Packages

6.2k listings for pi

🛡 Guards & policy Block or rewrite dangerous tool calls, sandbox commands, enforce permissions.

323 results · page 2 of 7

toolextension

pi-perms

Pi CLI extension — configurable permission policy from .agents/permissions.json and native agent configs

GitHub Actions ★ 0 ↓ 46
extension

@4meta5/pi-ozcar

Pi-first audit extension package for structured security reviews and deterministic comparison exports

📁🔧
4meta5 ★ 0 ↓ 37
extension

pi-permissive

A deliberately permissive permission gate for the Pi coding agent — blocks only destructive commands, never nags.

nilskluewer ★ 0 ↓ 34
extension

@bytesbrains/pi-agent-supervisor

Runtime safety net for AI agents — blocks dangerous commands, protects files, enforces rate limits, and records sessions.

📁🔧
nandal ★ 0 ↓ 34
extension

pi-switch-model

Free-form, LLM-driven model switching for Pi — resolve a free-text model reference and switch mid-conversation, no approval loop, no auto-restore

🔧
timzolleis ★ 0 ↓ 27
skillextension

@haemmid/pi-skill-paths

Canonical SKILL.md path correction and bash skill-access guard for Pi.

📁
haemmid ★ 0 ↓ 25
skill

pi-dependency-safety

Pi skill for reviewing npm-registry dependency safety across npm, pnpm, yarn, and bun before project initialization, feature work, package additions, or package updates.

GitHub Actions ★ 0 ↓ 22
extension

@ikuradon/pi-guardian

Codex-style sandbox boundary guardian gate for pi-coding-agent.

📁🔧 +1
ikuradon ★ 0 ↓ 20
promptextension

@jaraxxxx/pi-extensions

A comprehensive collection of extension packages for Pi the coding agent — token guard, system context, tool profiler, project detector, dirty guard, permission gate, prompt customizer, auto commit, turn clock, branch navigator, and more.

🤖📁 +1
jaraxxxx ★ 0 ↓ 19
extension

@baryonlabs/pi-dynamic-workflows

Claude-Code-style dynamic workflow orchestration for Pi (Baryon fork: crash-safe script errors + guarded sandbox).

🔀🔧
martinhong ★ 0 ↓ 18
extension

pi-shepherd

Line count guard and behavior rules extension for pi-coding-agent

🤖📡📁 +4
lain-residue ★ 0 ↓ 18
toolextension

cc-safety-net

A coding agent CLI hook - block destructive git and filesystem commands before execution

🤖📁 +1
GitHub Actions ↓ 25.9k
extension

betterwright

A persistent, policy-guarded Playwright browser for AI agents with network controls, trusted credential filling, proof screenshots, and CAPTCHA helpers.

🤖🔑📁 +4
GitHub Actions ↓ 10.1k
extension

@erichll/pi-auto-review

Model-backed boundary approval broker for Pi

🤖📡🔑📁 +2
erichll ↓ 4.9k
promptextension

pi-sandbox

OS-level sandboxing for pi with interactive permission prompts

📡📁 +2
GitHub Actions ↓ 4.3k
extension

@erichll/pi-sandbox

Sandbox Runtime-backed Linux and macOS sandbox with pi-auto-review approval

📁🌐 +3
erichll ↓ 4.3k
extension

@aliou/pi-guardrails

![banner](https://assets.aliou.me/github/aliou/pi-guardrails/banner.png)

🤖📡📁 +2
GitHub Actions ↓ 4.1k
extension

@amaster.ai/pi-security

Pi extension for resource-aware security policy engine and tool authorization

📁
2betop ↓ 3.7k
extension

@nklisch/pi-enhanced

Pi, enhanced — one install for nklisch's full harness: policy-gated command review, plugin marketplace, subagents, background tasks, research tools, search, model modes, and a curated UX set.

🤖📡🔑 +8
GitHub Actions ↓ 3.1k
extension

@pi-unipi/compactor

Context engine for Pi — zero-LLM compaction, session continuity, sandbox execution, and tool display optimization

🤖📁 +2
neuron-mr-white ↓ 2.9k
extension

@agentapprove/pi

Agent Approve extension for Pi - approve or deny AI agent tool calls from your iPhone and Apple Watch

🤖🔑📁 +2
jbeno ↓ 2.5k
promptextension

@hank-warren/pi-permission-selector

Numbered approval options and Tab-to-comment for Pi's extension select dialogs, including pi-auto-permissions command approval prompts.

🤖
hank-warren ↓ 2.5k
skillprompt

@piagent/platform

Reusable Pi agent platform, project adapters, MCP/tool policy, and coding workflow harness.

