dot-pi — security grade SAFE, quality 65/100

Security audit verdict: SAFE · quality 65/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by dannote · Agent Tool · ★ 51

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is dot-pi safe to install? View the security audit →

About dot-pi

dot-pi A curated Pi package with extensions, skills, prompt shortcuts, and rules. Install Install Pi first: Then install this package: For the recommended end-user setup, run the bootstrap script. Safer review-first flow: Convenience one-liner: The bootstrap is a POSIX script for macOS, Linux, and WSL. It installs Pi if missing, installs dot-pi with , offers , and explains optional companion packages (, , , and on macOS) before prompting. defaults to yes when Elixir or Mix is detected; other companions default to no. Headless/non-interactive Linux needs Node.js 22.19.0+ and npm available before Pi can install. Check with and ; install Node 22+ with your preferred Node manager or distro setup if needed. Use non-interactive defaults with: Useful bootstrap options: bash sh install.sh --help sh install.sh --local # install dot-pi into the current project sh install.sh --w

agent-skillsast-grepbrowser-automationcoding-agentextensionslsppipi-packageprompt-templatesskills

Quick Facts

Stars51
Forks4
LanguageTypeScript
CategoryAgent Tool
LicenseMIT
Quality Score64.6210678370143/100
Last Updated2026-09-04
Created2026-01-13
Platformsbrowser, node
Est. Tokens~20k

Compatible Skills

These tools work well together with dot-pi for enhanced workflows:

  • pi-fabric — semantic(0.47)+complementary+rare_topics+same_lang+similar_pop+shared_platform (71%)
  • my-pi — semantic(0.46)+complementary+rare_topics+same_lang+similar_pop+shared_platform (71%)
  • pi-cursor-sdk — semantic(0.39)+complementary+rare_topics+same_lang+similar_pop+shared_platform (68%)

dot-pi alternative? Top 6 similar tools

Looking for a dot-pi alternative? If you're comparing dot-pi with other agent tool tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • my-pi by spences10 · ⭐ 129

    Composable Pi coding agent with MCP, LSP, agent chains, prompt presets, and local eval telemetry

  • pi-agent-browser-native by fitchmultz · ⭐ 225

    pi extension that exposes agent-browser as a native tool for browser automation

  • bmad-module-skill-forge by armelhbobdad · ⭐ 91

    A standalone BMAD module that transforms code repositories, documentation websites, and developer discourse in

  • pi-tool-display by MasuRii · ⭐ 250

    Compact tool call rendering, diff visualization, and output truncation extension for Pi coding agent. Hides, c

  • pi-rtk-optimizer by MasuRii · ⭐ 228

    Pi extension that optimizes RTK command rewriting and tool output compaction for the coding agent.

  • kasetto by pivoshenko · ⭐ 202

    📼 Declarative AI agent environment manager, written in Rust

More Agent Tool Tools

Explore other popular agent tool tools:

View all Agent Tool tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is dot-pi?

dot-pi is Curated Pi package with extensions, skills, prompt shortcuts, and rules. It is categorized as a Agent Tool with 51 GitHub stars.

What programming language is dot-pi written in?

dot-pi is primarily written in TypeScript. It covers topics such as agent-skills, ast-grep, browser-automation.

How do I install or use dot-pi?

You can find installation instructions and usage details in the dot-pi GitHub repository at github.com/dannote/dot-pi. The project has 51 stars and 4 forks, indicating an active community.

What license does dot-pi use?

dot-pi is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to dot-pi?

The top alternatives to dot-pi on Agent Skills Hub include my-pi, pi-agent-browser-native, bmad-module-skill-forge. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Agent Tool tools