pi-perms
Pi CLI extension — configurable permission policy from .agents/permissions.json and native agent configs
6.2k listings for pi
323 results · page 2 of 7
Pi CLI extension — configurable permission policy from .agents/permissions.json and native agent configs
Pi-first audit extension package for structured security reviews and deterministic comparison exports
A deliberately permissive permission gate for the Pi coding agent — blocks only destructive commands, never nags.
Runtime safety net for AI agents — blocks dangerous commands, protects files, enforces rate limits, and records sessions.
Free-form, LLM-driven model switching for Pi — resolve a free-text model reference and switch mid-conversation, no approval loop, no auto-restore
Canonical SKILL.md path correction and bash skill-access guard for Pi.
Pi skill for reviewing npm-registry dependency safety across npm, pnpm, yarn, and bun before project initialization, feature work, package additions, or package updates.
Codex-style sandbox boundary guardian gate for pi-coding-agent.
A comprehensive collection of extension packages for Pi the coding agent — token guard, system context, tool profiler, project detector, dirty guard, permission gate, prompt customizer, auto commit, turn clock, branch navigator, and more.
Claude-Code-style dynamic workflow orchestration for Pi (Baryon fork: crash-safe script errors + guarded sandbox).
Line count guard and behavior rules extension for pi-coding-agent
A coding agent CLI hook - block destructive git and filesystem commands before execution
A persistent, policy-guarded Playwright browser for AI agents with network controls, trusted credential filling, proof screenshots, and CAPTCHA helpers.
Model-backed boundary approval broker for Pi
OS-level sandboxing for pi with interactive permission prompts
Sandbox Runtime-backed Linux and macOS sandbox with pi-auto-review approval

Pi extension for resource-aware security policy engine and tool authorization
Pi, enhanced — one install for nklisch's full harness: policy-gated command review, plugin marketplace, subagents, background tasks, research tools, search, model modes, and a curated UX set.
Context engine for Pi — zero-LLM compaction, session continuity, sandbox execution, and tool display optimization
Agent Approve extension for Pi - approve or deny AI agent tool calls from your iPhone and Apple Watch
Numbered approval options and Tab-to-comment for Pi's extension select dialogs, including pi-auto-permissions command approval prompts.
Reusable Pi agent platform, project adapters, MCP/tool policy, and coding workflow harness.
Tool-output redaction for Pi that replaces likely secrets before they reach the model context
Deny-first Pi guardrails that keep LLM shell and file access safe, transparent, and user-approved.
Global tool-output redaction for Pi — redacts secrets, certificates, PII, and connection strings across all tools before they reach the model.
Permission enforcement extension for the Pi coding agent.
Jeff is a model-native quality control plane and cooperative workflow protocol for trusted operators and friendly agents, not a security sandbox.
Pi permission extension — four permission modes (yolo/auto/approve/strict) with three-layer pipeline (AST + rules + AI classifier).
Minimal subagent runtime for Pi.
Pi extension — permission gate for dangerous bash commands (confirm/block with TUI dialog)
Ory plugin for Pi (the minimal coding agent): scaffolding skills, a local Ory instance, and authentication, authorization, and audit for every tool call
Keep Pi's TUI responsive during long streamed responses with incremental Markdown rendering
localterm <-> pi integration: Kitty graphics for the browser renderer, scrubbing localterm-managed secret env vars from the agent's bash-tool children, and OSC 9 desktop notifications when the agent finishes a long turn.
Deny-first typo-path model judge — a pi-permission-system Authorizer chain link
Offensive security case tracker for Pi Agent — bug bounties, CTFs, security audits
Pi coding agent extension that runs all tool calls inside a remote, ephemeral Daytona sandbox while the agent runs locally
Amber Protocol: repository-local governance kit for coding agents — install, audit, validate, and hand off agent-facing project state.
Declarative, user-definable permission modes for the pi coding agent: OS-level sandboxing (bubblewrap / sandbox-exec), an allow/ask/deny policy engine, real bash AST gating (tree-sitter), tool hiding, and skill/custom-tool gating.
Interactive guardrails for dangerous bash commands and protected file edits in Pi.
Codex-style automatic approval reviews for @gotgenes/pi-permission-system
A pi extension that prompts before session changes when the current git repo has uncommitted changes.
Guardian extension for pi — security guards that block accidental secret exposure, enforce command policies, protect .env files, and sandbox bash commands
OMP-style large-output policy for Pi tool results: minimization, bounded truncation, and spill-file preservation.
decorated-pi is a practical enhancement pack for pi coding agent — token-efficient workflow, cache-friendly design, and smarter tools.
Declarative command tools for pi — structured, pre-approved commands instead of a shell.
Anti-slop UI/UX design discipline for your Pi agent — anchors a lintable DESIGN.md, runs deterministic slop-audit gates (APCA contrast + tokens + states + slop tells), works with text-only models, ships reference design-system presets.
Configurable auto-reviewer Pi extension for parsed, structural command policy