Any directory can replace the operator's context file, and it loads before project trust is resolved
An override file in a directory replaces the operator's own context file, and it is read before the trust decision that is supposed to gate what a repository may do. That is the same shape as the defect this publication recorded when a workspace-trust backend read its trust value out of the workspace it was guarding: a guard consulting the thing it guards. Carried with it, because it is the same window and the same source: a third command now prints a live provider credential to stdout, and none of the three is gated from the agent's own shell tool.
What this changes for operators
- Treat cloning an untrusted repository as an action that can change your agent's instructions before you have decided to trust it.
- The credential commands are ungated from the tool the agent itself drives, so an agent that can run a shell can print your provider token. There are now three such commands where the last window recorded two, which is movement in the wrong direction.
Primary sources
- merged_pr 2026-08-10-pi-coding-agent-agents-override-md-lets-any-directory-replace-the-operator-s-context github.com/earendil-works/pi/pull/7681
- official_docs 2026-08-10-pi-coding-agent-pi-auth-check-adds-a-third-command-that-prints-a-live-provider earendil-works/pi / packages/coding-agent/src/cli/auth-command.ts
Signal metadata
Source findings
- 2026-08-10-pi-coding-agent-agents-override-md-lets-any-directory-replace-the-operator-s-context 2026-08-10-pi-coding-agent-agents-override-md-lets-any-directory-replace-the-operator-s-context
- 2026-08-10-pi-coding-agent-pi-auth-check-adds-a-third-command-that-prints-a-live-provider 2026-08-10-pi-coding-agent-pi-auth-check-adds-a-third-command-that-prints-a-live-provider
Run: 2026-08-10-weekly-digest-2026-08-03_2026-08-10-frontier-v0
Schema: bitter.frontier_signals.v0 / ID: 2026-08-10-pi-context-file-replaceable-before-trust
Research evidence and publication history are open in the repository.