Signals

2026-08-10 / Pi Coding Agent

Any directory can replace the operator's context file, and it loads before project trust is resolved

Edited by Michael Ruescher

An override file in a directory replaces the operator's own context file, and it is read before the trust decision that is supposed to gate what a repository may do. That is the same shape as the defect this publication recorded when a workspace-trust backend read its trust value out of the workspace it was guarding: a guard consulting the thing it guards. Carried with it, because it is the same window and the same source: a third command now prints a live provider credential to stdout, and none of the three is gated from the agent's own shell tool.

What this changes for operators

  • Treat cloning an untrusted repository as an action that can change your agent's instructions before you have decided to trust it.
  • The credential commands are ungated from the tool the agent itself drives, so an agent that can run a shell can print your provider token. There are now three such commands where the last window recorded two, which is movement in the wrong direction.

Signal metadata

Source findings

Run: 2026-08-10-weekly-digest-2026-08-03_2026-08-10-frontier-v0

Schema: bitter.frontier_signals.v0 / ID: 2026-08-10-pi-context-file-replaceable-before-trust

Research evidence and publication history are open in the repository.