@iurysza/pi-secret-env
Load shared credentials into Pi while blocking and redacting secret access.
6.2k listings for pi
323 results · page 6 of 7
Load shared credentials into Pi while blocking and redacting secret access.
Sandbox awareness for pi: shows a colored [sandboxed:<profile>] footer and injects sandbox-access context when pi runs inside agent-sandbox (asb), plus an asb-pi shell wrapper that launches pi sandboxed inside tmux.
Review Excel files for spreadsheet errors — mechanical checks (openpyxl) + Panko–Halverson taxonomy reasoning
Named profiles for pi: bundle model, thinking level, tools, and system-prompt instructions, with a soft model-allowlist guard for separating contexts like a personal OpenRouter budget from a work Vertex AI project.
🧠 Persistent memory + 🔍 session search + 🛡️ secret scanning for Pi. Token-aware policy-only memory by default, SQLite FTS5 search, auto-consolidation, procedural skills. 368 tests. Ported from Hermes agent.
Blocks destructive git operations (push, tag -d, reset --hard) in pi
A security middleware for Pi that intercepts and blocks the writing of API keys and secrets to disk.
Install the Choose-Security 3-skill security chain (review → document → remediate) into Claude Code, pi, and opencode in one command.
Free SEO toolkit for Pi — keyword research, difficulty scoring, competitor gap, site audit. Zero dependencies. Upsells to full SEO workflow engine.
Prevents Windows-native Pi file tools from silently writing to mangled paths when agents reuse Git Bash/MSYS paths like /c/Users/...
High-signal security review package for Pi.
Native permission and sandbox extension for pi.
ABP Pi whiteboarding guard plus whiteboarding skill: one user-facing question at a time.
Orchestrated multi-phase development missions for pi — architect, implement, test, audit, verify
Operation safety and secret egress guardrails for Pi
PRD-first SDD stack for Pi Agent with OpenSpec and strict Engram memory policy.
Bash command allowlist system for pi — grouped trust policies with glob matching, recursive parsing, and an interactive TUI manager
Pi extension that confirms before delete/edit operations - protects files from accidental changes
Supervised job runtime extension for pi with isolated workers, audit artifacts, and retry-aware orchestration.
Lightweight regex-based PII mask/unmask extension for Pi coding agent. Redacts emails, phones, SSNs, credit cards, API keys, and more before they reach the LLM. Restores originals in responses.
Claude-style OS-level sandboxing for pi with interactive permission prompts. Coexists with pi-tool-display and other bash-overriding extensions. Forked from carderne/pi-sandbox.
Audit npm dependencies for vulnerabilities, outdated packages, and license compliance — integrated into pi.dev workflow
Bash policy enforcement — provides a bash_readonly tool that blocks mutating commands
Deterministic explicit deletion guard for Pi
Secret detection and pi-share-hf integration for pi-coding-agent. Scans projects, sessions, and environment for secrets, syncs to pi-share-hf workspace, and manages the collection/upload pipeline.
Pi extension that intercepts 'tool not found' errors: injects skill documentation for matching skill names and falls back to bash for unknown tools with a command argument
Pi extension that prevents context bloat by automatically sandboxing heavy tool outputs (bash, web_search, fetch_content, exa_search, read) to temp files
Defense-in-depth protection for Pi coding agent. Blocks dangerous commands and protects sensitive files — fork of Serhioromano/pi-defender with defaultMode support.
Unofficial Pi skill wrapper for React Doctor (by Million.co) — scans React codebases for security, performance, correctness, and architecture issues.
Dynamic full-permission bypass toggle for pi-permission-system with backup/restore of policy files.
Agent-safe control plane for local CLIs in Pi.
Permission enforcement extension for the Pi coding agent
A proper sandbox extension for pi, using the Anthropic Sandbox Runtime
Production readiness validator. Score projects on code, tests, docs, config, deploy. Inspired by MrE's system-validator-100.
Dependency health scanner. Outdated, heavy, licenses, dupes, tree.
Gondolin micro-VM sandbox for clankie — runs agent tools inside an isolated VM with network policies, secret injection, and filesystem isolation
Core pi extensions: safe-guard, git-guard, auto-session, custom-footer, and more.
Security hooks for Pi to reduce accidental destructive actions and secret-file access.
Audited autoskills-style installer for pi. Detect stack, discover vetted skills, audit upstream bundles, cache locally, install safely.
MikroTik RouterOS .rsc auditor — 115 security checks, CVSS scoring, conflict detection, CVE lookup, cross-checks & linting
Pi extension that blocks mistyped or unknown slash commands from being sent as messages.
OS-level sandboxing for pi with interactive permission prompts (fork)
Chez Scheme WASM sandbox for Vera agent — platform-independent Scheme evaluation
Security scanner and runtime protection for Pi Coding Agent
A Pi extension that performs security audits on other extensions before install or update. Uses the currently selected AI model to analyze extension source code against configurable audit rules.
Deterministic tool-call guard for pi: path preflight, schema/repair, content rules, error enrichment, and destructive-bash blocking (interactive confirm + headless subagent hard-block)
Git safety guard: protect branches, scan secrets, prevent mistakes
Load API keys with secret-tool