@diegopetrucci/pi-permission-gate
A pi extension that prompts before dangerous shell commands and protected file writes.
Package details
Install @diegopetrucci/pi-permission-gate from npm and Pi will load the resources declared by the package manifest.
$ pi install npm:@diegopetrucci/pi-permission-gate- Package
@diegopetrucci/pi-permission-gate- Version
0.1.16- Published
- Oct 7, 2026
- Downloads
- 355/mo · 223/wk
- Author
- diegopetrucci
- License
- MIT
- Types
- extension
- Size
- 59.4 KB
- Dependencies
- 0 dependencies · 1 peer
Pi manifest JSON
{
"extensions": [
"index.ts"
]
}Security note
Pi packages can execute code and influence agent behavior. Review the source before installing third-party packages.
README
permission-gate
A small pi extension that prompts for confirmation before running potentially dangerous bash or PowerShell commands or writing to protected paths.
This started from the original permission-gate.ts example in earendil-works/pi and adds conservative shell and path hardening.
What it checks
rm -rf- PowerShell
Remove-Item -Recurse -Forceand its standard aliases, including module-qualified, interpolated, splatted, and backtick-escaped forms sudochmod/chownwith777- direct
write/editcalls touching normalized protected paths:- exact
.gitpath segments - exact
node_modulespath segments - secret-bearing
.envfiles such as.envand.env.production
- exact
Safe .env templates/examples such as .env.example and .env.production.template are allowed.
If pi is running without an interactive UI, it blocks matching commands and protected path writes by default.
For Pi's built-in local Windows PowerShell tool, commands that pass the fast lexical checks are also parsed with the same PowerShell installation's AST parser before execution. Malformed input, parser failures, Remove-Item parameter splatting, command-resolution changes (aliases/modules/providers/direct function or filter definitions), known script/process/job/member invocation wrappers, computed member calls, and analyzer inputs above 16,000 UTF-8 bytes are treated conservatively and require confirmation (or are blocked when no UI is available). Computed targets passed to provider-capable mutation commands also require confirmation because the target could resolve to Alias: or Function:. Literal quoted/commented examples, including literal here-strings, stay benign. Definitely enabled -WhatIf removals (-WhatIf, -WhatIf:$true, or -WhatIf:1) remain non-destructive and are allowed; computed switch values require confirmation.
Non-Windows and custom/remote powershell tools receive the conservative lexical checks, but only Pi's built-in local Windows tool can be verified with its actual parser. Pi extensions are trusted code: tool overrides, remote operations, spawn hooks, and mutations made by handlers loaded after this gate are outside its boundary and must enforce their own final-input policy.
This is a targeted confirmation guard for the command classes listed above, not a shell sandbox or a proof that every unlisted executable/API is harmless.
Pi 0.99 dispatch boundary
The policy is deliberately named-tool-only: it checks bash, powershell, write, and edit tool_call events. Pi 0.99 routes ctx.executeTool() calls (including calls made by codemode) through the same preflight tool-call pipeline and supplies parentToolCallId; the named checks therefore apply to nested calls too. Executed calls (including execution errors and isError results) reach the tool-result hook. Preflight-blocked, invalid, and unknown-tool calls instead produce Pi's host error result and, for nested calls, a bounded nested-call record without an after-execution tool_result event. Confirmation cancellation, UI failure, and missing UI fail closed.
MCP calls also pass through Pi's host pipeline, but arbitrary mcp__<server>__<tool> names are outside this extension's existing guarantee. This extension does not authorize arbitrary MCP tools, infer policy from readOnlyHint/destructiveHint annotations, or provide a universal MCP security sandbox. Any annotation-based or broader MCP policy requires separate human approval. Custom tools, remote/overridden implementations, and later handlers must enforce their own final-input policy.
Install
Standalone npm package
pi install npm:@diegopetrucci/pi-permission-gate
Collection package
pi install npm:@diegopetrucci/pi-extensions
GitHub package
pi install git:github.com/diegopetrucci/pi-extensions
Then reload pi:
/reload
Notes
- Hooks the
tool_callevent. - Inspects
bash,powershell,write, andedittool calls. - Validates shell timeouts as well as command strings and fails closed on malformed calls.
- Normalizes relative/absolute paths before matching so traversal tricks do not bypass the guard.
- Prompts with a simple
Yes/Noselector before allowing dangerous commands or protected path writes.