Packages

6.2k listings for pi · 0 reviewed by us

🛡 Guards & policy Block or rewrite dangerous tool calls, sandbox commands, enforce permissions.

323 results · page 6 of 7

skillextension

agent-booster-pack-contract-first

Interface Design Gate for Pi plus contract-first skill: pause and require human approval of contract/API shape before implementation lands.

🤖
kreek ↓ 86
skill

mikrotik-rsc-auditor

MikroTik RouterOS .rsc auditor — 115 security checks, CVSS scoring, conflict detection, CVE lookup, cross-checks & linting

GitHub Actions ↓ 85
extension

pi-mono-context-guard

Pi extension that guards context window growth by auto-limiting read and rg output

🤖📡📁 +1
emanuelcasco ↓ 85
skillextension

pi-chefs

Long-running expert Pi sessions (chefs) that other agents consult via pi-postman. Persona + skill-allowlist layer on top of pi-postman.

🤖📁 +2
GitHub Actions ↓ 84
skillextension

pi-skill-guard

Pi extension that intercepts 'tool not found' errors: injects skill documentation for matching skill names and falls back to bash for unknown tools with a command argument

📁
tychenjiajun ↓ 84
extension

pi-deepseek-cache

DeepSeek prefix-cache extension for pi — hit-rate telemetry, prefix guard, and cache-friendly compaction.

🤖🔑📁🌐 +2
ruanbw ↓ 83
extension

@capyup/pi-jobs

Supervised job runtime extension for pi with isolated workers, audit artifacts, and retry-aware orchestration.

📁🔧
capyup ↓ 83
extension

@fadouse/pi-permission

Native permission and sandbox extension for pi.

🤖🔑📁 +3
fadouse ↓ 82
extension

@chrischow/pi-lockdown

A Pi extension to add security constraints to agent tool usage.

🔀
chrischow ↓ 82
extension

pi-agent-sandbox

Sandbox awareness for pi: shows a colored [sandboxed:<profile>] footer and injects sandbox-access context when pi runs inside agent-sandbox (asb), plus an asb-pi shell wrapper that launches pi sandboxed inside tmux.

🤖📁
anonx3247 ↓ 80
extension

@davehardy20/pi-safe-tools

Pi safety bundle: safe command runners, damage prevention, and secret redaction.

🤖📁 +2
davehardy20 ↓ 80
extension

@pedro_klein/pi-readonly-bash

Bash policy enforcement — provides a bash_readonly tool that blocks mutating commands

🔧
pedro_klein ↓ 80
extension

@asqav/pi

Asqav extension for the pi coding agent - sign and gate tool calls before they execute

🔑
jagmarques ↓ 78
extension

@jc4649/pi-toolcall-guard

Deterministic tool-call guard for pi: path preflight, schema/repair, content rules, error enrichment, and destructive-bash blocking (interactive confirm + headless subagent hard-block)

🤖📁
jimmyc4649 ↓ 76
skillprompt

@amitkot/pi-permission-tune

Pi skill for maintaining @gotgenes/pi-permission-system config. Covers pattern matching, safe vs dangerous commands, and the prompt-to-rule workflow.

amitkot ↓ 76
extension

pi-shepherd

Line count guard and behavior rules extension for pi-coding-agent

🤖📡📁 +4
lain-residue ↓ 75
extension

pi-path-guard

Pi extension package that normalizes path-like tool arguments and enriches filesystem/edit failures.

📁
conte777 ↓ 73
extension

pi-enclave

VM-isolated sandbox for pi with automatic secret protection · from yapp

🤖📁 +2
GitHub Actions ↓ 71
skillextension

@fbraza/pi-sci-reviewer

Pi extension that runs the scientific-audit skill, parses its verdict, and syncs findings to todos. Bundles the scientific-audit skill.

🤖📁
fbraza ↓ 70
skill

@firstpick/pi-skill-subagent-governance

Portable Agent Skill that governs delegation admissibility for a parent orchestrator, covering zero-or-multiple fanout, the static two-worker minimum, role-fit balance, one-writer isolation, worker handoffs, bounded retry safety, and reviewer finding disp

firstpick ↓ 70
promptextension

@hank-warren/pi-permission-selector

Numbered approval options and Tab-to-comment for Pi's extension select dialogs, including pi-auto-permissions command approval prompts.

🤖
hank-warren ↓ 70
extension

@artale/pi-pentest

Security scanning: nmap wrapper, vulnerability checks

artale ↓ 67
extension

pi-pii-mask

Lightweight regex-based PII mask/unmask extension for Pi coding agent. Redacts emails, phones, SSNs, credit cards, API keys, and more before they reach the LLM. Restores originals in responses.

🤖
alfrancisgabriel ↓ 66
extension

pi-root-grant

Pi extension that lets agents request temporary sudo-backed root access with explicit user approval.

📁🔧
faithless ↓ 65
extension

pi-bash-readonly

Sandboxed read-only bash for Pi agents via bwrap

📁🔧 +1
GitHub Actions ↓ 65
extension

pi-missions

Orchestrated multi-phase development missions for pi — architect, implement, test, audit, verify

🤖📁
itisbryan ↓ 64
extension

pi-getpass

Pi package providing a secure getpass tool for temporary secret environment variables

🔧
yibowei ↓ 64
extension

pi-env-guard

Environment variable validation, secret leak detection, and drift analysis for pi.dev projects

📁🔧
realvendex ↓ 63
promptextension

@rjshrjndrn/pi-sandbox

Filesystem boundary enforcement for pi — prompts before the agent escapes your project

📁
rjshrjndrn ↓ 63
extension

@kky42/pi-sandbox

Pi-compatible sandbox extension for filesystem-aware bash and tool enforcement

📁
kky42 ↓ 62
extension

@4meta5/pi-zsh

Allowlist-only zsh script runner extension for pi coding agents.

📁🔧
4meta5 ↓ 62
skillextension

pi-agent-booster-pack

Agent Booster Pack helps Pi produce code that is well-organized, low in complexity and side effects, and is secure and high-performing.

kreek ↓ 61
extension

@ifiokjr/oh-pi-extensions

Core pi extensions: safe-guard, git-guard, auto-session, custom-footer, and more.

🤖📁 +3
ifiokjr ↓ 61
extension

@clankie/sandbox

Gondolin micro-VM sandbox for clankie — runs agent tools inside an isolated VM with network policies, secret injection, and filesystem isolation

🤖📁🔧 +1
thiagovarela ↓ 60
extension

pi-context-saver

Pi extension that prevents context bloat by automatically sandboxing heavy tool outputs (bash, web_search, fetch_content, exa_search, read) to temp files

📁🔧 +1
hyperspaceng ↓ 59
extension

pi-file-protection

Pi extension that confirms before delete/edit operations - protects files from accidental changes

ruru516 ↓ 59
extension

@artale/pi-infra

Platform engineering audit tool (Kelsey Hightower edition).

📁
artale ↓ 57
extension

@hyperprior/pi-safety

Confirmation and protection layer for dangerous git/bash/edit/write actions

hyperprior ↓ 57
extension

pi-dep-audit

Audit npm dependencies for vulnerabilities, outdated packages, and license compliance — integrated into pi.dev workflow

📁🌐🔧 +1
realvendex ↓ 56
promptextension

pi-boundary

Filesystem boundary enforcement for pi — prompts before the agent escapes your project

📁
rjshrjndrn ↓ 55
extension

@0xkobold/pi-secret-guardian

Secret detection and pi-share-hf integration for pi-coding-agent. Scans projects, sessions, and environment for secrets, syncs to pi-share-hf workspace, and manages the collection/upload pipeline.

🤖📁 +2
moikapy ↓ 54
extension

pi-yolo-bypass

Dynamic full-permission bypass toggle for pi-permission-system with backup/restore of policy files.

📁
skyscribe ↓ 54
skillprompt

@skkac/pilot-inspector

Pilot Inspector — A silent sidecar governance agent for Pi that audits workflow, prompt health, and context hygiene at compaction boundaries. Phase 4: Compaction guard, cross-session trends, auto skill generation.

🤖🔑📁🌐 +1
skkac ↓ 51