Packages

6.2k listings for pi · 0 reviewed by us

🛡 Guards & policy Block or rewrite dangerous tool calls, sandbox commands, enforce permissions.

323 results · page 2 of 7

toolextension

decorated-pi

decorated-pi is a practical enhancement pack for pi coding agent — token-efficient workflow, cache-friendly design, and smarter tools.

🤖🔑📁 +5
weckerrr ↓ 902
promptextension

@diegopetrucci/pi-permission-gate

A pi extension that prompts before dangerous bash commands and protected file writes.

diegopetrucci ↓ 883
skilltool

oh-my-vul

Evidence-first vulnerability research skills and CLI for Pi, Codex, and Claude Code

🔑📁🌐
bpple33661 ↓ 882
extension

@shelken/pi-guard

Hard-block dangerous agent bash commands and secret path access

📁
GitHub Actions ↓ 872
extension

@minhduydev/pi-learning

Append-only project-local learning ledger for Pi with two separate trust gates: manual human approval, and a bounded auto-safe machine gate that is on by default in Pi-trusted projects. Selective fork of Matt Devy's pi-continuous-learning.

🤖📡📁
minhduydev ↓ 868
promptextension

@diegopetrucci/pi-dirty-repo-guard

A pi extension that prompts before session changes when the current git repo has uncommitted changes.

diegopetrucci ↓ 854
extension

smart-approve

High-risk-only approval hook with LLM risk analysis, behavior detection, protected-path interception, and decision memory for oh-my-pi (OMP) and pi-agent.

📁🛠 +1
mentalfl0w ↓ 848
extension

pi-wayfinder-guard

Pi extension enforcing no-implementation during wayfinder (fog mode), with a parallel four-axis code review.

🤖📁 +2
tianhai ↓ 840
extension

@pi-unipi/compactor

Context engine for Pi — zero-LLM compaction, session continuity, sandbox execution, and tool display optimization

🤖📁 +2
neuron-mr-white ↓ 815
promptextension

@agentoom/pi-spending-guard

Track LLM spending per task and pause when a configurable threshold is reached — continue, refine the prompt, or stop. Pi extension by agentoom.com.

🤖📁
agentoom ↓ 807
extension

@mammothb/pi-permissions

Permission enforcement extension for pi — gates tool calls, bash commands (via arbiter executable), and file paths

📡📁 +1
mammothb ↓ 795
extension

pi-fff-non-ascii-guard

Pi extension that detects and renames non-ASCII filenames before fff-core can panic on UTF-8 byte boundaries.

🤖📁🔧 +1
GitHub Actions ↓ 791
extension

@orca-sec/pi-orca

Official ryk Pi integration for fail-closed bash and file protection.

🤖📁 +1
karc14 ↓ 790
skillextension

loop-skills

Research-driven planning, debugging, and audit skills for Codex, Pi, and Claude Code

🤖📁🌐 +2
tech1e ↓ 784
extension

@erichll/pi-auto-review

Model-backed boundary approval broker for Pi

🤖📡🔑📁 +2
erichll ↓ 757
extension

pi-cwd-guard

Small Pi safety extension for cwd access, protected paths, runtime config confirmation, and common destructive bash commands.

🤖📁
devnazim ↓ 704
extension

@andre-barbosa/pi-review

A read-only two-stage code review extension for pi

🤖🔑📁 +1
andre-barbosa ↓ 701
skillextension

pi-skill-shiori

Pi extension that reduces Agent Skill catalog tokens with policy-based skill retrieval and on-demand skill loading.

🤖📁🔧 +1
GitHub Actions ↓ 697
extension

@upstash/box-pi

Pi coding agent extension that runs all tool calls inside a remote Upstash Box sandbox while the agent runs locally

🤖🔑 +2
GitHub Actions ↓ 663
extension

@spences10/pi-nopeek

Secret-safe workflow reminder that steers Pi agents to use nopeek instead of exposing .env values

🤖
spences10 ↓ 652
skill

@firstpick/pi-skill-research-orchestration

Agents should invoke this skill for broad multi-claim research projects needing planning, parallel investigation, source merging, gap closure, citation audit, and final synthesis when narrower research skills are insufficient.

firstpick ↓ 644
extension

@uiyzzi/pi-asroot

sudo for pi — agent asks, user types their password into a masked TUI input, password never reaches the model

🤖📁
GitHub Actions ↓ 640
extension

@uiyzzi/pi-shroud

High-performance secret firewall for pi — secrets usable as shell vars, never visible to models

🤖📁
GitHub Actions ↓ 635
extension

pi-permission-suite

Four approval modes + command-level security restrictions for the Pi coding agent. Act / Auto / Ask / Plan mode switching, rule engine, subagent auto-approval.

🤖📁 +2
eddie0521 ↓ 630
extension

pi-herdr-sudo-task

Blocking, user-approved sudo tasks in a dedicated Herdr pane

📁🔧
GitHub Actions ↓ 619
skilltool

@blackbelt-technology/pi-dashboard-code-review-toolkit

Code-review workflow skills for pi sessions — code-review (AI-powered review with severity labels via the CodeRabbit CLI) and autofix (safely review and apply CodeRabbit PR review-thread feedback with per-change approval). Pure-skill package, no extension

GitHub Actions ↓ 615
extension

@diegopetrucci/pi-agent-workflow-audit

A pi extension that runs an isolated repo workflow audit and returns only the final report to the main session.

🤖📁 +1
diegopetrucci ↓ 615
extension

pi-vuln-scanner

A pi extension that scans locally installed pi packages for vulnerabilities and supply-chain risk.

🔑📁🌐 +1
GitHub Actions ↓ 612
extension

@senad-d/protectme

Pi extension that guards agent network and website access with global and project allow lists.

🤖📁🌐 +1
GitHub Actions ↓ 575
extension

pi-seatbelt-sandbox

macOS Seatbelt sandbox extension package for pi bash and file-tool access controls.

📁🔧 +1
thaodangspace ↓ 551
toolextension

whisper-pi

Native Pi extension: give a Pi coding agent a real, routable Whisper IPv6 /128 identity - keyless verify/RDAP; the full control plane, /128 egress, and the whisper.security graph (Cypher + 29 recipes) with a key.

🔧
kakooch ↓ 543
promptextension

@false00/cyber-news

Interactive cybersecurity news briefing for the Pi coding agent with live multi-source headlines and deep-dive story prompts

🤖📁🌐
false00 ↓ 540
promptextension

@d3ara1n/pi-access-denied

Sandbox write/edit/bash to the project dir — prompt / deny / allow modes, configurable deny-with-redirect rules, per-session allow-deny memory

📁
GitHub Actions ↓ 540
extension

@celestoai/pi

Run Pi coding tools in a Celesto computer

🤖🔑📁 +4
GitHub Actions ↓ 536
extension

@isr4el-silv4/loop-guard

Pi extension that detects and prevents LLM loops in tool calls and reasoning

🤖
isr4el-silv4 ↓ 518
extension

pi-refusal-guard

A Claude safety-classifier refusal shouldn't kill your turn — rescue, retarget the server-side fallback chain, and see what's tripping.

🤖📁📡
GitHub Actions ↓ 500
extension

pi-redact-all

Global tool-output redaction for Pi — redacts secrets, certificates, PII, and connection strings across all tools before they reach the model.

🤖📁📡
steimerbyte ↓ 495
extension

pi-widget-host

Host package for managing one shared Pi widget slot across multiple providers with preset policies and a built-in demo provider.

📁
GitHub Actions ↓ 489
extension

@liziy/plan-guard

Tab 键切换计划/执行模式

🤖
liziy ↓ 487
prompt

@uiyzzi/pi-askpass

TUI secret prompt for pi — agent asks, user types in a masked input, value never reaches the model

🤖📁 +2
GitHub Actions ↓ 487
extension

@itc-steve/pi-ask-complete

Pi extension: bottom-panel ask_user + bash permission gate (Allow / Allow permanently / Deny with reason) writing ~/.pi/agent/permission.json

🤖📁 +2
GitHub Actions ↓ 475
skill

@firstpick/pi-package-skill-lifecycle

Self-contained Pi package for skill lifecycle management: memory, skill-bank audit, evaluation, creation, and refinement tools.

🤖📁🔧 +1
firstpick ↓ 460
extension

pi-excel-hygiene

Review Excel files for spreadsheet errors — mechanical checks (openpyxl) + Panko–Halverson taxonomy reasoning

🤖📁🔧 +1
wwyxin ↓ 442
extension

pi-sensitive-guard

Pi extension that protects sensitive files, blocks secret writes, and optionally redacts protected read output.

📡📁 +1
masurii ↓ 432
extension

@christianmoesl/pi-sbx

Run Pi coding-agent tool calls inside Docker sbx sandboxes

🤖📁 +2
christianmoesl ↓ 430