Packages

6.2k listings for pi

🛡 Guards & policy Block or rewrite dangerous tool calls, sandbox commands, enforce permissions.

323 results · page 3 of 7

extension

pi-playpen

Global, multi-project OS sandboxing for the pi coding agent

🤖📁 +2
moreheadm ↓ 418
extension

@mammothb/pi-permissions

Permission enforcement extension for pi — gates tool calls, bash commands (via arbiter executable), and file paths

📡📁 +1
mammothb ↓ 416
extension

@diegopetrucci/pi-agent-workflow-audit

A pi extension that runs an isolated repo workflow audit and returns only the final report to the main session.

🤖📁 +1
diegopetrucci ↓ 414
extension

pi-bash-confirm

Pi package for confirming bash commands before execution with Telegram notifications

🔑📁🌐 +1
matteo.collina ↓ 385
toolextension

@bacnh85/pi-windows-tools

Pi extension for Windows-native tool manipulation — shell profiles, path conversion, command execution, WSL bridge, safety policy, and developer tool discovery.

🤖📁🔧 +1
bacnh85 ↓ 377
extension

@ramtinj95/pi-infra-command-guard

Approval guard for risky infrastructure, cloud, container, repository, secret, and local file commands in Pi and GPT-5.6 Code Mode

🤖📁 +2
ramtinj95 ↓ 343
extension

pi-marketplace

Pi extension for searching, auditing, and installing pi packages from npm — with security review and optional pi.dev enrichment

📁🌐🔧 +1
diwu507 ↓ 331
skillextension

pi-skill-shiori

Pi extension that reduces Agent Skill catalog tokens with policy-based skill retrieval and on-demand skill loading.

🤖📁🔧 +1
GitHub Actions ↓ 318
skilltool

oh-my-vul

Evidence-first vulnerability research skills and CLI for Pi, Codex, and Claude Code

🔑📁🌐
bpple33661 ↓ 312
promptextension

@d3ara1n/pi-access-denied

Sandbox write/edit/bash to the project dir — prompt / deny / allow modes, configurable deny-with-redirect rules, per-session allow-deny memory

📁
GitHub Actions ↓ 308
extension

pi-minimal-permission-system

Minimal permission enforcement extension for the Pi coding agent.

📁
GitHub Actions ↓ 306
extension

@eggmasonvalue/pi-subagent

Observable, steerable, isolated-context subagents for pi — resume any child mid-task, flush partial results on interrupt/timeout, lean machine-facing envelope, optional model allowlist.

📁🔧
eggmasonvalue ↓ 301
extension

@pandi-coding-agent/pandi-container

Extensión de Pi para administrar sandboxes de Apple `container` (micro-VMs Linux): un comando /container y una herramienta container_sandbox invocable por el modelo (status/list/create/run/stop/remove).

🔧
andrestobelem ↓ 295
extension

pi-herdr-sudo-task

Blocking, user-approved sudo tasks in a dedicated Herdr pane

📁🔧
GitHub Actions ↓ 285
skill

@blackbelt-technology/pi-dashboard-eng-disciplines

Cross-cutting engineering-discipline skills for pi sessions — interview-me, doubt-driven-review, code-simplification, security-hardening, performance-optimization, observability-instrumentation, systematic-debugging, node-inspect-debugger, scenario-design

GitHub Actions ↓ 276
extension

@vtstech/pi-security

Security extension for Pi Coding Agent

🤖📁🔧 +1
vtstech ↓ 273
extension

@false00/pi-elasticsearch

Production-focused Elasticsearch automation tools for the Pi coding agent — curated tools for search, documents, indices, cluster administration, security, lifecycle, and full API reach via the official JS client and raw REST access

🔑📁🔧
false00 ↓ 270
extension

@spences10/pi-confirm-destructive

Git-aware Pi guardrail that asks for confirmation before destructive shell actions can change or lose work

📁
spences10 ↓ 269
promptextension

@false00/cyber-news

Interactive cybersecurity news briefing for the Pi coding agent with live multi-source headlines and deep-dive story prompts

🤖📁🌐
false00 ↓ 256
extension

pi-widget-host

Host package for managing one shared Pi widget slot across multiple providers with preset policies and a built-in demo provider.

📁
GitHub Actions ↓ 239
extension

pi-defender

Defense-in-depth protection for Pi coding agent. Blocks dangerous commands and protects sensitive files — rename of pi-damage-control.

🤖🔑📁 +4
serhioromano ↓ 238
extension

@shelken/pi-guard

Hard-block dangerous agent bash commands and secret path access

📁
GitHub Actions ↓ 238
extension

@guygrigsby/pi-subagent-routing

Inject a subagent model-routing policy: the orchestrator plans and judges on its own live model and fans implementation out to cheaper subagents, reviewing before it accepts.

