sloppi
A sandboxed Pi setup with ask mode and terminal UI customizations.
Package details
Install sloppi from npm and Pi will load the resources declared by the package manifest.
$ pi install npm:sloppi- Package
sloppi- Version
0.0.2- Published
- Aug 20, 2026
- Downloads
- 251/mo · 251/wk
- Author
- spence-s
- License
- MIT
- Types
- extension, theme
- Size
- 121.6 KB
- Dependencies
- 6 dependencies · 2 peers
Pi manifest JSON
{
"extensions": [
"./agent/extensions/ask-mode.ts",
"./agent/extensions/commit.ts",
"./agent/extensions/permissions/index.ts",
"./agent/extensions/sandbox/index.ts",
"./agent/extensions/startup-banner.ts",
"./agent/extensions/shell-ui.ts",
"./agent/extensions/zshrc.ts"
],
"themes": [
"./agent/themes/dracula.json"
]
}Security note
Pi packages can execute code and influence agent behavior. Review the source before installing third-party packages.
README
Sloppi
███████╗██╗ ██████╗ ██████╗ ██████╗ ██╗ ╭╮ )( ╭╮ ) ╲╲
██╔════╝██║ ██╔═══██╗██╔══██╗██╔══██╗██║ ╰╯ ( ) ╰╯ ( ╲╲
███████╗██║ ██║ ██║██████╔╝██████╔╝██║ ╔════════════════╗ ╲╲
╚════██║██║ ██║ ██║██╔═══╝ ██╔═══╝ ██║ ║ ██ ≋≋≋ ██ ≋≋ ║ ╲╲
███████║███████╗╚██████╔╝██║ ██║ ██║ ╚██████████████╝
╚══════╝╚══════╝ ╚═════╝ ╚═╝ ╚═╝ ╚═╝ ████████████
A shareable Pi package that sandboxes filesystem tools, adds a read-only ask mode, and customizes the terminal header and footer.
Install
Review the source before installing: Pi packages execute with your user permissions.
Install from npm:
pi install npm:sloppi
Or install the latest development version directly from GitHub:
pi install git:github.com/spence-s/sloppi
To try either source for one session without changing Pi settings:
pi -e npm:sloppi
pi -e git:github.com/spence-s/sloppi
Manage the installation with:
pi update npm:sloppi
pi remove npm:sloppi
pi config # enable or disable individual Sloppi extensions
Sloppi does not change Pi's project trust behavior.
Requirements
- Node.js 22 or newer
- macOS:
brew install ripgrep - Linux: install
bubblewrap,socat,ripgrep, andfd
Sandbox currently supports macOS and Linux. Its shell UI uses Nerd Font icons but remains usable without them.
For web research in ask mode, install pi-web-access separately:
pi install npm:pi-web-access
Extensions
ask-mode.ts—/ask on|off|toggle|statuscontrols modes;/ask <prompt>toggles modes before submitting the prompt.commit.ts—/commitstages all changes and loads an editable, model-generated Conventional Commit command into Pi's input;/commit modelselects its model.permissions/— applies regex-based ask or deny rules to shell commands;/permissionsedits project rules.sandbox/— runs Pi's filesystem tools inside Anthropic Sandbox Runtime;/sandboxmanages its access. Itsresearch_scouttool runs an isolated scout with only sandboxed read, grep, find, and list access. Select its fixed model with/sandbox global→Research Scout model.startup-banner.ts— replaces Pi's TUI header.shell-ui.ts— adds a Powerlevel10k-inspired prompt and status area to Pi's terminal UI.zshrc.ts— loads zsh aliases for host-side!commands.
Sandbox overrides Pi's built-in bash, edit, find, grep, ls, read, and write tools. It blocks unapproved extension tools from host execution; Pi web-access tools remain host-side so provider credentials are not exposed to sandboxed commands.
Sandbox configuration
Sandbox writes sandbox.json beside Pi's agent directory. This is ~/.pi/sandbox.json by default and follows PI_CODING_AGENT_DIR when that environment variable is set.
Global SRT options live at the root. Project overrides live under projects["/absolute/project/path"]; arrays are combined and project scalar values override global values.
{
"network": {
"allowedDomains": ["registry.npmjs.org:443"]
},
"sandbox": {
"exposeEnv": ["SAFE_GLOBAL_VAR"]
},
"projects": {
"/absolute/project/path": {
"filesystem": {
"allowRead": ["/shared/read-only"],
"allowWrite": ["/shared/writable"]
},
"sandbox": {
"exposeEnv": ["SAFE_PROJECT_VAR"]
}
}
}
}
exposeEnv contains host environment variable names, not values. Global and project lists combine; missing variables are ignored. Exposing HOME opts into the host home directory for tool configuration lookup, but filesystem rules still control access to it. Sloppi's fixed PATH, LANG, TMPDIR, and USER values cannot be overridden.
Request policies add method, path, and exact header-value restrictions to an allowed destination:
{
"network": {
"allowedDomains": ["api.example.com:443"]
},
"sandbox": {
"requestPolicies": [{
"destination": "api.example.com:443",
"allow": [{
"methods": ["POST"],
"pathPrefixes": ["/v1/jobs"],
"headers": {"x-environment": ["preview"]}
}]
}]
}
}
Global and project request policies combine. A listed destination denies requests unless one allow rule matches; predicates within a rule all apply. paths matches exactly, while pathPrefixes matches a path segment and its children. Destinations require an exact host:port and must also be present in network.allowedDomains. Sloppi enables SRT TLS termination when policies are configured, so protected HTTPS destinations cannot be listed in tlsTerminate.excludeDomains. Do not store secret header values in this file. Run /reload after editing the file.
Use /sandbox to manage the current project's access interactively. Use /sandbox global to open the same controls for global access. Access views and rule lists show the effective configuration, while changes apply only to the selected project or global layer. Request policies are configured manually; the advanced editor validates the complete serializable SRT configuration before saving and warns before enabling weaker isolation options.
By default, filesystem tools can write only the current project and private session scratch space. Global Pi skills and Git/npm package directories are readable. Network access is denied until allowed. A blocked network request can prompt to add a project domain rule; use /sandbox to disable those prompts.
Sandbox is an additional experimental boundary, not a guarantee. Broad filesystem paths, domains, Unix sockets, Apple Events, or weaker SRT isolation options reduce its protection. See Anthropic Sandbox Runtime for platform limitations.
Development
npm install
npm run check
npm run lint
npm test
Tests use Node's native test runner. Runtime state and machine-specific Pi settings are gitignored.