Evidence record / pi-coding-agent

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.

2026-09-21-pi-coding-agent-extensions-gained-authenticated-model-calls-and-full-transcript-control-context-handlers

Extensions gained authenticated model calls and full-transcript control; context handlers lost sight of system messages. What an operator can now do that they could not on 2026-08-20: an extension can call any configured provider with the user’s resolved credentials, and can rewrite the entire request including the system prompt and send it verbatim, and can hide messages from the model while keeping the raw log intact. The scaffolding removed: mutating agent.state.messages as a context hack no longer works. The authority an extension holds grew, in a harness whose security posture is still “extensions are trusted code.”

Channel: tagged-release. Half: capability. Date: 2026-09-19 (v0.86.0), 2026-09-21 (v0.87.0).

Operator consequence: Re-audit third-party extensions for modelRegistry.stream, context_with_system, and appendContextEdit on upgrade to 0.86/0.87; each is a place spend, prompt, or visible history can change without the user seeing it in the transcript. SDK embedders who mutate agent.state.messages must port to SessionManager calls on 0.87.0.

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-pi-coding-agent-extensions-gained-authenticated-model-calls-and-full-transcript-control-context-handlers

Profile citations

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact