@zhushanwen/pi-permission
Pi permission extension — four permission modes (yolo/auto/approve/strict) with three-layer pipeline (AST + rules + AI classifier).
6.2k listings for pi · 0 reviewed by us
323 results · page 3 of 7
Pi permission extension — four permission modes (yolo/auto/approve/strict) with three-layer pipeline (AST + rules + AI classifier).
Code-mode tool for the pi coding agent: a sandboxed Python meta-tool (via @pydantic/monty) that lets the agent write code against host tools and build ephemeral code tools
Install the Choose-Security 3-skill security chain (review → document → remediate) into Claude Code, pi, and opencode in one command.
Pi extension for searching, auditing, and installing pi packages from npm — with security review and optional pi.dev enrichment
Pi coding agent extension that runs all tool calls inside a remote, ephemeral Daytona sandbox while the agent runs locally
Global, multi-project OS sandboxing for the pi coding agent
Permission system extension for pi coding agent
Anti-slop UI/UX design discipline for your Pi agent — anchors a lintable DESIGN.md, runs deterministic slop-audit gates (APCA contrast + tokens + states + slop tells), works with text-only models, ships reference design-system presets.
A lightweight OS-level guard for Pi: agents stay useful, sensitive paths stay blocked, and writes stay inside the workspace you allow. No container overhead. No workflow drama.
In-process tool guard and subagent posture hardening for Pi coding agent. Enforces filesystem allow/deny lists and domain allowlists on read, write, edit, fetch_content, web_search, and get_search_content — with interactive ask-tier prompts to grant acces
Pi extension for sanity checks on agent operations
Core pi extensions: git-guard, auto-session, custom-footer, and more.
General-purpose permission system for pi tools, handling permissions for bash and file tools with extensible matchers for custom tools.
Config-driven permission system for Pi agents. Deny-by-default tool restriction with glob matching, path normalization, self-protection, and structured logging.
Runtime safety net for AI agents — blocks dangerous commands, protects files, enforces rate limits, and records sessions.
Canonical SKILL.md path correction and bash skill-access guard for Pi.
A Claude-Code-style **Shift+Tab mode cycle** for the [pi coding agent](https://pi.dev).
iota embedded policy engine as a pi coding-agent extension: hash-pinned bless, agents.yaml enforcement for read/write/edit/bash, JSONL decision log
Redacts secrets (env vars, .env files, token patterns) from the model context and tool outputs, exposing them only as $SECRET_* shell env vars the model can reference but never read
Run Pi file and shell tools in an isolated Apple Container or Docker workspace
Deterministic explicit deletion guard for Pi
Prebuilt and audited distribution of the Pi permission system extension
Keep Pi's TUI responsive during long streamed responses with incremental Markdown rendering
Extensión de Pi para ejecutar sandboxes efímeros y restringidos con Podman mediante /podman y la tool podman_sandbox.
Pi package that adds a diff approval viewer before edit and write tools change files.
Pi extension that groups discuss, write, and commit guards under focus-prefixed commands.
Pi extension for OpenAI Codex Security — scan repositories for vulnerabilities, review findings, and fix them with the pi agent
An Agent Skill for evidence-backed release preparation, changelog drafting, SemVer recommendations, and approval-gated publishing plans.
X/Twitter API v2 reference skill for pi — auth (Bearer / OAuth 1.0a / 2.0), endpoints, pricing, and a mandatory cost guard.
Pi package for confirming bash commands before execution with Telegram notifications
Permission enforcement extension for the Pi coding agent.
Guard Pi shell commands with Destructive Command Guard.
Agent profiles for pi — preconfigured model, system prompt, tool restrictions, and permission gates
Blocks destructive git operations (push, tag -d, reset --hard) in pi
Inject a subagent model-routing policy: the orchestrator plans and judges on its own live model and fans implementation out to cheaper subagents, reviewing before it accepts.
Use automatically when evaluating or applying Dolt, the Git-like version-controlled SQL database, for database branching, merging, diffs, audit history, rollback, or versioned MySQL replica workflows.
Editable distribution of Pi Guardrails for local policy customization
Minimal permission enforcement extension for the Pi coding agent.
Interactive menus & input for pi — proactive multi-question tabs, option search filter, single/multi select, typed input (text/secret/number/date/path), configurable emoji
Code diff assistant for VS Code.
Named profiles for pi: bundle model, thinking level, tools, and system-prompt instructions, with a soft model-allowlist guard for separating contexts like a personal OpenRouter budget from a work Vertex AI project.
Agents should invoke this skill for code security reviews, leaked secret checks, dependency risk, unsafe shell/Python/TypeScript/Rust patterns, auth/input-validation flaws, SAST-style audits, or supply-chain concerns in repositories.
When the example safety extensions don't cover what you need, this should! Simple with approval flow and windows sandbox capability (with Sandboxie)
Autonomous security testing harness for pi-mono. Expert hacker persona, hypothesis-tree REPL, tool auto-install, pipeline chaining, 30+ bug-bounty tools, self-evolving skills. Find vulnerabilities, chain exploits, write PoC reports. Authorized testing onl
Agents should invoke this skill for Linux server security reviews, SSH hardening, firewall/open-port audits, user/permission checks, exposed services, or host hardening requests. Produces severity-rated findings and practical remediation steps.
Guardian extension for pi — security guards that block accidental secret exposure, enforce command policies, protect .env files, and sandbox bash commands
Unconditionally blocks destructive bash commands before execution. A pi extension that guards against rm, git reset --hard, docker rm, aws delete operations, and more.
Agent-safe Obsidian vault access for Pi: auto-detect, retrieve, validate, plan, write, edit, manage, and explicitly destroy Markdown with human approval.