cc-safety-net
A coding agent CLI hook - block destructive commands and secret file access
$ pi install npm:cc-safety-netExtensions, skills, prompt templates, and themes published to npm. Install with pi install npm:<package>. See the package docs for details.
A coding agent CLI hook - block destructive commands and secret file access
$ pi install npm:cc-safety-netAST-backed steering hooks for pi — deterministic tool-call guardrails with command-level effective-cwd scoping.
$ pi install npm:@cad0p/pi-steeringVerification-oriented smart compaction extension for Pi Coding Agent — deterministic extraction, exploration, synthesis, verification, metrics, and safety checks.
$ pi install npm:pi-smart-compactFork of @ogulcancelik/pi-auto-permissions with dialog-answer user evidence: context-aware Bash permissions for Pi with automated guardian review.
$ pi install npm:@hank-warren/pi-auto-permissionsPath Guard for pi — blocks destructive commands & path overwrites, protects .env/keys, with strict/normal/loose/trusted/naked guard modes (/guard). pi 防误删/防误覆盖扩展,支持 5 种防护模式。
$ pi install npm:@yaosu/pi-path-guardAgent Approve extension for Pi - approve or deny AI agent tool calls from your iPhone and Apple Watch
$ pi install npm:@agentapprove/piReal workspace undo/redo for Pi. Bring Claude Code style /rewind and OpenCode /undo safety to @earendil-works/pi-coding-agent.
$ pi install npm:pi-workspace-historyTypeSafe AI (Jev) decisions for Pi: batched Choice/Score/Noul evaluation tool, terminal playground, and a typed API other extensions build on.
$ pi install npm:pi-typesafeDeny-first Pi guardrails that keep LLM shell and file access safe, transparent, and user-approved.
$ pi install npm:@senad-d/guardmeA governed Agent Factory for Pi: launch communicating agent teams, run tmux-backed factories, validate artifacts, and package repeatable workflows.
$ pi install npm:zob-harness基于 AST 的 Pi 代理安全防护扩展 — 解析 Bash 命令,拦截危险操作(继承自 pi-damage-control)
$ pi install npm:pi-ast-guardPi control center for bounded 9Router model, pool, mission, quality, analytics, and safety workflows
$ pi install npm:pi-multi-orchestratorGuardrail extensions for Agentic Driver: advisory review, bounded Herdr communication, and guarded worker lifecycle.
$ pi install npm:@evoclock/pi-agentic-driverDeclarative flag-presence and flag-allowlist predicates for pi-steering rules. First official external plugin.
$ pi install npm:@cad0p/pi-steering-flagsShared TUI building blocks for pi extensions — spinner, card, status widget, view, ticker, context stash, width safety, preview runtime.
$ pi install npm:@everyx/pi-uiSend Pi agents back to work when they stop before the job is done.
$ pi install npm:pi-agent-foremanA collection of pi extensions and skills for annotation UIs, context management, workflow audits, contrarian review, review-comment triage, notifications, brrr push alerts, safety guards, GitHub research, repo-local knowledge, todos, tool rendering, model
$ pi install npm:@diegopetrucci/pi-extensions📜 Napkin integration for pi — vault context, knowledge tools, and automatic distillation with git-worktree concurrency safety
$ pi install npm:@cad0p/pi-napkinLLM-powered safety gate for pi: classifies bash and MCP tool calls by risk before execution, with CWD-aware judgments.
$ pi install npm:@johansja/pi-permission-gateAutomatically locks Pi's interactive input while an agent is running.
$ pi install npm:@j1nn0/pi-input-lockOne toggle to auto-approve everything, with an undo trail: three-tier bash guard, file pre-images, fail-closed everywhere
$ pi install npm:@pify/yoloPi extension: detects and interrupts infinite thinking-block and tool-call loops in real time before they exhaust your context window.
$ pi install npm:pi-loop-policePin a session goal and keep the agent anchored to it: settled-idle continuation, safety limits, evidence-gated completion
$ pi install npm:@pify/goalInteractive guardrails for dangerous bash commands and protected file edits in Pi.
