil-works/pi-coding-agent` 1.1.0\n- security.txt: none\n- Watching changelog \u003chttps://pi.dev/changelog\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/earendil-pi.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- Four default tools (read, bash, edit, write), with MCP tools reachable through codemode scripts and not declared to the model by default\n- `--mode json` streams JSONL events and `--mode rpc` takes JSONL commands, both documented record by record, with a Python client example\n- Built-in MCP client for stdio and streamable HTTP servers with OAuth, per-tool exposure settings and a conformance job in CI\n- Project trust stops a repository's `.pi` settings, extensions and MCP servers loading until approved, and non-interactive modes skip them by default\n- npm releases carry SLSA provenance from GitHub Actions trusted publishing, and the installer pins transitive dependencies\n\n## Weaknesses\n\n- No permission system or sandbox. Tool calls run with the user's rights and without an approval prompt\n- An anonymous install and update ping to pi.dev and a latest-version request are on by default\n- Four advisories published on 8 June 2026, one rated high and one medium, all fixed by 0.79.0\n- No privacy policy for pi.dev or the CLI found, and pi.dev has no security.txt\n- Eight of the last 15 CI runs on main failed on 7 and 8 October 2026, and a breaking provider rename shipped in patch release 1.0.3\n\n## Before you call it (notes for agents)\n\n1. Run Pi inside a container or VM for unattended work. It has no sandbox and doesn't ask before running shell commands\n2. Use `pi --mode json` and wait for `agent_settled`. A failed response doesn't set a nonzero exit code in JSON mode\n3. Split the JSONL stream on LF only. Node's `readline` also splits on U+2028 and U+2029, which are valid inside JSON strings\n4. Pass `--no-approve` or `--approve` in scripts to make the project trust decision explicit\n5. Set `PI_TELEMETRY=0` and `PI_SKIP_VERSION_CHECK=1`, or `PI_OFFLINE=1`, to stop the default requests to pi.dev\n\n## Connect\n\nInstall:\n\n```bash\ncurl -fsSL https://pi.dev/install.sh | sh   # or: npm install -g --ignore-scripts @earendil-works/pi-coding-agent\n```\n\nHeadless / CI:\n\n```json\n{\n  \"command\": \"pi --mode json --no-session --no-approve \\\"$TASK\\\"\",\n  \"env\": {\n    \"PI_SKIP_VERSION_CHECK\": \"1\",\n    \"PI_TELEMETRY\": \"0\"\n  }\n}\n```\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| goose | BB | 73.9 | 72 | agent.harness, agent.mcp-client | no | https://www.anchorterminal.com/tools/goose.md |\n| OpenAI Codex | BB | 73 | 82 | agent.harness, agent.mcp-client | no | https://www.anchorterminal.com/tools/openai-codex.md |\n| Qwen Code | BB | 72.4 | 93 | agent.harness, agent.mcp-client | no | https://www.anchorterminal.com/tools/qwen-code.md |\n| Gemini CLI | BB | 72 | 99 | agent.harness, agent.mcp-client | no | https://www.anchorterminal.com/tools/gemini-cli.md |\n| OpenHands | BB | 70.8 | 126 | agent.harness, agent.mcp-client | no | https://www.anchorterminal.com/tools/openhands.md |\n| OpenCode | B | 67.7 | 200 | agent.harness, agent.mcp-client | no | https://www.anchorterminal.com/tools/opencode.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The README says Pi has no built-in permission system for filesystem, process, network or credential access and runs with the rights of the user who launched it (source: \u003chttps://github.com/earendil-works/pi\u003e)\n- 1.0.0 is dated 1 October 2026 and 1.1.0 followed on 7 October 2026, after 0.x releases going back to at least November 2025 (source: \u003chttps://github.com/earendil-works/pi/blob/main/packages/coding-agent/CHANGELOG.md\u003e)\n- A built-in MCP client for stdio and streamable HTTP servers arrived in 0.99.0 on 29 September 2026. MCP tools default to `codemode` exposure and aren't declared to the model (source: \u003chttps://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/mcp.md\u003e)\n- Project trust gates a repository's `.pi` settings, extensions and MCP servers. Print, JSON and RPC modes skip them unless `--approve` is passed or the default is changed (source: \u003chttps://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/security.md\u003e)\n- Four advisories with CVEs were published on 8 June 2026, one high and one medium, all fixed by 0.79.0 (source: \u003chttps://github.com/earendil-works/pi/security/advisories\u003e)\n- An anonymous install and update ping to pi.dev is on by default and is turned off with `PI_TELEMETRY=0` or `enableInstallTelemetry` (source: \u003chttps://github.com/earendil-works/pi/blob/main/packages/coding-agent/docs/settings.md\u003e)\n- Issues and pull requests from new contributors are closed automatically and reviewed daily by maintainers (source: \u003chttps://github.com/earendil-works/pi/blob/main/CONTRIBUTING.md\u003e)\n- The repository was badlogic/pi-mono, and the old path redirects to earendil-works/pi (source: \u003chttps://github.com/earendil-works/pi\u003e)\n\n## Compare\n\n- [Aider vs Pi](https://www.anchorterminal.com/compare/aider-vs-earendil-pi.md): D 46.9 vs B 68.4\n- [Amp vs Pi](https://www.anchorterminal.com/compare/amp-vs-earendil-pi.md): C 57.1 vs B 68.4\n- [Claude Code vs Pi](https://www.anchorterminal.com/compare/claude-code-vs-earendil-pi.md): C 61.9 vs B 68.4\n- [Cline vs Pi](https://www.anchorterminal.com/compare/cline-vs-earendil-pi.md): C 60.4 vs B 68.4\n- [Cursor CLI vs Pi](https://www.anchorterminal.com/compare/cursor-cli-vs-earendil-pi.md): F 35.3 vs B 68.4\n- [Devin vs Pi](https://www.anchorterminal.com/compare/devin-vs-earendil-pi.md): C 55.7 vs B 68.4\n- [Pi vs Gemini CLI](https://www.anchorterminal.com/compare/earendil-pi-vs-gemini-cli.md): B 68.4 vs BB 72\n- [Pi vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/earendil-pi-vs-github-copilot-cli.md): B 68.4 vs C 57.6\n- [Pi vs goose](https://www.anchorterminal.com/compare/earendil-pi-vs-goose.md): B 68.4 vs BB 73.9\n- [Pi vs Kiro CLI](https://www.anchorterminal.com/compare/earendil-pi-vs-kiro-cli.md): B 68.4 vs C 59.9\n- [Pi vs OpenAI Codex](https://www.anchorterminal.com/compare/earendil-pi-vs-openai-codex.md): B 68.4 vs BB 73\n- [Pi vs OpenCode](https://www.anchorterminal.com/compare/earendil-pi-vs-opencode.md): B 68.4 vs B 67.7\n- [Pi vs OpenHands](https://www.anchorterminal.com/compare/earendil-pi-vs-openhands.md): B 68.4 vs BB 70.8\n- [Pi vs Prime Agent](https://www.anchorterminal.com/compare/earendil-pi-vs-prime-agent.md): B 68.4 vs C 60.5\n- [Pi vs Qwen Code](https://www.anchorterminal.com/compare/earendil-pi-vs-qwen-code.md): B 68.4 vs BB 72.4\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on pi.dev or one of its subdomains, or the README of github.com/earendil-works/pi. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"earendil-pi\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/earendil-pi\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/earendil-pi.svg\" alt=\"Pi on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Pi on Anchor Terminal](https://www.anchorterminal.com/badges/earendil-pi.svg)](https://www.anchorterminal.com/tools/earendil-pi)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/earendil-pi\"\u003ePi on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Pi is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/earendil-pi-dark.png\n- Light: https://www.anchorterminal.com/assets/share/earendil-pi-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Agent harnesses",
        "url": "https://www.anchorterminal.com/categories/agent-harnesses"
      },
      {
        "name": "Pi",
        "url": ""
      }
    ],
    "description": "Pi is an open-source terminal coding agent from Earendil, run on the owner's machine with any of 15 or more model providers. It has interactive, print, JSON and RPC modes, a TypeScript SDK and a built-in MCP client.",
    "facts": [
      "rank #180 of 722",
      "None auth",
      "0 desk reviews"
    ],
    "h1": "Pi",
    "image": "https://www.anchorterminal.com/assets/og/tools-earendil-pi.png",
    "path": "/tools/earendil-pi",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Pi review for AI agents, grade B (68.4/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/earendil-pi"
  },
  "tokens": {
    "markdown": 7150,
    "slim": 1530
  },
  "version": 1
}
