by DLYZZT
A local-first, cross-platform Electron desktop workspace for Pi Coding Agent, with sessions, project files, browser tools, skills, plugins, and messaging integrations.
# Add to your Claude Code skills
git clone https://github.com/DLYZZT/pi-desktopLast scanned: 8/7/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@earendil-works/pi-coding-agent: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@electron/node-gyp: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@electron/rebuild: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "app-builder-lib: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups",
"severity": "high"
},
{
"type": "npm-audit",
"message": "builder-util: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "builder-util-runtime: electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`",
"severity": "high"
},
{
"type": "npm-audit",
"message": "cacache: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "dmg-builder: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "dompurify: DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.",
"severity": "low"
},
{
"type": "npm-audit",
"message": "electron-builder: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "electron-builder-squirrel-windows: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "electron-publish: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "esbuild: esbuild allows arbitrary file read when running the development server on Windows",
"severity": "low"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass",
"severity": "high"
},
{
"type": "npm-audit",
"message": "js-yaml: JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported",
"severity": "high"
},
{
"type": "npm-audit",
"message": "make-fetch-happen: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "mermaid: Mermaid configuration APIs allow prototype pollution",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure",
"severity": "high"
},
{
"type": "npm-audit",
"message": "protobufjs: protobufjs: Denial of Service via infinite loop in .proto option parsing",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "tar: node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "undici: undici vulnerable to downstream response desynchronization via retry interceptor",
"severity": "high"
}
],
"status": "FAILED",
"scannedAt": "2026-08-07T05:40:30.231Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how pi-desktop compares with popular alternatives.
pi-desktop is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by DLYZZT. A local-first, cross-platform Electron desktop workspace for Pi Coding Agent, with sessions, project files, browser tools, skills, plugins, and messaging integrations. It has 225 GitHub stars.
pi-desktop failed SkillsLLM's automated security scan, which flagged one or more high-severity issues. Review the Security Report section carefully before using it.
Clone the repository with "git clone https://github.com/DLYZZT/pi-desktop" and add it to your Claude Code skills directory (see the Installation section above).
pi-desktop is primarily written in TypeScript. It is open-source under DLYZZT on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh pi-desktop against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
把 Pi Coding Agent 变成真正的桌面工作台。
本地优先 · 零内部服务器 · 跨平台应用
English · 简体中文
下载 v0.2.3 · 截图 · 功能 · 快速开始 · 架构 · 变更记录 · 路线图

@ 文件引用WebContentsView 承载真实 Chromium 页面,支持多 Tab、临时/持久 Profile、登录态、下载、上传和代理process_* tools 持续运行 Vite、React、Three.js、Storybook、Flask、Spring Boot、mock API 和 watch build;普通短命令继续走 Bash&、nohup 或外部终端v0.2.3 的受管后台进程支持 macOS、Linux 和 Windows 11 x64;Windows ARM64、Windows Server 和 32 位 Windows 暂不支持。
agent.stop,因此 Agent close 会明确关闭其所在 pane,不会静默伪造停止语义.docx)文档/help、/status、/new、/compact 和 /reloadsandbox: true、严格 CSP 与类型化 IPC 契约最新稳定版为 v0.2.3,提供 macOS Apple Silicon / Intel、Windows x64 和 Linux x64 安装包。
Pi Agent Desktop v0.2.3 已内置 Pi Coding Agent 0.85.0 运行时。普通用户使用 Agent 本身无需单独安装 Pi CLI、Pi Coding Agent、Node.js 或 npm;安装桌面应用并配置模型提供商后即可使用。Skills、Plugins 或 Agent 脚本需要额外开发工具时,应用会优先复用健康的系统安装,也可以在用户确认后安装应用私有运行时。
应用会读取 ~/.pi/agent/ 中的会话与配置。如果你已经使用 Pi CLI,可以直接复用现有数据,无需迁移;此前没有使用过 Pi CLI 也不影响使用。
Pi Desktop 会先发现并验证用户已经安装的 Node.js/npm、Python、Git、Bash、uv、jq 和 Bun;内置的 rg/fd 保证离线搜索可用。
git clone https://github.com/DLYZZT/pi-desktop.git
cd pi-desktop
npm ci
npm run dev
Pi Agent Desktop 使用 Electron 三进程模型,将高权限桌面能力、Agent 运行时和 UI 隔离开来。
flowchart LR
Main["Electron Main<br/>窗口 · 托盘 · 协议 · Host 监督"]
Host["Agent Host / utilityProcess<br/>Pi Agent · 会话 · 文件 · 配置"]
UI["Renderer<br/>React 19 · Vite"]
Browser["Main-owned WebContentsView<br/>远程网页 · Profile · 网络策略"]
Processes["受管项目进程<br/>dev server · watcher · mock API"]
Data["~/.pi/agent/<br/>会话 · 模型 · 配置"]
Main --> Host
Main --> UI
Main --> Browser
Host -->|"revisioned Browser RPC"| Main
Host -->|"POSIX worker / Windows Job helper"| Processes
Main -.->|"crash reaper"| Processes
Browser -->|"独立授权的 localhost 访问"| Processes
UI <-->|"Typed MessagePort IPC"| Host
Host <--> Data
utilityProcess 中运行 Pi Coding Agent,处理会话、文件、配置与扩展WebContentsView,不获得应用 preload、Node 或主 Renderer bridge~/.pi/agent/| 命令 | 说明 |
|---|---|
npm run dev |
启动 Vite、主进程构建监听与 Electron |
npm run typecheck |
执行 TypeScript 类型检查 |
npm run test |
运行自动化测试套件 |
npm run check:contract |
检查 API 方法与 Host handler 覆盖关系 |
npm run smoke |
运行 Electron 冒烟测试 |
npm run test:browser-electron |
运行本地 Browser Electron 集成测试 |
npm run test:managed-process-workflows |
运行受管进程生命周期与清理测试 |
npm run test:herdr-e2e |
使用指定官方 binary 运行隔离 Herdr E2E |
npm run test:herdr-desktop-e2e |
运行 production Electron/Renderer Herdr 集成 E2E |
npm run test:windows-managed-helper |
在 Windows x64 验收 Rust helper 与 Job Object |
npm run verify |
执行提交前的完整质量检查 |
npm run build |
构建 main、preload 与 renderer |
npm run pack |
生成未封装的应用目录 |
npm run dist |
生成当前平台配置的全部架构安装包 |
npm run dist:mac:signed |
生成当前 Mac 架构的 Developer ID 签名包 |
npm run dist:mac:notarized |
生成签名并经 Apple 公证的 macOS 包 |
src/
├── contract/ # IPC 类型契约与 RPC 层
├── main/ # Electron 主进程与 crash reaper
├── preload/ # 安全桥接接口
├── agent-host/ # Agent、会话、文件、配置与受管进程
├── renderer/ # React 桌面界面
└── shared/ # 可测试的纯函数与共享模块
native/
└── windows-managed-process-helper/ # Windows x64 Rust / Job Object helper
欢迎通过 Issues 提交问题或建议,也欢迎直接发起 Pull Request。提交代码前请至少运行:
npm run verify