$ pi install npm:@firstpick/pi-extension-safety-guardThe carrier that runs kendex's hooks under Pi: it dispatches the rendered kendex/hooks.json registry on every listener kendex maps a hook event onto, so a PreToolUse, PostToolUse, Stop, TaskCompleted or SessionStart hook fires, the bash guards kendex rend
$ pi install npm:@vanillagreen/pi-hooksA pi extension that prompts before session changes when the current git repo has uncommitted changes.
$ pi install npm:@diegopetrucci/pi-dirty-repo-guardConfigurable Bash safety rules with per-rule actions and custom matchers for Pi
$ pi install npm:pi-safety-guardsFocused code retrieval, editing, safety checks, and language-server support for Pi.
$ pi install npm:@floydous/pi-agent-kernelA pi extension that prompts before dangerous shell commands and protected file writes.
$ pi install npm:@diegopetrucci/pi-permission-gateA pi extension that confirms destructive session actions.
$ pi install npm:@diegopetrucci/pi-confirm-destructiveSafe git-worktree management for pi: create/list/merge/remove with safety rails, no shell interpolation, Windows-first, zero tmux
$ pi install npm:@pify/worktreeGit-aware Pi guardrail that asks for confirmation before destructive shell actions can change or lose work
$ pi install npm:@spences10/pi-confirm-destructivepi extension for fixed-task-set eval runs and prompt/system comparisons
$ pi install npm:@tryinget/pi-evalset-labPi extension for Windows-native tool manipulation — shell profiles, path conversion, command execution, WSL bridge, safety policy, and developer tool discovery.
$ pi install npm:@bacnh85/pi-windows-toolsPi extension: confirm before write/edit with profiles, diff preview, and persistent allow/deny memory. Reads always allowed.
$ pi install npm:pi-edit-approvalContext-aware Bash permissions for Pi with automated guardian review.
$ pi install npm:@ogulcancelik/pi-auto-permissionspi extension: gate git/gh write operations (commit, push, PRs, and more) behind interactive user approval.
$ pi install npm:pi-git-safeguardConfirm or block dangerous bash commands before the Pi coding agent executes them.
$ pi install npm:@nilskluewer/pi-auto-permission-gateCommit-message format validation predicates for pi-steering. Bundled formats: Conventional Commits 1.0.0 (Angular preset type allowlist), bracketed JIRA-style ticket references. Extensible via `commitFormatFactory`.
$ pi install npm:@cad0p/pi-steering-commit-formatWhen the example safety extensions don't cover what you need, this should! Simple with approval flow and windows sandbox capability (with Sandboxie)
$ pi install npm:pi-supersafetyHigh-risk-only approval hook with LLM risk analysis, behavior detection, protected-path interception, and decision memory for oh-my-pi (OMP) and pi-agent.
$ pi install npm:smart-approveFail-open fork of cc-safety-net — blocks destructive git/filesystem commands, but defaults to fail-OPEN on broken/legacy config so the shell never bricks.
$ pi install npm:pi-safety-netOPA-backed bash command guard for the pi ecosystem — structured decision-output.v1 JSON, fail-open default, Claude Code hook protocol compatible. Agent-agnostic engine + CLI.
$ pi install npm:pi-opa-netConfirm destructive bash and git actions before Pi runs them
$ pi install npm:@zenspc/pi-safetyUnconditionally blocks destructive bash commands before execution. A pi extension that guards against rm, git reset --hard, docker rm, aws delete operations, and more.
$ pi install npm:@giuseppe.trisciuoglio/pi-prevent-destructive-commandsSQLite safety workflow reminder that steers Pi agents to use gated mcp-sqlite-tools instead of raw sqlite3
$ pi install npm:@spences10/pi-sqlite-toolsPowerful session deletion tool for Pi. Delete multiple sessions at once, grouped by project, with safety confirmations.
$ pi install npm:pi-delete-session