- add AdvicePresenter rendering a pi-native setWidget panel while a permission dialog is up: judgment verdict with reason, high-risk skip with category, or an unavailable cause - highlight the decision-relevant command fragment via a focus cascade: high-risk match, triggering unit, then executed unit - clear the widget when permissions:decision resolves the same request - add dialogAdvice config key (default true, invalid falls back with a diagnostic) and cover formatting, lifecycle, and config in tests
pi-extensions
English | 简体中文
Personal extensions for the pi coding agent, focused on Bash permissions: unwrap, inspect, and re-adjudicate commands before they run.
Packages
| Package | npm | Description |
|---|---|---|
| pi-permission-ai-judge | @sikongjueluo/pi-permission-ai-judge | AI judge — a model rules allow / deny / defer on each pending Bash ask; shadow logs only, enforce auto-approves |
| pi-permission-inner-cmd | @sikongjueluo/pi-permission-inner-cmd | Unwraps transparent Bash wrappers (timeout, time, …) and authorizes the inner command |
Install
Per package from npm:
pi install npm:@sikongjueluo/pi-permission-ai-judge
pi install npm:@sikongjueluo/pi-permission-inner-cmd
Or the whole repo via git (both extensions mount through the root package.json pi.extensions manifest):
pi install git:github.com/SikongJueluo/pi-extensions
Either way, effective in any directory. Prerequisites:
- Enable
@gotgenes/pi-permission-system≥ 32 - Add the extensions to the authorizer chain — order is consultation order, UI sessions only:
// ~/.pi/agent/extensions/pi-permission-system/config.json
{ "authorizerChain": ["inner-cmd", "ai-bash-judge"] }
See the ai-judge README for modes, judge model, and guardrails.
Development
pnpm workspace, TypeScript + vitest.
pnpm install
pnpm check # tsc --noEmit
pnpm test # vitest run
Design decisions live in docs/adr/.
Release
Bump the version in packages/<pkg>/package.json, commit, then tag and push:
jj tag set @sikongjueluo/pi-permission-ai-judge@0.1.0 -r <rev>
jj git push # pushes the bookmark and new tags
The publish workflow verifies the tag matches the package.json name and version, runs check and tests, then publishes to npm with provenance. Requires the NPM_TOKEN repository secret (granular token with publish rights on the @sikongjueluo scope, or a classic automation token).
License
GPL-3.0