Packages

6.2k listings for pi · 0 reviewed by us

🛡 Guards & policy Block or rewrite dangerous tool calls, sandbox commands, enforce permissions.

323 results · page 4 of 7

extension

@nightona-co/pi

Pi coding agent extension that runs all tool calls inside a remote, ephemeral Nightona sandbox while the agent runs locally

🤖🔑 +2
amaraa0404 ↓ 223
extension

pi-permission-layers

Pi extension to handle permissions using a layered approach

📁
gsanhueza ↓ 223
extension

pi-gondolin-mount

pi extension that sandboxes LLM coding agents inside a Gondolin micro-VM with configurable additional mounts

🤖📁🔧 +1
abobco ↓ 223
extension

@nilskluewer/pi-permission-gate

Confirm or block dangerous bash commands before the Pi coding agent executes them.

🔑
nilskluewer ↓ 223
extension

@eggmasonvalue/pi-subagent

Observable, steerable, isolated-context subagents for pi — resume any child mid-task, flush partial results on interrupt/timeout, lean machine-facing envelope, optional model allowlist.

📁🔧
eggmasonvalue ↓ 222
extension

@0xkobold/pi-gateway

Hermes-style messaging gateway for pi - multi-platform agent with sessions, security, and background tasks

🔑📁🌐 +2
moikapy ↓ 222
skillextension

agent-booster-pack

Agent Booster Pack for Pi: skills + Interface Design Gate runtime + proof-first runtime + whiteboarding guard + final value guard, in one install. Meta-package; depends on the four siblings.

🤖📁 +2
kreek ↓ 216
extension

pi-container-sandbox

pi coding-agent extension that runs every read/write/edit/bash op inside a per-session Linux container (Apple `container` or Docker).

🤖📁 +2
thegreataxios ↓ 214
extension

@0xkobold/pi-whitelist

Tri-state tool permission system (allow/deny/ask) for AI agent tool invocations

📁
moikapy ↓ 211
extension

@dihak/pix-gate

Pi extension — permission gate for dangerous bash commands (confirm/block with TUI dialog)

dihak ↓ 210
extension

@the-forge-flow/security-harness-pi

Security harness for the PI coding agent — forbids dangerous commands and gates sensitive ones behind user approval

📁
the-forge-flow-ai ↓ 198
skillextension

agent-booster-pack-skills

General Agent Booster Pack skills for Pi: data, security, debugging, refactoring, and more. Runtime-owned skills ship with their matching extension packages. Renamed from pi-agent-booster-pack; old name deprecated.

kreek ↓ 193
skill

@barlevalon/documentation-system-skill

Apply Divio's four-quadrant documentation system to write, audit, classify, restructure, and review technical documentation. Use when creating or improving tutorials, how-to guides, reference docs, explanations, docs...

GitHub Actions ↓ 192
extension

@ramarivera/pi-model-guardrails

Deterministic destructive-command guard + inviolable-constraint policy engine and deviation state machine for the Pi coding agent

🤖🔑📁 +2
GitHub Actions ↓ 189
extension

@nklisch/pi-enhanced

Pi, enhanced — one install for nklisch's full harness: policy-gated command review, plugin marketplace, subagents, background tasks, research tools, search, model modes, and a curated UX set.

🤖📡🔑 +8
GitHub Actions ↓ 188
toolextension

@boozedog/pi-codemode

Pi Codemode plugin - TypeScript code execution with sandboxed tools, just-bash shell, and MCP integration

🤖🔑📁 +3
boozedog ↓ 187
skill

pi-react-doctor

Unofficial Pi skill wrapper for React Doctor (by Million.co) — scans React codebases for security, performance, correctness, and architecture issues.

im-nick ↓ 184
promptextension

@piotr-oles/pi-bash-timeout

Pi Agent extension: inject a default bash timeout and append timeout policy guidance to the system prompt

🤖
piotr-oles ↓ 183
extension

@nqbao/pi-sandbox

OS-level sandbox for pi coding agent — macOS sandbox-exec / Linux bubblewrap kernel-enforced isolation

📁🔧 +1
nqbao ↓ 182
extension

@aslamplr/pi-safe-shell

Protect your production assets from dangerous bash commands. Default no-bash mode with user approval gates and whitelist support.

🤖📡📁 +3
GitHub Actions ↓ 181
extension

@grwnd/pi-governance

Governance, RBAC, audit, and HITL for Pi-based coding agents

📁🌐 +1
dt-grwnd ↓ 177
extension

pi-sdd-stack

PRD-first SDD stack for Pi Agent with OpenSpec and strict Engram memory policy.

