Skip to content

Security

Use GitHub private vulnerability reporting. Do not publish a suspected vulnerability in an issue.

Provide the affected versions, reproduction steps, expected impact, and a redacted proof of concept. Remove credentials, prompts, session files, logs containing private data, endpoints, and real model selections.

Read the complete security policy before submitting a report.

pi-subagent-models changes child launch request fields. It is not a sandbox or authorization mechanism.

Responsibility Owner
Model override selection pi-subagent-models
Tool permissions and capability limits Pi and pi-subagents
Provider credentials Pi provider configuration
Child process isolation pi-subagents runtime and host environment
Secret handling in prompts and tools User and runtime policy

The package performs no telemetry, analytics, or network requests.