Packages

6.2k listings for pi · 0 reviewed by us

🛡 Guards & policy Block or rewrite dangerous tool calls, sandbox commands, enforce permissions.

323 results · page 3 of 7

extension

@zhushanwen/pi-permission

Pi permission extension — four permission modes (yolo/auto/approve/strict) with three-layer pipeline (AST + rules + AI classifier).

📁
zhushanwen321 ↓ 410
extension

pi-code-tool

Code-mode tool for the pi coding agent: a sandboxed Python meta-tool (via @pydantic/monty) that lets the agent write code against host tools and build ephemeral code tools

📁🌐🔧
josephakern ↓ 406
skill

choose-security

Install the Choose-Security 3-skill security chain (review → document → remediate) into Claude Code, pi, and opencode in one command.

📁
beast-course ↓ 399
extension

pi-marketplace

Pi extension for searching, auditing, and installing pi packages from npm — with security review and optional pi.dev enrichment

📁🌐🔧 +1
diwu507 ↓ 395
extension

@daytona/pi

Pi coding agent extension that runs all tool calls inside a remote, ephemeral Daytona sandbox while the agent runs locally

🤖🔑 +2
GitHub Actions ↓ 391
extension

pi-playpen

Global, multi-project OS sandboxing for the pi coding agent

🤖📁 +2
moreheadm ↓ 381
extension

@pi-lab/permissions

Permission system extension for pi coding agent

📁
cheny341 ↓ 377
skill

@bacnh85/pi-ux

Anti-slop UI/UX design discipline for your Pi agent — anchors a lintable DESIGN.md, runs deterministic slop-audit gates (APCA contrast + tokens + states + slop tells), works with text-only models, ships reference design-system presets.

🤖📁🔧 +1
bacnh85 ↓ 373
extension

pi-guard-sandbox

A lightweight OS-level guard for Pi: agents stay useful, sensitive paths stay blocked, and writes stay inside the workspace you allow. No container overhead. No workflow drama.

📁🌐 +2
runminton ↓ 365
promptextension

pi-secure-it

In-process tool guard and subagent posture hardening for Pi coding agent. Enforces filesystem allow/deny lists and domain allowlists on read, write, edit, fetch_content, web_search, and get_search_content — with interactive ask-tier prompts to grant acces

📁🔧 +1
GitHub Actions ↓ 361
extension

@jerryan/pi-sanity

Pi extension for sanity checks on agent operations

📁
jerryan ↓ 361
extension

@ifi/oh-pi-extensions

Core pi extensions: git-guard, auto-session, custom-footer, and more.

🤖📡🔑 +5
ifiokjr ↓ 358
extension

pi-guard

General-purpose permission system for pi tools, handling permissions for bash and file tools with extensible matchers for custom tools.

📡📁
GitHub Actions ↓ 356
extension

pi-permission-gate

Config-driven permission system for Pi agents. Deny-by-default tool restriction with glob matching, path normalization, self-protection, and structured logging.

🤖📁🔀
juanjeojeda ↓ 353
extension

@bytesbrains/pi-agent-supervisor

Runtime safety net for AI agents — blocks dangerous commands, protects files, enforces rate limits, and records sessions.

📁🔧
nandal ↓ 351
skillextension

@haemmid/pi-skill-paths

Canonical SKILL.md path correction and bash skill-access guard for Pi.

📁
haemmid ↓ 351
extension

@aprimediet/permission-modes

A Claude-Code-style **Shift+Tab mode cycle** for the [pi coding agent](https://pi.dev).

🤖📡🔀 +2
aditya.prima ↓ 344
extension

@iota-policy/pi-extension

iota embedded policy engine as a pi coding-agent extension: hash-pinned bless, agents.yaml enforcement for read/write/edit/bash, JSONL decision log

📁
GitHub Actions ↓ 337
extension

@arvoretech/pi-secret-firewall

Redacts secrets (env vars, .env files, token patterns) from the model context and tool outputs, exposing them only as $SECRET_* shell env vars the model can reference but never read

🤖📁
GitHub Actions ↓ 334
extension

@kjrjay/pi-sandbox

Run Pi file and shell tools in an isolated Apple Container or Docker workspace

🤖🔑📁 +4
kjrjay ↓ 327
extension

pi-command-guardian

Deterministic explicit deletion guard for Pi

sunnyx11 ↓ 325
extension

@xicode/pi-permission-system

Prebuilt and audited distribution of the Pi permission system extension

🤖📁 +2
GitHub Actions ↓ 321
extension

pi-streaming-guard

Keep Pi's TUI responsive during long streamed responses with incremental Markdown rendering

monotykamary ↓ 317
extension

@pandi-coding-agent/pandi-podman

Extensión de Pi para ejecutar sandboxes efímeros y restringidos con Podman mediante /podman y la tool podman_sandbox.

