No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by tianrendong · Agent Tool · ★ 52
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is pi-chrome safe to install? View the security audit →
pi-chrome Let Pi use your existing signed-in Chrome profile after explicit authorization. MIT · 0 runtime deps · loopback-only bridge () · inspect before loading. Verify connectivity in one command: . is backed by a small MIT-licensed Chrome extension that runs inside the Chrome profile you already use — including every site you're already signed into. Agents can inspect or control Chrome only after you run in the current Pi session. 60-second install instruction To install pi-chrome, run the following command: Then in Pi, run the next command, which will: Reveal the bundled browser-extension folder in Finder, and copy the folder path to your clipboard. Pop open the chrome://extensions webpage in Chrome. In the Chrome Extensions page it opened, YOU WILL NEED TO: Turn on developer mode (top right). Click the load unpacked button (top left). Use Cmd + Shift + G
| Stars | 52 |
| Forks | 22 |
| Language | JavaScript |
| Category | Agent Tool |
| License | MIT |
| Quality Score | 64.5075395191432/100 |
| Last Updated | 2026-09-29 |
| Created | 2026-05-13 |
| Platforms | browser, node |
| Est. Tokens | ~16k |
Explore other popular agent tool tools:
pi-chrome is Pi coding agent extension that gives Pi tools to use Chrome with user's existing profile. It is categorized as a Agent Tool with 52 GitHub stars.
pi-chrome is primarily written in JavaScript.
You can find installation instructions and usage details in the pi-chrome GitHub repository at github.com/tianrendong/pi-chrome. The project has 52 stars and 22 forks, indicating an active community.
pi-chrome is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: