Packages

6.2k listings for pi · 0 reviewed by us

🛡 Guards & policy Block or rewrite dangerous tool calls, sandbox commands, enforce permissions.

323 results · page 1 of 7

extension

@yevhen.b/pi-preflight

Tool-call approvals and policy rules for Pi.

🤖🔑📁 +2
yevhen.bobrov ★ 19 ↓ 26
extension

pi-thegreataxios-staples

Personal staple extension for pi coding-agent — protected paths

thegreataxios ★ 13 ↓ 35
tool

@tangle-network/tcloud-agent

Agent run-loop primitive over Tangle sandbox transports — runs an AgentProfile against a brief with criterion gates, budget caps, and streaming events. Includes TangleToolProvider for Pi tool integration.

🤖📁🌐🔧 +1
tin-tangle-tools ★ 0 ↓ 20.6k
extension

@yoseph_23/implannotator

Approval-gated frontend implementation for Pi, combining Implannotator design guidance with Plannotator reviews.

🤖📡📁 +3
yoseph_23 ★ 0 ↓ 309
extension

@akshaykarle/pi-tools

Pi coding agent extensions — security hardening, agent teams and more

🤖📡🔑 +7
akshaykarle ★ 0 ↓ 307
extension

@a5c-ai/babysitter-pi

Orchestrate complex, multi-step workflows with event-sourced state management, hook-based extensibility, and human-in-the-loop approval — pi

🤖📡📁
tmuskal ↓ 10.0k
toolextension

cc-safety-net

A coding agent CLI hook - block destructive git and filesystem commands before execution

🤖📁 +1
GitHub Actions ↓ 8.7k
extension

betterwright

A persistent, policy-guarded Playwright browser for AI agents with network controls, trusted credential filling, proof screenshots, and CAPTCHA helpers.

🤖🔑📁 +4
GitHub Actions ↓ 7.0k
promptextension

pi-sandbox

OS-level sandboxing for pi with interactive permission prompts

📡📁 +2
GitHub Actions ↓ 5.8k
extension

@xaccefy/pi-casefile

Offensive security case tracker for Pi Agent — bug bounties, CTFs, security audits

🤖📁 +2
xaccefy ↓ 5.7k
extension

@xaccefy/pi-exploitsearch

ExploitSearch extension for Pi Agent — query preview.is security corpus for attack techniques, primitives, and bypasses

🔑📁🌐🔧
xaccefy ↓ 4.2k
extension

@aliou/pi-guardrails

![banner](https://assets.aliou.me/github/aliou/pi-guardrails/banner.png)

🤖📡📁 +2
GitHub Actions ↓ 4.0k
extension

@agentapprove/pi

Agent Approve extension for Pi - approve or deny AI agent tool calls from your iPhone and Apple Watch

🤖🔑📁 +2
jbeno ↓ 3.7k
skillprompt

@piagent/platform

Reusable Pi agent platform, project adapters, MCP/tool policy, and coding workflow harness.

🤖📁 +4
vt-mmm ↓ 3.6k
extension

@amaster.ai/pi-security

Pi extension for resource-aware security policy engine and tool authorization

📁
2betop ↓ 2.9k
extension

@johanthoren/jeff

Jeff is a model-native quality control plane and cooperative workflow protocol for trusted operators and friendly agents, not a security sandbox.

🔑📁🔧 +1
GitHub Actions ↓ 2.9k
skillextension

@ory/pi

Ory plugin for Pi (the minimal coding agent): scaffolding skills, a local Ory instance, and authentication, authorization, and audit for every tool call

📁
GitHub Actions ↓ 2.5k
extension

@agwab/pi-subagent

Minimal subagent runtime for Pi.

🤖📁🔧 +1
GitHub Actions ↓ 2.3k
extension

pi-permission-system

Permission enforcement extension for the Pi coding agent.

🤖📡🔑📁 +3
masurii ↓ 2.1k
extension

@thurstonsand/pi-permissions

Pi extension package for user, project, and package-level tool permission hooks

📡📁 +1
GitHub Actions ↓ 2.0k
extension

pi-defender

Defense-in-depth protection for Pi coding agent. Blocks dangerous commands and protects sensitive files — rename of pi-damage-control.

🤖🔑📁 +4
serhioromano ↓ 2.0k
extension

@xynogen/pix-gate

Pi extension — permission gate for dangerous bash commands (confirm/block with TUI dialog)

GitHub Actions ↓ 1.8k
extension

@pandi-coding-agent/pandi-container

Extensión de Pi para administrar sandboxes de Apple `container` (micro-VMs Linux): un comando /container y una herramienta container_sandbox invocable por el modelo (status/list/create/run/stop/remove).

🔧
andrestobelem ↓ 1.8k
skill

amber-protocol

Amber Protocol: repository-local governance kit for coding agents — install, audit, validate, and hand off agent-facing project state.

📁
amsterdam-littlehill ↓ 1.7k
skill

@yammd/forge-skills

Global AI Skills Ecosystem for code review and audit

yammd ↓ 1.7k
themeskill

zmarketplace

Cross-agent marketplace search: find, audit, and install plugins/skills/themes/prompts across pi, omp, claude code, opencode, gemini cli, and codex

🔑📁🌐 +1
zicodev ↓ 1.7k
extension

pi-perm

Config-driven Pi sandbox and permission extension using sandbox-runtime.

📁🔧 +1
dcrcold ↓ 1.7k
promptextension

picodesandbox

OS-level sandboxing for pi with interactive permission prompts

📁🔧 +1
tomasko ↓ 1.6k
extension

pi-approval-guardian

A fail-closed-by-default Pi approval gate that reviews shell actions, private data access, and sensitive file mutations with an isolated risk model and explicit temporary bypass.

🤖🔑📁 +1
GitHub Actions ↓ 1.4k
extension

@xaccefy/pi-engage

Authenticated-session manager for Pi Agent — store and resolve cookie, OAuth client-credentials, and mTLS auth for authorized pentest targets

🔑📁🌐 +2
xaccefy ↓ 1.3k
extension

@ramtinj95/pi-infra-command-guard

Approval guard for risky infrastructure, cloud, container, repository, secret, and local file commands in Pi and GPT-5.6 Code Mode

🤖📁 +2
ramtinj95 ↓ 1.3k
tool

hyperresearch-pi

Deep research harness for pi — tier-adaptive 16-step pipeline with adversarial audit, source provenance, and a persistent searchable vault. Wraps the hyperresearch Python CLI.

🤖📁 +3
gongsunyuan ↓ 1.3k
extension

@agentoom/pi-reviewer

Post-task multi-area code review extension for pi — 7 specialised review areas (general, security, code quality, UI/UX, testing, performance, scope) with a checkbox picker UI

🔑📁🌐
agentoom ↓ 1.3k
toolextension

pi-opa-net

OPA-backed bash command guard for the pi ecosystem — structured decision-output.v1 JSON, fail-open default, Claude Code hook protocol compatible. Agent-agnostic engine + CLI.

📁🌐
buihongduc132 ↓ 1.3k
skill

@firstpick/pi-skill-deep-research

Agents should invoke this skill for high-stakes or complex research needing multi-source evidence, scientific/technical fact-checking, decision traces, or rigorous verification. Runs deterministic two-phase research with schema/policy validation.

firstpick ↓ 1.2k
extension

@spences10/pi-redact

Tool-output redaction for Pi that replaces likely secrets before they reach the model context

spences10 ↓ 1.2k
extension

@josephyoung/pi-heimdall

Guardian extension for pi — security guards that block accidental secret exposure, enforce command policies, protect .env files, and sandbox bash commands

📁🔧 +1
GitHub Actions ↓ 1.2k
toolextension

@bacnh85/pi-windows-tools

Pi extension for Windows-native tool manipulation — shell profiles, path conversion, command execution, WSL bridge, safety policy, and developer tool discovery.

🤖📁🔧 +1
bacnh85 ↓ 1.1k
extension

@senad-d/guardme

Deny-first Pi guardrails that keep LLM shell and file access safe, transparent, and user-approved.

🤖📁
GitHub Actions ↓ 1.1k
extension

@spences10/pi-confirm-destructive

Git-aware Pi guardrail that asks for confirmation before destructive shell actions can change or lose work

📁
spences10 ↓ 1.0k
extension

@monotykamary/pi-localterm

localterm <-> pi integration: Kitty graphics for the browser renderer, scrubbing localterm-managed secret env vars from the agent's bash-tool children, and OSC 9 desktop notifications when the agent finishes a long turn.

📡📁🔧
monotykamary ↓ 1.0k
extension

@erichll/pi-sandbox

Sandbox Runtime-backed Linux and macOS sandbox with pi-auto-review approval

📁🌐 +3
erichll ↓ 995
skill

@soulofzephir/pi-skill-pentesting

Comprehensive pentesting & security check skill for Pi coding agent - headers, ports, SQLi, XSS, OWASP Top 10

soulofzephir ↓ 988
skill

@loopskills/claude-skills

Research-driven planning, debugging, and audit skills for Claude Code and Pi

🤖📁🌐 +2
tech1e ↓ 963
skillextension

pi-permission-modes

Declarative, user-definable permission modes for the pi coding agent: OS-level sandboxing (bubblewrap / sandbox-exec), an allow/ask/deny policy engine, real bash AST gating (tree-sitter), tool hiding, and skill/custom-tool gating.

🤖📁 +3
wynainfo ↓ 943