🔧
andrestobelem ↓ 306
extension

pi-show-diffs

Pi package that adds a diff approval viewer before edit and write tools change files.

🤖📡📁 +1
xryul ↓ 302
extension

pi-focus-guard

Pi extension that groups discuss, write, and commit guards under focus-prefixed commands.

🤖📁
cgint ↓ 301
toolextension

pi-codex-security

Pi extension for OpenAI Codex Security — scan repositories for vulnerabilities, review findings, and fix them with the pi agent

🤖🔑🔧
davecodes ↓ 299
skill

@barlevalon/release-prep-skill

An Agent Skill for evidence-backed release preparation, changelog drafting, SemVer recommendations, and approval-gated publishing plans.

GitHub Actions ↓ 294
skill

@getpipher/x-api

X/Twitter API v2 reference skill for pi — auth (Bearer / OAuth 1.0a / 2.0), endpoints, pricing, and a mandatory cost guard.

rz1989 ↓ 294
extension

pi-bash-confirm

Pi package for confirming bash commands before execution with Telegram notifications

🔑📁🌐 +1
matteo.collina ↓ 289
extension

pi-dcg

Guard Pi shell commands with Destructive Command Guard.

📁🌐 +1
GitHub Actions ↓ 282
promptextension

@dougbots/pi-agents

Agent profiles for pi — preconfigured model, system prompt, tool restrictions, and permission gates

🤖📁🔀 +1
sdougbrown ↓ 269
extension

@qmxme/pi-git-guard

Blocks destructive git operations (push, tag -d, reset --hard) in pi

GitHub Actions ↓ 265
extension

@guygrigsby/pi-subagent-routing

Inject a subagent model-routing policy: the orchestrator plans and judges on its own live model and fans implementation out to cheaper subagents, reviewing before it accepts.

🤖
guygrigsby ↓ 264
skill

@firstpick/pi-skill-dolt-database-version-control

Use automatically when evaluating or applying Dolt, the Git-like version-controlled SQL database, for database branching, merging, diffs, audit history, rollback, or versioned MySQL replica workflows.

firstpick ↓ 261
extension

@yassimba/pi-guardrails

Editable distribution of Pi Guardrails for local policy customization

🤖📡📁 +3
yassimba ↓ 261
extension

pi-minimal-permission-system

Minimal permission enforcement extension for the Pi coding agent.

📁
GitHub Actions ↓ 256
prompt

@kassing/pi-menu

Interactive menus & input for pi — proactive multi-question tabs, option search filter, single/multi select, typed input (text/secret/number/date/path), configurable emoji

🤖📁🔧
kassing ↓ 254
extension

pi-vscode-sr

Code diff assistant for VS Code.

🤖📁🛠
serhioromano ↓ 247
promptextension

@danypops/pi-profiles

Named profiles for pi: bundle model, thinking level, tools, and system-prompt instructions, with a soft model-allowlist guard for separating contexts like a personal OpenRouter budget from a work Vertex AI project.

🤖📁🔀
danypops ↓ 244
skill

@firstpick/pi-skill-code-security

Agents should invoke this skill for code security reviews, leaked secret checks, dependency risk, unsafe shell/Python/TypeScript/Rust patterns, auth/input-validation flaws, SAST-style audits, or supply-chain concerns in repositories.

firstpick ↓ 238
extension

pi-supersafety

When the example safety extensions don't cover what you need, this should! Simple with approval flow and windows sandbox capability (with Sandboxie)

🤖📁
zenforic ↓ 232
skill

@m4xx101/vibeshack

Autonomous security testing harness for pi-mono. Expert hacker persona, hypothesis-tree REPL, tool auto-install, pipeline chaining, 30+ bug-bounty tools, self-evolving skills. Find vulnerabilities, chain exploits, write PoC reports. Authorized testing onl

🤖📡🔑 +7
m4xx101 ↓ 231
skill

@firstpick/pi-skill-server-audit

Agents should invoke this skill for Linux server security reviews, SSH hardening, firewall/open-port audits, user/permission checks, exposed services, or host hardening requests. Produces severity-rated findings and practical remediation steps.

firstpick ↓ 229
extension

@casualjim/pi-heimdall

Guardian extension for pi — security guards that block accidental secret exposure, enforce command policies, protect .env files, and sandbox bash commands

📁🔧 +1
GitHub Actions ↓ 227
extension

pi-obsidian-vault

Agent-safe Obsidian vault access for Pi: auto-detect, retrieve, validate, plan, write, edit, manage, and explicitly destroy Markdown with human approval.

📁🔧
itscool2b ↓ 224