pi-provider-guard
A pi coding-agent extension that keeps pi off the metered anthropic provider and appends user-supplied harness policy prose to every turn.
Package details
Install pi-provider-guard from npm and Pi will load the resources declared by the package manifest.
$ pi install npm:pi-provider-guard- Package
pi-provider-guard- Version
0.1.0- Published
- Aug 30, 2026
- Downloads
- 173/mo · 7/wk
- Author
- schuettc
- License
- MIT
- Types
- extension
- Size
- 25.9 KB
- Dependencies
- 0 dependencies · 0 peers
Pi manifest JSON
{
"extensions": [
"./src/index.ts"
]
}Security note
Pi packages can execute code and influence agent behavior. Review the source before installing third-party packages.
README
pi-provider-guard
A pi extension that keeps pi off the metered anthropic provider and appends your own harness policy prose into every turn.
What it does
- Captures a safe (non-metered) baseline model at
session_startas the revert target of last resort. - On
model_select, reverts an anthropic (metered) selection back to a safe model — the previous model if it was itself safe, otherwise the captured baseline — unlessPI_ALLOW_METERED_ANTHROPICis exactly1(any other value,0included, leaves the guardrail armed). The revert is attempted first and success is only reported once it lands; a failed revert, or a metered selection with no safe target at all, notifies aterrorlevel instead of leaving the user silently on the metered provider. No path ever callssetModelwith an anthropic model. - On
before_agent_start, appends your harness policy prose (loaded from config, see below) to the system prompt. With no configured prose the system prompt is returned unchanged.
Install
pi install npm:pi-provider-guard
Policy prose is user-supplied
This package ships no baked-in policy prose. The rules you want carried into every turn are read at runtime from your own config file:
~/.pi/agent/extensions/pi-provider-guard/config.json
with a prose field that is an array of strings:
{
"prose": [
"Your first earned rule.",
"Your second earned rule."
]
}
Each string becomes a line under a fixed header (Harness policy — earned rules from operating this harness, not permission settings:) appended to the system prompt. A missing, unreadable, or malformed file — or a missing/non-array prose field — is treated as no prose: the system prompt is left untouched and turn start never fails.
Permission policy is separate
The metered-provider guardrail here is independent of pi's file/tool permission system. If you want to allow read/write/edit and deny *.env, ~/.ssh/*, etc., configure that with a permission-system extension (e.g. @gotgenes/pi-permission-system) and its own config — this package does not manage permissions.
Tests
node --test src/*.test.ts
The pure gate/prose logic (src/gate.ts, src/prose.ts) and the wired extension behavior (src/index.ts) are unit-tested with zero mocking against a fake pi.