@diegopetrucci/pi-permission-gate
A pi extension that prompts before dangerous shell commands and protected file writes.
Package details
Install @diegopetrucci/pi-permission-gate from npm and Pi will load the resources declared by the package manifest.
$ pi install npm:@diegopetrucci/pi-permission-gate- Package
@diegopetrucci/pi-permission-gate- Version
0.1.14- Published
- Sep 1, 2026
- Downloads
- 522/mo · 29/wk
- Author
- diegopetrucci
- License
- MIT
- Types
- extension
- Size
- 54.5 KB
- Dependencies
- 0 dependencies · 1 peer
Pi manifest JSON
{
"extensions": [
"index.ts"
]
}Security note
Pi packages can execute code and influence agent behavior. Review the source before installing third-party packages.
README
permission-gate
A small pi extension that prompts for confirmation before running potentially dangerous bash or PowerShell commands or writing to protected paths.
This started from the original permission-gate.ts example in earendil-works/pi and adds conservative shell and path hardening.
What it checks
rm -rf- PowerShell
Remove-Item -Recurse -Forceand its standard aliases, including module-qualified, interpolated, splatted, and backtick-escaped forms sudochmod/chownwith777- direct
write/editcalls touching normalized protected paths:- exact
.gitpath segments - exact
node_modulespath segments - secret-bearing
.envfiles such as.envand.env.production
- exact
Safe .env templates/examples such as .env.example and .env.production.template are allowed.
If pi is running without an interactive UI, it blocks matching commands and protected path writes by default.
For Pi's built-in local Windows PowerShell tool, commands that pass the fast lexical checks are also parsed with the same PowerShell installation's AST parser before execution. Malformed input, parser failures, Remove-Item parameter splatting, command-resolution changes (aliases/modules/providers/direct function or filter definitions), known script/process/job/member invocation wrappers, computed member calls, and analyzer inputs above 16,000 UTF-8 bytes are treated conservatively and require confirmation (or are blocked when no UI is available). Computed targets passed to provider-capable mutation commands also require confirmation because the target could resolve to Alias: or Function:. Literal quoted/commented examples, including literal here-strings, stay benign. Definitely enabled -WhatIf removals (-WhatIf, -WhatIf:$true, or -WhatIf:1) remain non-destructive and are allowed; computed switch values require confirmation.
Non-Windows and custom/remote powershell tools receive the conservative lexical checks, but only Pi's built-in local Windows tool can be verified with its actual parser. Pi extensions are trusted code: tool overrides, remote operations, spawn hooks, and mutations made by handlers loaded after this gate are outside its boundary and must enforce their own final-input policy.
This is a targeted confirmation guard for the command classes listed above, not a shell sandbox or a proof that every unlisted executable/API is harmless.
Install
Standalone npm package
pi install npm:@diegopetrucci/pi-permission-gate
Collection package
pi install npm:@diegopetrucci/pi-extensions
GitHub package
pi install git:github.com/diegopetrucci/pi-extensions
Then reload pi:
/reload
Notes
- Hooks the
tool_callevent. - Inspects
bash,powershell,write, andedittool calls. - Validates shell timeouts as well as command strings and fails closed on malformed calls.
- Normalizes relative/absolute paths before matching so traversal tricks do not bypass the guard.
- Prompts with a simple
Yes/Noselector before allowing dangerous commands or protected path writes.