@yevhen.b/pi-preflight
Tool-call approvals and policy rules for Pi.
6.2k listings for pi · 0 reviewed by us
286 results · page 1 of 6
Tool-call approvals and policy rules for Pi.
Personal staple extension for pi coding-agent — protected paths
Approval-gated frontend implementation for Pi, combining Implannotator design guidance with Plannotator reviews.
Pi coding agent extensions — security hardening, agent teams and more
Orchestrate complex, multi-step workflows with event-sourced state management, hook-based extensibility, and human-in-the-loop approval — pi
A coding agent CLI hook - block destructive git and filesystem commands before execution
A persistent, policy-guarded Playwright browser for AI agents with network controls, trusted credential filling, proof screenshots, and CAPTCHA helpers.
OS-level sandboxing for pi with interactive permission prompts
Offensive security case tracker for Pi Agent — bug bounties, CTFs, security audits
ExploitSearch extension for Pi Agent — query preview.is security corpus for attack techniques, primitives, and bypasses

Agent Approve extension for Pi - approve or deny AI agent tool calls from your iPhone and Apple Watch
Pi extension for resource-aware security policy engine and tool authorization
Jeff is a model-native quality control plane and cooperative workflow protocol for trusted operators and friendly agents, not a security sandbox.
Interactive guardrails for dangerous bash commands and protected file edits in Pi.
Ory plugin for Pi (the minimal coding agent): scaffolding skills, a local Ory instance, and authentication, authorization, and audit for every tool call
Minimal subagent runtime for Pi.
Permission enforcement extension for the Pi coding agent.
Pi extension package for user, project, and package-level tool permission hooks
Defense-in-depth protection for Pi coding agent. Blocks dangerous commands and protects sensitive files — rename of pi-damage-control.
Permission enforcement extension for Pi/OMP
Pi extension — permission gate for dangerous bash commands (confirm/block with TUI dialog)
Extensión de Pi para administrar sandboxes de Apple `container` (micro-VMs Linux): un comando /container y una herramienta container_sandbox invocable por el modelo (status/list/create/run/stop/remove).
Config-driven Pi sandbox and permission extension using sandbox-runtime.
OS-level sandboxing for pi with interactive permission prompts
A fail-closed-by-default Pi approval gate that reviews shell actions, private data access, and sensitive file mutations with an isolated risk model and explicit temporary bypass.
Authenticated-session manager for Pi Agent — store and resolve cookie, OAuth client-credentials, and mTLS auth for authorized pentest targets
Approval guard for risky infrastructure, cloud, container, repository, secret, and local file commands in Pi and GPT-5.6 Code Mode
Post-task multi-area code review extension for pi — 7 specialised review areas (general, security, code quality, UI/UX, testing, performance, scope) with a checkbox picker UI
OPA-backed bash command guard for the pi ecosystem — structured decision-output.v1 JSON, fail-open default, Claude Code hook protocol compatible. Agent-agnostic engine + CLI.
Tool-output redaction for Pi that replaces likely secrets before they reach the model context
Guardian extension for pi — security guards that block accidental secret exposure, enforce command policies, protect .env files, and sandbox bash commands
Pi extension for Windows-native tool manipulation — shell profiles, path conversion, command execution, WSL bridge, safety policy, and developer tool discovery.
Deny-first Pi guardrails that keep LLM shell and file access safe, transparent, and user-approved.
Deny-first typo-path model judge — a pi-permission-system Authorizer chain link
Git-aware Pi guardrail that asks for confirmation before destructive shell actions can change or lose work
localterm <-> pi integration: Kitty graphics for the browser renderer, scrubbing localterm-managed secret env vars from the agent's bash-tool children, and OSC 9 desktop notifications when the agent finishes a long turn.
Sandbox Runtime-backed Linux and macOS sandbox with pi-auto-review approval
Declarative, user-definable permission modes for the pi coding agent: OS-level sandboxing (bubblewrap / sandbox-exec), an allow/ask/deny policy engine, real bash AST gating (tree-sitter), tool hiding, and skill/custom-tool gating.
decorated-pi is a practical enhancement pack for pi coding agent — token-efficient workflow, cache-friendly design, and smarter tools.
A pi extension that prompts before dangerous bash commands and protected file writes.
Hard-block dangerous agent bash commands and secret path access
Append-only project-local learning ledger for Pi with two separate trust gates: manual human approval, and a bounded auto-safe machine gate that is on by default in Pi-trusted projects. Selective fork of Matt Devy's pi-continuous-learning.
A pi extension that prompts before session changes when the current git repo has uncommitted changes.
High-risk-only approval hook with LLM risk analysis, behavior detection, protected-path interception, and decision memory for oh-my-pi (OMP) and pi-agent.
Pi extension enforcing no-implementation during wayfinder (fog mode), with a parallel four-axis code review.
Context engine for Pi — zero-LLM compaction, session continuity, sandbox execution, and tool display optimization
Track LLM spending per task and pause when a configurable threshold is reached — continue, refine the prompt, or stop. Pi extension by agentoom.com.