context-mode
MCP plugin that saves 98% of your context window. Works with Claude Code, Gemini CLI, VS Code Copilot, OpenCode, and Codex CLI. Sandboxed code execution, FTS5 knowledge base, and intent-driven search.
$ pi install npm:context-modeExtensions, skills, prompt templates, and themes published to npm. Install with pi install npm:<package>. See the package docs for details.
MCP plugin that saves 98% of your context window. Works with Claude Code, Gemini CLI, VS Code Copilot, OpenCode, and Codex CLI. Sandboxed code execution, FTS5 knowledge base, and intent-driven search.
$ pi install npm:context-modeCustom pi coding-agent extensions: bwrap sandbox, workspace guard, opencode edit, and more
$ pi install npm:@trim21/personal-pi-extensionsAgent run-loop primitive over Tangle sandbox transports — runs an AgentProfile against a brief with criterion gates, budget caps, and streaming events. Includes TangleToolProvider for Pi tool integration.
$ pi install npm:@tangle-network/tcloud-agentLinux (bubblewrap) and macOS (Seatbelt) process sandbox for Pi backed by Anthropic's @anthropic-ai/sandbox-runtime. Fail-closed static filesystem policy plus per-connection network approval from pi-auto-review; sandboxes main-agent Bash and built-in subag
$ pi install npm:@erichll/pi-sandboxFail-closed, model-backed approval broker for Pi: deterministically hard-denies dangerous operations, reviews dangerous boundaries with a reviewer model, and issues one-shot expiring grants that OS sandbox adapters must consume before retrying.
$ pi install npm:@erichll/pi-auto-reviewPi extension for detached, sandboxed subagent runs that keep the foreground session free.
$ pi install npm:pi-better-subagentsPi extension bundle for a default write sandbox, subagents, durable background tasks, and goal tracking.
$ pi install npm:pi-better-harnessJeff is a model-native quality control plane and cooperative workflow protocol for trusted operators and friendly agents, not a security sandbox.
$ pi install npm:@johanthoren/jeffContext engine for Pi — zero-LLM compaction, session continuity, sandbox execution, and tool display optimization
$ pi install npm:@pi-unipi/compactorPi extension: active-provider quota footer for OpenAI Codex and Kimi Coding.
$ pi install npm:pi-sandbox-usage-statusOS-level sandboxing for pi with interactive permission prompts
$ pi install npm:picodesandboxPi coding agent extension that runs all tool calls inside a remote Upstash Box sandbox while the agent runs locally
$ pi install npm:@upstash/box-piPi permission extension — four permission modes (yolo/auto/approve/strict) with three-layer pipeline (AST + rules + AI classifier).
$ pi install npm:@zhushanwen/pi-permissionDeclarative, user-definable permission modes for the pi coding agent: OS-level sandboxing (bubblewrap / sandbox-exec), an allow/ask/deny policy engine, real bash AST gating (tree-sitter), tool hiding, and skill/custom-tool gating.
$ pi install npm:pi-permission-modesTyped, sandboxed Code Mode access to configured MCP servers for Pi
$ pi install npm:pi-codemcpGuardian extension for pi — security guards that block accidental secret exposure, enforce command policies, protect .env files, and sandbox bash commands
$ pi install npm:@casualjim/pi-heimdallPi Codemode plugin - TypeScript code execution with sandboxed tools, typed host CLI, and MCP integration
$ pi install npm:@boozedog/pi-codemodeOS-level sandboxing for pi with interactive permission prompts
$ pi install npm:@xzzpig/pi-sandboxDeclarative, routed multi-agent workflows for Pi — a Microsoft-agentic-workflow-style YAML grammar (typed steps, conditional routes, parallel/for_each fan-out, human gates, sub-workflows) run by a decoupled, fail-closed state machine with a sandboxed temp
$ pi install npm:privateer-workflowContainer sandbox for DoomPi launches: the agent, extensions, and tools run inside Docker or Podman while the terminal stays on the host
$ pi install npm:@agimon-ai/doompi-sandboxOS-sandboxed read-only / restricted execution for pi (bubblewrap on Linux, sandbox-exec on macOS).
$ pi install npm:pi-os-guardSandbox write/edit/bash to the project dir — prompt / deny / allow modes, configurable deny-with-redirect rules, per-session allow-deny memory
$ pi install npm:@d3ara1n/pi-access-deniedFail-closed, model-backed approval broker for Pi: deterministically hard-denies dangerous operations, reviews dangerous boundaries with a reviewer model, and issues one-shot expiring grants that OS sandbox adapters must consume before retrying.
$ pi install npm:@brglng/pi-auto-reviewmacOS Seatbelt sandbox extension package for pi bash and file-tool access controls.
$ pi install npm:pi-seatbelt-sandboxGuardian extension for pi — security guards that block accidental secret exposure, enforce command policies, protect .env files, and sandbox bash commands
$ pi install npm:@josephyoung/pi-heimdallPi coding agent extension that runs all tool calls inside a remote, ephemeral Daytona sandbox while the agent runs locally
$ pi install npm:@daytona/piExtensión de Pi para administrar sandboxes de Apple `container` (micro-VMs Linux): un comando /container y una herramienta container_sandbox invocable por el modelo (status/list/create/run/stop/remove).
$ pi install npm:@pandi-coding-agent/pandi-containerpi extension that sandboxes LLM coding agents inside a Gondolin micro-VM with configurable additional mounts
$ pi install npm:pi-gondolin-mountRun Pi coding-agent tool calls inside Docker sbx sandboxes
$ pi install npm:@christianmoesl/pi-sbxOpinionated Pi package with web search, review workflows, sandboxing, memory, usage reporting, skills, and a theme
$ pi install npm:tau-coding-agentRun Pi file and shell tools in an isolated Apple Container or Docker workspace
$ pi install npm:@kjrjay/pi-sandboxWhen the example safety extensions don't cover what you need, this should! Simple with approval flow and windows sandbox capability (with Sandboxie)
$ pi install npm:pi-supersafetyExtensión de Pi para ejecutar sandboxes efímeros y restringidos con Podman mediante /podman y la tool podman_sandbox.
$ pi install npm:@pandi-coding-agent/pandi-podmanFull Tau package for Pi with coding workflows, web search, sandboxing, memory, Telegram, Home Assistant, OpenSCAD, skills, and a theme
$ pi install npm:tau-all-agentCode-mode tool for the pi coding agent: a sandboxed Python meta-tool (via @pydantic/monty) that lets the agent write code against host tools and build ephemeral code tools
$ pi install npm:pi-code-toolA lightweight OS-level guard for Pi: agents stay useful, sensitive paths stay blocked, and writes stay inside the workspace you allow. No container overhead. No workflow drama.
$ pi install npm:pi-guard-sandboxVM-isolated sandbox for pi with automatic secret protection · from yapp
$ pi install npm:pi-enclaveServer-side Pi extension factory that routes built-in tools to a remote OpenSandbox sandbox
$ pi install npm:pi-extension-opensandboxOn-demand disposable Docker sandbox for Pi: run code in a fresh, offline Debian container with read-only project mount and per-run network approval.
$ pi install npm:pi-sandbox-dockerpi coding-agent extension that runs every read/write/edit/bash op inside a per-session Linux container (Apple `container` or Docker).
$ pi install npm:pi-container-sandboxMCP plugin that saves 98% of your context window. Works with Claude Code, Gemini CLI, VS Code Copilot, OpenCode, and Codex CLI. Sandboxed code execution, FTS5 knowledge base, and intent-driven search.
$ pi install npm:@h4rvey-g/context-modeOS-level sandbox for pi coding agent — macOS sandbox-exec / Linux bubblewrap kernel-enforced isolation
$ pi install npm:@nqbao/pi-sandboxSecurity harness for the PI coding agent — forbids dangerous commands and gates sensitive ones behind user approval
$ pi install npm:@the-forge-flow/security-harness-pi