Evidence record / pi-coding-agent

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.

2026-09-21-pi-coding-agent-rpc-steer-and-follow-up-no-longer-bypass-extension-input-handlers

RPC steer and follow_up no longer bypass extension input handlers. Pi has no built-in approval layer; operators who filter or rewrite input do it in an extension input handler. Before 0.86.0, anything driving Pi over RPC could inject steering or follow-up messages that never reached that handler.

Channel: tagged-release. Half: defect. Date: 2026-09-08 fixed; 2026-09-19 tagged (v0.86.0).

Operator consequence: If you embed Pi over RPC and rely on an input extension as a gate or a redactor, upgrade to 0.86.0 and assume earlier embedded sessions were ungated on those two commands.

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-pi-coding-agent-rpc-steer-and-follow-up-no-longer-bypass-extension-input-handlers

Profile citations

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact