Evidence record / pi-coding-agent

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.

Authentication file mode set at creation time

What Changed

Introduced AUTH_FILE_WRITE_OPTIONS constant with mode 0o600 (owner read/write only) applied to all FileAuthStorageBackend writeFileSync() calls. Reduces the security window where auth files could exist with insecure permissions before subsequent chmod operations.

Operator Implication

Hardens credential storage by ensuring authentication files never briefly exist with world-readable permissions. Closes temporal window for permission escalation.

Receipt

Finding metadata

Run: 2026-06-03-weekly-digest-2026-05-28_2026-06-03-frontier-v0

Finding ID: 2026-06-02-pi-coding-agent-auth-file-permissions

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact