Packages

6.2k listings for pi · 0 reviewed by us

🛡 Guards & policy Block or rewrite dangerous tool calls, sandbox commands, enforce permissions.

286 results · page 1 of 6

extension

@yevhen.b/pi-preflight

Tool-call approvals and policy rules for Pi.

🤖🔑📁 +2
yevhen.bobrov ★ 19 ↓ 26
extension

pi-thegreataxios-staples

Personal staple extension for pi coding-agent — protected paths

thegreataxios ★ 13 ↓ 35
extension

@yoseph_23/implannotator

Approval-gated frontend implementation for Pi, combining Implannotator design guidance with Plannotator reviews.

🤖📡📁 +3
yoseph_23 ★ 0 ↓ 309
extension

@akshaykarle/pi-tools

Pi coding agent extensions — security hardening, agent teams and more

🤖📡🔑 +7
akshaykarle ★ 0 ↓ 307
extension

@a5c-ai/babysitter-pi

Orchestrate complex, multi-step workflows with event-sourced state management, hook-based extensibility, and human-in-the-loop approval — pi

🤖📡📁
tmuskal ↓ 10.0k
toolextension

cc-safety-net

A coding agent CLI hook - block destructive git and filesystem commands before execution

🤖📁 +1
GitHub Actions ↓ 8.7k
extension

betterwright

A persistent, policy-guarded Playwright browser for AI agents with network controls, trusted credential filling, proof screenshots, and CAPTCHA helpers.

🤖🔑📁 +4
GitHub Actions ↓ 7.0k
promptextension

pi-sandbox

OS-level sandboxing for pi with interactive permission prompts

📡📁 +2
GitHub Actions ↓ 5.8k
extension

@xaccefy/pi-casefile

Offensive security case tracker for Pi Agent — bug bounties, CTFs, security audits

🤖📁 +2
xaccefy ↓ 5.7k
extension

@xaccefy/pi-exploitsearch

ExploitSearch extension for Pi Agent — query preview.is security corpus for attack techniques, primitives, and bypasses

🔑📁🌐🔧
xaccefy ↓ 4.2k
extension

@aliou/pi-guardrails

![banner](https://assets.aliou.me/github/aliou/pi-guardrails/banner.png)

🤖📡📁 +2
GitHub Actions ↓ 4.0k
extension

@agentapprove/pi

Agent Approve extension for Pi - approve or deny AI agent tool calls from your iPhone and Apple Watch

🤖🔑📁 +2
jbeno ↓ 3.7k
extension

@amaster.ai/pi-security

Pi extension for resource-aware security policy engine and tool authorization

📁
2betop ↓ 2.9k
extension

@johanthoren/jeff

Jeff is a model-native quality control plane and cooperative workflow protocol for trusted operators and friendly agents, not a security sandbox.

🔑📁🔧 +1
GitHub Actions ↓ 2.9k
skillextension

@ory/pi

Ory plugin for Pi (the minimal coding agent): scaffolding skills, a local Ory instance, and authentication, authorization, and audit for every tool call

📁
GitHub Actions ↓ 2.5k
extension

@agwab/pi-subagent

Minimal subagent runtime for Pi.

🤖📁🔧 +1
GitHub Actions ↓ 2.3k
extension

pi-permission-system

Permission enforcement extension for the Pi coding agent.

🤖📡🔑📁 +3
masurii ↓ 2.1k
extension

@thurstonsand/pi-permissions

Pi extension package for user, project, and package-level tool permission hooks

📡📁 +1
GitHub Actions ↓ 2.0k
extension

pi-defender

Defense-in-depth protection for Pi coding agent. Blocks dangerous commands and protects sensitive files — rename of pi-damage-control.

🤖🔑📁 +4
serhioromano ↓ 2.0k
extension

@xynogen/pix-gate

Pi extension — permission gate for dangerous bash commands (confirm/block with TUI dialog)

GitHub Actions ↓ 1.8k
extension

@pandi-coding-agent/pandi-container

Extensión de Pi para administrar sandboxes de Apple `container` (micro-VMs Linux): un comando /container y una herramienta container_sandbox invocable por el modelo (status/list/create/run/stop/remove).

🔧
andrestobelem ↓ 1.8k
extension

pi-perm

Config-driven Pi sandbox and permission extension using sandbox-runtime.

📁🔧 +1
dcrcold ↓ 1.7k
promptextension

picodesandbox

OS-level sandboxing for pi with interactive permission prompts

📁🔧 +1
tomasko ↓ 1.6k
extension

pi-approval-guardian

A fail-closed-by-default Pi approval gate that reviews shell actions, private data access, and sensitive file mutations with an isolated risk model and explicit temporary bypass.