🤖📁 +4
vt-mmm ↓ 2.4k
extension

@spences10/pi-redact

Tool-output redaction for Pi that replaces likely secrets before they reach the model context

spences10 ↓ 2.0k
extension

@senad-d/guardme

Deny-first Pi guardrails that keep LLM shell and file access safe, transparent, and user-approved.

🤖📁
GitHub Actions ↓ 2.0k
extension

pi-redact-all

Global tool-output redaction for Pi — redacts secrets, certificates, PII, and connection strings across all tools before they reach the model.

🤖📁📡
steimerbyte ↓ 1.7k
extension

pi-permission-system

Permission enforcement extension for the Pi coding agent.

🤖📡🔑📁 +3
masurii ↓ 1.7k
extension

@johanthoren/jeff

Jeff is a model-native quality control plane and cooperative workflow protocol for trusted operators and friendly agents, not a security sandbox.

🔑📁🔧 +1
GitHub Actions ↓ 1.6k
extension

@zhushanwen/pi-permission

Pi permission extension — four permission modes (yolo/auto/approve/strict) with three-layer pipeline (AST + rules + AI classifier).

📁
zhushanwen321 ↓ 1.6k
extension

@agwab/pi-subagent

Minimal subagent runtime for Pi.

🤖📁🔧 +1
GitHub Actions ↓ 1.5k
extension

@xynogen/pix-gate

Pi extension — permission gate for dangerous bash commands (confirm/block with TUI dialog)

GitHub Actions ↓ 1.5k
skillextension

@ory/pi

Ory plugin for Pi (the minimal coding agent): scaffolding skills, a local Ory instance, and authentication, authorization, and audit for every tool call

📁
GitHub Actions ↓ 1.2k
extension

pi-streaming-guard

Keep Pi's TUI responsive during long streamed responses with incremental Markdown rendering

monotykamary ↓ 1.2k
extension

@monotykamary/pi-localterm

localterm <-> pi integration: Kitty graphics for the browser renderer, scrubbing localterm-managed secret env vars from the agent's bash-tool children, and OSC 9 desktop notifications when the agent finishes a long turn.

📡📁🔧
monotykamary ↓ 1.1k
extension

@xaccefy/pi-casefile

Offensive security case tracker for Pi Agent — bug bounties, CTFs, security audits

🤖📁 +2
xaccefy ↓ 961
extension

@daytona/pi

Pi coding agent extension that runs all tool calls inside a remote, ephemeral Daytona sandbox while the agent runs locally

🤖🔑 +2
GitHub Actions ↓ 938
skill

amber-protocol

Amber Protocol: repository-local governance kit for coding agents — install, audit, validate, and hand off agent-facing project state.

📁
amsterdam-littlehill ↓ 934
skillextension

pi-permission-modes

Declarative, user-definable permission modes for the pi coding agent: OS-level sandboxing (bubblewrap / sandbox-exec), an allow/ask/deny policy engine, real bash AST gating (tree-sitter), tool hiding, and skill/custom-tool gating.

🤖📁 +3
wynainfo ↓ 863
promptextension

@diegopetrucci/pi-dirty-repo-guard

A pi extension that prompts before session changes when the current git repo has uncommitted changes.

diegopetrucci ↓ 673
extension

@casualjim/pi-heimdall

Guardian extension for pi — security guards that block accidental secret exposure, enforce command policies, protect .env files, and sandbox bash commands

📁🔧 +1
GitHub Actions ↓ 672
extension

@vanillagreen/pi-output-policy

OMP-style large-output policy for Pi tool results: minimization, bounded truncation, and spill-file preservation.

📁
vanillagreencom ↓ 639
toolextension

decorated-pi

decorated-pi is a practical enhancement pack for pi coding agent — token-efficient workflow, cache-friendly design, and smarter tools.

🤖🔑📁 +5
weckerrr ↓ 535
extension

pi-armory

Declarative command tools for pi — structured, pre-approved commands instead of a shell.

🔑📁 +4
GitHub Actions ↓ 493
skill

@bacnh85/pi-ux

Anti-slop UI/UX design discipline for your Pi agent — anchors a lintable DESIGN.md, runs deterministic slop-audit gates (APCA contrast + tokens + states + slop tells), works with text-only models, ships reference design-system presets.

🤖📁🔧 +1
bacnh85 ↓ 428
extension

@nklisch/pi-clearance

Configurable auto-reviewer Pi extension for parsed, structural command policy

🤖🔑📁 +4
nklisch ↓ 423