🤖📁 +2
pablognu ↓ 177
skill

@blackbelt-technology/pi-dashboard-eng-disciplines

Cross-cutting engineering-discipline skills for pi sessions — interview-me, doubt-driven-review, code-simplification, security-hardening, performance-optimization, observability-instrumentation, systematic-debugging, node-inspect-debugger, scenario-design

GitHub Actions ↓ 173
skillextension

implannotator

Approval-gated frontend implementation for Pi, combining Implannotator design guidance with Plannotator reviews.

🤖📡📁 +3
yoseph_23 ↓ 173
extension

pi-mono-sentinel

Pi extension that guards against content-based secret leaks and indirect script execution

📡📁
emanuelcasco ↓ 173
extension

zens-ink-seo

Free SEO toolkit for Pi — keyword research, difficulty scoring, competitor gap, site audit. Zero dependencies. Upsells to full SEO workflow engine.

respectevery01 ↓ 172
extension

@vtstech/pi-security

Security extension for Pi Coding Agent

🤖📁🔧 +1
vtstech ↓ 172
extension

@dr4x14913/pi-python-sandbox

Pi extension that adds a safe readonly python sandbox in the currrent directory

🔧
dr4x14913 ↓ 170
skillextension

@awsljx/pi-hermes-memory

🧠 Persistent memory + 🔍 session search + 🛡️ secret scanning for Pi. Token-aware policy-only memory by default, SQLite FTS5 search, auto-consolidation, procedural skills. 368 tests. Ported from Hermes agent.

🤖📁🔧 +1
awsljx ↓ 168
skilltool

pi-secrets-guard

Block secrets and PII before they land: regex + entropy scanning for files, diffs, and AI coding agents. CLI, MCP server, Claude/Cursor skill, and pi extension.

📁
vaibhav290797 ↓ 168
toolextension

@m4riok/pi-ide-bridge

Pi extension for VS Code diff approval workflows and editor context bridging.

🤖🔑📁 +4
m4riok ↓ 167
extension

pi-switch-model

Free-form, LLM-driven model switching for Pi — resolve a free-text model reference and switch mid-conversation, no approval loop, no auto-restore

🔧
timzolleis ↓ 166
extension

pi-quick-perms

Permission enforcement and quick policy commands for the Pi coding agent.

🤖📁 +2
GitHub Actions ↓ 164
extension

pi-tool-wal

Write-ahead log for Pi tool calls: record intent before execution, reconcile results after, persist to SQLite for audit and crash recovery

📁
boyuruan ↓ 164
toolextension

pi-sandbox-proxy

pi coding-agent extension that intercepts network operations with approval flows, vulnerability scanning, and supply chain security enforcement.

🤖📁🌐 +1
thegreataxios ↓ 159
extension

@self-deprecated/pi-agent-tick

Agent Tick control-plane integration for Pi: remote decisions, approvals, and session status updates

📡🔑📁 +3
jeprecated ↓ 158
skillprompt

@odradekk/vera-session-tools

Session lifecycle tools for Vera agent (ask-user, todo, check-vera, output-guard, compaction, prompt-rules, read-cap, conditional-rules, system-env, skill-catalog, time, notify-sound)

🤖🔑📁 +6
odradekk ↓ 150
extension

pi-thinking-only-guard

Auto-recover trapped tool calls from thinking blocks for Qwen3.6 and similar models

🤖
reluxa ↓ 148
extension

executor-pi

`executor-pi` is a first-class Pi extension for running Executor from inside Pi with native approval, elicitation, rendering, and project-aware Executor configuration.

📁🔧
aryasaatvik ↓ 147
extension

pi-posher

Helps clankers keep code prim and proper with linters, formatters and security tools

🤖📁 +2
jeffphil ↓ 147
toolextension

pi-casefile

Offensive security case tracker for pi and Codex — bug bounties, CTFs, security audits

🤖📁 +2
xaccefy ↓ 147
extension

pi-grok-build-acp

Use the official Grok Build ACP agent from Pi with interactive permission bridging.

🤖🔑📁 +1
am518 ↓ 143
skill

@getpipher/quality

Code quality skills for pi — linting/fixing, TypeScript strict checks, production-readiness audit, multi-persona QA, and a brutal pre-prod code roast.

rz1989 ↓ 142
extension

pi-autonomy-profiles

Standalone Auto Mode commands, permission modes, and guardrails for Pi

📁
hafiezul ↓ 142
extension

@baryonlabs/pi-dynamic-workflows

Claude-Code-style dynamic workflow orchestration for Pi (Baryon fork: crash-safe script errors + guarded sandbox).

🔀🔧
martinhong ↓ 135
extension

pi-permissions

Configurable allow/deny permission rules for pi tool calls — control which bash commands, file reads, writes, and edits the agent can perform.

📁
GitHub Actions ↓ 134