@casualjim/pi-pstack
Pi-native fork of pstack skills, Poteto Mode, and bundled agents. Delegates through pi-herdr-agents instead of its own subagent tool.
Package details
Install @casualjim/pi-pstack from npm and Pi will load the resources declared by the package manifest.
$ pi install npm:@casualjim/pi-pstack- Package
@casualjim/pi-pstack- Version
0.1.12- Published
- Oct 5, 2026
- Downloads
- 2,153/mo · 590/wk
- Author
- casualjim
- License
- MIT
- Types
- extension, skill
- Size
- 34.9 MB
- Dependencies
- 0 dependencies · 3 peers
Pi manifest JSON
{
"skills": [
"./skills"
],
"extensions": [
"./extensions/pstack"
]
}Security note
Pi packages can execute code and influence agent behavior. Review the source before installing third-party packages.
README
pi-pstack
A pi-mimir fork of pstack. It keeps all upstream skills that are platform-portable (48; make-bot-ui is Cursor-platform-only and setup-pstack configures Cursor's model rule, both excluded), the sticky Poteto Mode, and the bundled poteto-agent and comment-sicko agents — but it delegates through pi-herdr-agents instead of shipping its own subagent tool.
Why this fork exists
Upstream pi-pstack registers a tool named subagent. pi-herdr-agents registers a tool with the same name. Loading both made one shadow the other. This fork drops the subagent tool registration entirely so pi-herdr-agents' subagent is the only one, and pstack's bundled agents become inputs to it.
How delegation works here
pi-herdr-agents resolves roles from bundled, role-pack, global, and project definitions. This extension publishes its bundled agents/ directory as a role pack, registering it on the pi-herdr-subagents:roles:discover:v1 event when the extension loads. The host reads and validates the definitions in place, so nothing is copied into ~/.pi/agent/agents.
After install, check the roles with subagents_list and delegate the pi-herdr-agents way:
subagent({ name: "Fix retry regression", agent: "poteto-agent", task: "investigate and fix the retry regression, then verify it" })
poteto-agent self-instructs to read the bundled poteto-mode skill in full before working, so the behavior upstream got via prompt injection is preserved without this fork injecting anything.
What's included
- 48 skills under
skills/, matching the upstream inventory minus Cursor-onlymake-bot-uiandsetup-pstack(prose adapted where Pi differs). poteto-agentandcomment-sickoagent definitions underagents/, published to pi-herdr-agents as a role pack.- Commands:
/poteto-mode(sticky Poteto Mode for the session). - Tools: none. Task tracking, session recall, and subagent model routing use the host environment (
set_tasksfamily,recall,subagents_write_task_models).
What's removed vs upstream
- The
subagenttool and its child-Pi process runner. Use pi-herdr-agents'subagentinstead. /setup-pstack,pstack_config,pstack_todo,pstack_sessions, and the~/.pi/agent/pstack/models.jsonrole map. The live role-to-model routing is pi-herdr-agents'models.tasks/models.agentsconfig (subagents_write_task_models). Workflow skills consult that config for the per-callmodelthey pass tosubagent. Panel roles take model lists; set those viamodels.agentsper agent ortask:<category>routing.
Safety
The extension requests confirmation for recognizable shell commands that push, alter pull requests, merge, deploy, mutate infrastructure, or recursively delete files. In non-interactive mode it blocks these commands. This is a guardrail, not a complete shell-security sandbox.
To run without approval prompts, set confirmExternalActions to false in the pstack config file: $PI_CODING_AGENT_DIR/pstack/config.json when that env var is set, otherwise ~/.omp/agent/pstack/config.json under omp or ~/.pi/agent/pstack/config.json under pi (same resolution as pi-headroom's settings). Restart the host after a config change. A missing, malformed, or non-boolean config keeps the guard enabled. With the guard disabled, agents are told to run recognized external commands without asking and still pause for irreversible writes (force-pushes to shared branches, deployments, data deletion, customer messages).
License and provenance
Derived from Cursor's pstack, licensed under MIT. See LICENSE.