🤖
guygrigsby ↓ 237
skill

@firstpick/pi-skill-deep-research

Agents should invoke this skill for high-stakes or complex research needing multi-source evidence, scientific/technical fact-checking, decision traces, or rigorous verification. Runs deterministic two-phase research with schema/policy validation.

firstpick ↓ 232
extension

pi-guard

General-purpose permission system for pi tools, handling permissions for bash and file tools with extensible matchers for custom tools.

📡📁
GitHub Actions ↓ 231
skilltool

@blackbelt-technology/pi-dashboard-code-review-toolkit

Code-review workflow skills for pi sessions — code-review (AI-powered review with severity labels via the CodeRabbit CLI) and autofix (safely review and apply CodeRabbit PR review-thread feedback with per-change approval). Pure-skill package, no extension

GitHub Actions ↓ 227
extension

pi-code-tool

Code-mode tool for the pi coding agent: a sandboxed Python meta-tool (via @pydantic/monty) that lets the agent write code against host tools and build ephemeral code tools

📁🌐🔧
josephakern ↓ 224
extension

pi-supersafety

When the example safety extensions don't cover what you need, this should! Simple with approval flow and windows sandbox capability (with Sandboxie)

🤖📁
zenforic ↓ 224
extension

smart-approve

High-risk-only approval hook with LLM risk analysis, behavior detection, protected-path interception, and decision memory for oh-my-pi (OMP) and pi-agent.

📁🛠 +1
mentalfl0w ↓ 224
promptextension

@dougbots/pi-agents

Agent profiles for pi — preconfigured model, system prompt, tool restrictions, and permission gates

🤖📁🔀 +1
sdougbrown ↓ 221
extension

@pandi-coding-agent/pandi-podman

Extensión de Pi para ejecutar sandboxes efímeros y restringidos con Podman mediante /podman y la tool podman_sandbox.

🔧
andrestobelem ↓ 221
extension

@celestoai/pi

Run Pi coding tools in a Celesto computer

🤖🔑📁 +4
GitHub Actions ↓ 219
extension

pi-approval-guardian

A fail-closed-by-default Pi approval gate that reviews shell actions, private data access, and sensitive file mutations with an isolated risk model and explicit temporary bypass.

🤖🔑📁 +1
GitHub Actions ↓ 218
toolextension

pi-opa-net

OPA-backed bash command guard for the pi ecosystem — structured decision-output.v1 JSON, fail-open default, Claude Code hook protocol compatible. Agent-agnostic engine + CLI.

📁🌐
buihongduc132 ↓ 216
extension

pi-ward

File access guard for the pi coding agent — declarative filesystem boundaries.

📁🔧
GitHub Actions ↓ 207
skill

@getpipher/x-api

X/Twitter API v2 reference skill for pi — auth (Bearer / OAuth 1.0a / 2.0), endpoints, pricing, and a mandatory cost guard.

rz1989 ↓ 204
extension

pi-enclave

VM-isolated sandbox for pi with automatic secret protection · from yapp

🤖📁 +2
GitHub Actions ↓ 187
skill

@firstpick/pi-package-skill-lifecycle

Self-contained Pi package for skill lifecycle management: memory, skill-bank audit, evaluation, creation, and refinement tools.

🤖📁🔧 +1
firstpick ↓ 176
extension

@josephyoung/pi-heimdall

Guardian extension for pi — security guards that block accidental secret exposure, enforce command policies, protect .env files, and sandbox bash commands

📁🔧 +1
GitHub Actions ↓ 172
extension

pi-permission-suite

Four approval modes + command-level security restrictions for the Pi coding agent. Act / Auto / Ask / Plan mode switching, rule engine, subagent auto-approval.

🤖📁 +2
eddie0521 ↓ 151
extension

pi-obsidian-vault

Agent-safe Obsidian vault access for Pi: auto-detect, retrieve, validate, plan, write, edit, manage, and explicitly destroy Markdown with human approval.

📁🔧
itscool2b ↓ 148
skillextension

agent-booster-pack

Agent Booster Pack for Pi: skills + Interface Design Gate runtime + proof-first runtime + whiteboarding guard + final value guard, in one install. Meta-package; depends on the four siblings.

🤖📁 +2
kreek ↓ 143
extension

pi-permission-gate

Config-driven permission system for Pi agents. Deny-by-default tool restriction with glob matching, path normalization, self-protection, and structured logging.

🤖📁🔀
juanjeojeda ↓ 143
skillextension

implannotator

Approval-gated frontend implementation for Pi, combining Implannotator design guidance with Plannotator reviews.

🤖📡📁 +3
yoseph_23 ↓ 140
extension

@0xkobold/pi-gateway

Hermes-style messaging gateway for pi - multi-platform agent with sessions, security, and background tasks

🔑📁🌐 +2
moikapy ↓ 136
extension

@xaccefy/pi-exploitsearch

ExploitSearch extension for Pi Agent — query preview.is security corpus for attack techniques, primitives, and bypasses

🔑📁🌐🔧
xaccefy ↓ 134
extension

pi-cwd-guard

Small Pi safety extension for cwd access, protected paths, runtime config confirmation, and common destructive bash commands.

🤖📁
devnazim ↓ 134