pi-xpi
v0.9.4by xaccefy
XPI: offensive security tools for Pi Agent and OMP (fork): casefile ledger with honest-PoC gates, web lookup, exploit technique search, and todo tracking.
What pi-xpi does, in the publisher's words
Security tooling for the Pi agent: casefile tracking, web search, exploit-technique intelligence, code search, and todos.
XPI turns the Pi agent into a security researcher: a case ledger with enforced gates, real exploit-technique grounding, web lookup, fast code search, and a pipeline that keeps findings honest.
- Casefile: hypothesis → investigating → confirmed → reported, with gates at every step
- Machine-owned PoC gates: zero exit is necessary but never proof: direct-response findings require nonce-bound body evidence plus a DNS-pinned, conclusive target_only replay against an operator-approved control; reflection-capable requests can add a harness-generated target-only canary; only the main agent may make the semantic decision and commit phase 2
- Exploit chains: ChainSuggest surfaces combinations the model missed
From the project README, punctuation lightly normalized · Open the README on GitHub
- Skills
- 3
- MCP servers
- 0
- Stars
- 14
- License
- MIT
- Repo created
- 2026-07-05
- Last pushed
- 2026-08-18
- Publisher type
- User
- Version
- 0.9.4
Links
Skills · 3
- casefile
- Use when tracking security investigations, bug bounty findings, CTF leads, audit evidence, exploit chains, dead ends, or reports in the Casefile ledger.
- cyberwf
- Bounded swarm vulnerability discovery pipeline for broad bug-bounty or security-audit sweeps. Use when the user explicitly asks for the full pipeline, enables /xp or /xp swarm, or wants parallel specialist review. Prefer /xp lite or the casefile skill for CTFs, focused one-target work, and single s…
- web-pentest
- Web application penetration testing methodology for Pi agent, reconnaissance, auth handling, per-class attack methodology, detection, confirmation, evasion, and reporting. Use when testing a live web target within a sanctioned engagement. Per-class methodology lives in classes/<slug>.md; read only…
Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
Category
Security & Compliance. Assigned by this directory. Agent Plugins 1.0.0 has no category field, so no manifest declares one.
Keywords
pi-package · pi-extension · xpi · security · bug-bounty · pentest · ctf · exploit · web-search
Related by publisher and keywords
Offensive security case ledger for Pi Agent, evidence tracking with machine-verified PoC gates.
Investigate incidents, review code and execute UAT for release readiness, scan code for vulnerabilities, and run penetration tests with AWS DevOps Agent and AWS Security Agent.
A Model Context Protocol server with Exa for web search, code search, and web crawling. Provides real-time web searches with configurable tool selection, allowing users to enable or disable specific search capabilities.
Set up, run and fix MegaLinter on any repository: 100+ linters for 69+ languages, 23+ formats and 21+ tooling formats, from CI or locally.
Real-time web search, reasoning, and research through Perplexity's API
Stripe agent plugin with skills for Stripe integrations including best practices, API and SDK upgrade guidance, and a remote MCP server configuration.
[](https://agentpluginsdirectory.com/plugins/pi-xpi)✓ Verified . We fetched the manifest from GitHub and checked it against the official Agent Plugins 1.0.0 schema at agent-plugins.org.