@derogab/pi-auto-mode

Checks Bash commands before execution

Packages

Package details

extension

Install @derogab/pi-auto-mode from npm and Pi will load the resources declared by the package manifest.

$ pi install npm:@derogab/pi-auto-mode
Package
@derogab/pi-auto-mode
Version
0.5.1
Published
Oct 2, 2026
Downloads
157/mo · 52/wk
Author
derogab
License
unknown
Types
extension
Size
51.9 KB
Dependencies
1 dependency · 1 peer
Pi manifest JSON
{
  "extensions": [
    "./extensions/auto-mode.ts"
  ]
}

Security note

Pi packages can execute code and influence agent behavior. Review the source before installing third-party packages.

README

auto-mode

A Pi plugin that adds an optional safety check to Pi's built-in bash tool using explicit policy rules and a local classifier for commands not covered by those rules.

WARNING: this plugin is under active development and must be considered alpha software. Use it with caution.

Install

pi install npm:@derogab/pi-auto-mode

To use a classifier model, install the unified llama CLI and make it available on your PATH. Auto-mode starts and maintains llama serve in the background on an available local port while enabled with a model selected, downloading the selected model to the Hugging Face cache when needed. Concurrent Pi instances share one server per model, keeping a single copy of it in memory; the server stops once the last of those instances stops using it.

Controls

Run /auto-mode to manage the plugin settings.

Configure

Create auto-mode.json in either or both locations:

  • Pi's user agent directory, normally ~/.pi/agent/auto-mode.json
  • The trusted project's .pi/auto-mode.json
{
  "allow": [
    "^git status$",
    "^git diff$",
    "^npm test$",
    "^npm run (lint|build)$"
  ],
  "ask": [
    "^git commit(?:\\s|$)",
    "^git push(?:\\s|$)",
    "^npm publish(?:\\s|$)"
  ],
  "deny": [
    "^git push(?=\\s|$)(?=[\\s\\S]*\\s(?:-[a-zA-Z]*f[a-zA-Z]*|--force(?:-with-lease)?(?:=\\S+)?)(?:\\s|$))",
    "(^|\\s)(sudo|doas)(\\s|$)",
    "\\brm\\b(?=[\\s\\S]*\\s(?:-[a-zA-Z]*[rR][a-zA-Z]*|--(?:r|re|rec|recu|recur|recurs|recursi|recursiv|recursive))(?:\\s|$))(?=[\\s\\S]*\\s(?:-[a-zA-Z]*f[a-zA-Z]*|--(?:f|fo|for|forc|force))(?:\\s|$))"
  ]
}

Rules are checked in order: deny, ask, allow, then the classifier. With No model selected, unmatched commands require confirmation instead; they are blocked when confirmation is unavailable or declined. Each rule is a case-sensitive JavaScript regular expression matched as written against the command. Rules from both files are combined. Missing files are ignored; invalid files block commands.

Auto-mode is not a sandbox or a guarantee of safety.

The classifier uses the 0.8B, 2B, 4B, or 9B SingGuard-NSFA model by the SingGuard Team at Ant Group's AI Security Lab, released under the Apache 2.0 license.