@ian-pascoe/pi-web-tools
Bounded public web search and textual URL fetching for Pi
Package details
Install @ian-pascoe/pi-web-tools from npm and Pi will load the resources declared by the package manifest.
$ pi install npm:@ian-pascoe/pi-web-tools- Package
@ian-pascoe/pi-web-tools- Version
0.2.0- Published
- Oct 2, 2026
- Downloads
- 670/mo · 24/wk
- Author
- ianpascoe_
- License
- MIT
- Types
- extension, skill
- Size
- 52 KB
- Dependencies
- 3 dependencies · 4 peers
Pi manifest JSON
{
"skills": [
"./skills"
],
"extensions": [
"./src/index.ts"
]
}Security note
Pi packages can execute code and influence agent behavior. Review the source before installing third-party packages.
README
@ian-pascoe/pi-web-tools
Bounded Web Search and Web Fetch model tools for Pi. Web Search discovers current public information through Exa or Parallel. Web Fetch retrieves one HTTP or HTTPS URL as text, Markdown, or HTML.
Install
Pi loads the source extension from this repository:
pi install git:github.com/ian-pascoe/pi-extensions
Select packages/pi-web-tools/src/index.ts for a filtered Git installation. After publishing, install the package directly:
pi install npm:@ian-pascoe/pi-web-tools
Requires Node.js 22.19 or newer and Pi >=0.99.0.
Tools
web_search
Searches current public web information. Pi deterministically chooses Exa or Parallel once per session with FNV-1a checksum parity; API-key presence never changes that choice. Both providers support anonymous requests. Set optional process environment keys before starting Pi:
export EXA_API_KEY=...
export PARALLEL_API_KEY=...
| Parameter | Values | Default |
|---|---|---|
query |
required string | — |
numResults |
integer 1–20 | 8 |
livecrawl |
fallback or preferred |
fallback |
type |
auto, fast, or deep |
auto |
contextMaxCharacters |
integer 1–50,000 | Exa effective default: 10,000 |
Exa receives all controls and an optional EXA_API_KEY endpoint credential. Parallel receives the query and Pi session ID; its protocol has no matching tuning fields. Search results are provider text without citation rewriting. A provider failure has no retry and never falls back to the other provider.
web_fetch
Fetches exactly one absolute HTTP or HTTPS URL. HTTP is preserved, native fetch redirects are followed, and loopback, link-local, and private-network URLs are permitted in Pi's local trust model.
| Parameter | Values | Default |
|---|---|---|
url |
required absolute HTTP or HTTPS URL | — |
format |
text, markdown, or html |
markdown |
timeout |
number greater than 0 through 120 seconds | 30 seconds |
Only textual MIME types are returned: an absent type, text/*, JSON, XML, JavaScript, and structured +json/+xml types. SVG is accepted as XML. Other images and files are rejected. HTML converts to Markdown or plain text when requested; scripts and other active embedded content are not executed. A Cloudflare 403 challenge gets one retry with the pi-web-tools user agent inside the original timeout budget.
Both tools declare MCP-style annotations: read-only, non-destructive, idempotent, and open-world. Pi reports them through pi.getAllTools() so permission extensions can decide which calls to confirm; Pi does not send them to model providers.
Script results
Both tools declare an outputSchema and return matching structuredContent, so a Pi codemode script receives an object instead of the model-facing text. Field names are snake_case, like Pi's bash and pi-termctrl; the session details keep their existing shape. The model still reads the same text, and a failed call still throws.
| Tool | Script value |
|---|---|
web_search |
{ provider, content, full_output_path? } |
web_fetch |
{ url, content_type, format, content, truncated, full_output_path? } (final URL) |
Scripts cannot read the private spill file, so content carries more than the model sees. Web Search content is the Search Provider's complete text answer (at most 256 KiB). Web Fetch content is the complete converted text up to 1 MiB of UTF-8, cut on a character boundary; truncated is true only for a longer page. full_output_path appears whenever the model-visible text was truncated, and then names the file with the complete text.
Search results stay provider free text: Exa and Parallel return prose-and-snippet blobs rather than records, so the schema does not invent result fields. It adds the selected provider and the complete text.
Limits and security
Web Search response bodies stop at 256 KiB. Web Fetch response bodies stop at 5 MiB. Both tools apply Pi's 50 KiB or 2,000-line model-output limit after parsing or conversion. When output is truncated, the complete text is written to a unique private temporary directory and the returned result includes its path and exact counts. Script results are bounded separately, as described above. The operating system owns later temporary-file cleanup.
Queries and URLs leave the machine for their Search Provider or requested host. Web Fetch intentionally permits private-network destinations, so use it only where the model and extension are trusted. The package provides no browser automation, JavaScript execution, extension-owned crawling, cookie storage, cache, settings, commands, or citation rewriting.
API keys are read once when the extension loads, used only to construct the final provider request, and never intentionally included in model content, result details, errors, or temporary files.
License
MIT