Evidence record / pi-coding-agent
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.
2026-09-21-pi-coding-agent-rpc-steer-and-follow-up-no-longer-bypass-extension-input-handlers
RPC steer and follow_up no longer bypass extension input handlers. Pi has no built-in approval layer; operators who filter or rewrite input do it in an extension input handler. Before 0.86.0, anything driving Pi over RPC could inject steering or follow-up messages that never reached that handler.
Channel: tagged-release. Half: defect. Date: 2026-09-08 fixed; 2026-09-19 tagged (v0.86.0).
Operator consequence: If you embed Pi over RPC and rely on an input extension as a gate or a redactor, upgrade to 0.86.0 and assume earlier embedded sessions were ungated on those two commands.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-pi-coding-agent-rpc-steer-and-follow-up-no-longer-bypass-extension-input-handlers
Profile citations
- Pi Coding Agent / claim / rpc-steer-input-handlers
- Pi Coding Agent / posture / governance
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact