Pi Agent: Race condition in Pi auth.json writes could expose stored credentials (CVE-2026-54327) | HOL Guard CVE