xaccefy avatar

pi-xpi

v0.9.4

by xaccefy

XPI: offensive security tools for Pi Agent and OMP (fork): casefile ledger with honest-PoC gates, web lookup, exploit technique search, and todo tracking.

What pi-xpi does, in the publisher's words

Security tooling for the Pi agent: casefile tracking, web search, exploit-technique intelligence, code search, and todos.

XPI turns the Pi agent into a security researcher: a case ledger with enforced gates, real exploit-technique grounding, web lookup, fast code search, and a pipeline that keeps findings honest.

  • Casefile: hypothesis → investigating → confirmed → reported, with gates at every step
  • Machine-owned PoC gates: zero exit is necessary but never proof: direct-response findings require nonce-bound body evidence plus a DNS-pinned, conclusive target_only replay against an operator-approved control; reflection-capable requests can add a harness-generated target-only canary; only the main agent may make the semantic decision and commit phase 2
  • Exploit chains: ChainSuggest surfaces combinations the model missed

From the project README, punctuation lightly normalized · Open the README on GitHub

Skills
3
MCP servers
0
Stars
14
License
MIT
Repo created
2026-07-05
Last pushed
2026-08-18
Publisher type
User
Version
0.9.4

Links

Skills · 3

casefile
Use when tracking security investigations, bug bounty findings, CTF leads, audit evidence, exploit chains, dead ends, or reports in the Casefile ledger.
cyberwf
Bounded swarm vulnerability discovery pipeline for broad bug-bounty or security-audit sweeps. Use when the user explicitly asks for the full pipeline, enables /xp or /xp swarm, or wants parallel specialist review. Prefer /xp lite or the casefile skill for CTFs, focused one-target work, and single s…
web-pentest
Web application penetration testing methodology for Pi agent, reconnaissance, auth handling, per-class attack methodology, detection, confirmation, evasion, and reporting. Use when testing a live web target within a sanctioned engagement. Per-class methodology lives in classes/<slug>.md; read only…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.

Category

Security & Compliance. Assigned by this directory. Agent Plugins 1.0.0 has no category field, so no manifest declares one.

Keywords

pi-package · pi-extension · xpi · security · bug-bounty · pentest · ctf · exploit · web-search

Related by publisher and keywords

  • Offensive security case ledger for Pi Agent, evidence tracking with machine-verified PoC gates.

  • Investigate incidents, review code and execute UAT for release readiness, scan code for vulnerabilities, and run penetration tests with AWS DevOps Agent and AWS Security Agent.

  • exaexa-labs

    A Model Context Protocol server with Exa for web search, code search, and web crawling. Provides real-time web searches with configurable tool selection, allowing users to enable or disable specific search capabilities.

  • megalinteroxsecurity

    Set up, run and fix MegaLinter on any repository: 100+ linters for 69+ languages, 23+ formats and 21+ tooling formats, from CI or locally.

  • perplexityperplexityai

    Real-time web search, reasoning, and research through Perplexity's API

  • stripestripe

    Stripe agent plugin with skills for Stripe integrations including best practices, API and SDK upgrade guidance, and a remote MCP server configuration.

Add the verified badge to your README[![Verified by AgentPluginsDirectory.com against Schema 1.0.0](https://agentpluginsdirectory.com/badge.svg)](https://agentpluginsdirectory.com/plugins/pi-xpi)

✓ Verified . We fetched the manifest from GitHub and checked it against the official Agent Plugins 1.0.0 schema at agent-plugins.org.