🤖🔑📁 +1
GitHub Actions ↓ 1.4k
extension

@xaccefy/pi-engage

Authenticated-session manager for Pi Agent — store and resolve cookie, OAuth client-credentials, and mTLS auth for authorized pentest targets

🔑📁🌐 +2
xaccefy ↓ 1.3k
extension

@ramtinj95/pi-infra-command-guard

Approval guard for risky infrastructure, cloud, container, repository, secret, and local file commands in Pi and GPT-5.6 Code Mode

🤖📁 +2
ramtinj95 ↓ 1.3k
extension

@agentoom/pi-reviewer

Post-task multi-area code review extension for pi — 7 specialised review areas (general, security, code quality, UI/UX, testing, performance, scope) with a checkbox picker UI

🔑📁🌐
agentoom ↓ 1.3k
toolextension

pi-opa-net

OPA-backed bash command guard for the pi ecosystem — structured decision-output.v1 JSON, fail-open default, Claude Code hook protocol compatible. Agent-agnostic engine + CLI.

📁🌐
buihongduc132 ↓ 1.3k
extension

@spences10/pi-redact

Tool-output redaction for Pi that replaces likely secrets before they reach the model context

spences10 ↓ 1.2k
extension

@josephyoung/pi-heimdall

Guardian extension for pi — security guards that block accidental secret exposure, enforce command policies, protect .env files, and sandbox bash commands

📁🔧 +1
GitHub Actions ↓ 1.2k
toolextension

@bacnh85/pi-windows-tools

Pi extension for Windows-native tool manipulation — shell profiles, path conversion, command execution, WSL bridge, safety policy, and developer tool discovery.

🤖📁🔧 +1
bacnh85 ↓ 1.1k
extension

@senad-d/guardme

Deny-first Pi guardrails that keep LLM shell and file access safe, transparent, and user-approved.

🤖📁
GitHub Actions ↓ 1.1k
extension

@spences10/pi-confirm-destructive

Git-aware Pi guardrail that asks for confirmation before destructive shell actions can change or lose work

📁
spences10 ↓ 1.0k
extension

@monotykamary/pi-localterm

localterm <-> pi integration: Kitty graphics for the browser renderer, scrubbing localterm-managed secret env vars from the agent's bash-tool children, and OSC 9 desktop notifications when the agent finishes a long turn.

📡📁🔧
monotykamary ↓ 1.0k
extension

@erichll/pi-sandbox

Sandbox Runtime-backed Linux and macOS sandbox with pi-auto-review approval

📁🌐 +3
erichll ↓ 995
skillextension

pi-permission-modes

Declarative, user-definable permission modes for the pi coding agent: OS-level sandboxing (bubblewrap / sandbox-exec), an allow/ask/deny policy engine, real bash AST gating (tree-sitter), tool hiding, and skill/custom-tool gating.

🤖📁 +3
wynainfo ↓ 943
toolextension

decorated-pi

decorated-pi is a practical enhancement pack for pi coding agent — token-efficient workflow, cache-friendly design, and smarter tools.

🤖🔑📁 +5
weckerrr ↓ 902
promptextension

@diegopetrucci/pi-permission-gate

A pi extension that prompts before dangerous bash commands and protected file writes.

diegopetrucci ↓ 883
extension

@shelken/pi-guard

Hard-block dangerous agent bash commands and secret path access

📁
GitHub Actions ↓ 872
extension

@minhduydev/pi-learning

Append-only project-local learning ledger for Pi with two separate trust gates: manual human approval, and a bounded auto-safe machine gate that is on by default in Pi-trusted projects. Selective fork of Matt Devy's pi-continuous-learning.

🤖📡📁
minhduydev ↓ 868
promptextension

@diegopetrucci/pi-dirty-repo-guard

A pi extension that prompts before session changes when the current git repo has uncommitted changes.

diegopetrucci ↓ 854
extension

smart-approve

High-risk-only approval hook with LLM risk analysis, behavior detection, protected-path interception, and decision memory for oh-my-pi (OMP) and pi-agent.

📁🛠 +1
mentalfl0w ↓ 848
extension

pi-wayfinder-guard

Pi extension enforcing no-implementation during wayfinder (fog mode), with a parallel four-axis code review.

🤖📁 +2
tianhai ↓ 840
extension

@pi-unipi/compactor

Context engine for Pi — zero-LLM compaction, session continuity, sandbox execution, and tool display optimization

🤖📁 +2
neuron-mr-white ↓ 815
promptextension

@agentoom/pi-spending-guard

Track LLM spending per task and pause when a configurable threshold is reached — continue, refine the prompt, or stop. Pi extension by agentoom.com.

🤖📁
agentoom ↓ 807