npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@aefree/pi-safety-rails

v0.1.4

Published

Pi safety-focused extensions for shell execution and tool result hygiene.

Readme

Pi Safety Rails

Pi package containing safety-focused extensions for shell execution and tool-result hygiene.

Included extensions

  • tool-output-redactor
  • path-permissions

Purpose

This package provides practical safety rails for Pi:

  • redact token-like secrets from tool outputs before they reach the model/session
  • block sensitive filesystem paths through deny-only path permissions

Tool output redaction

  • Redacts token-like secrets from tool outputs before they are shown to the model/session.
  • Applies to text content and nested string fields in tool result details.

Path permissions

  • Deny-only path blocking for file-oriented tools.
  • Current v1 target tools:
    • read
    • write
    • edit
    • grep
    • find
    • ls
  • Configuration files:
    • user-global: ~/.pi/agent/path-permissions.json
    • project-local overlay: .pi/path-permissions.json
  • The first version intentionally ignores allow rules and only honors deny.

Example config with Windows and macOS paths:

{
  "permission": {
    "external_directory": {
      "C:/Windows/**": "deny",
      "/Users/yourname/Library/Keychains/**": "deny"
    },
    "edit": {
      "C:/Windows/**": "deny",
      "/Users/yourname/.ssh/**": "deny"
    }
  }
}

Replace yourname with the macOS account name. A trailing /** denies both the named directory and its descendants, without matching sibling prefixes.

Deny matching is case-insensitive on Windows and macOS, while denial messages retain the path's original display casing. macOS matching deliberately fails closed: it remains case-insensitive even on a case-sensitive APFS volume, so a differently cased path can be conservatively denied there. Linux matching remains case-sensitive.

Rules are evaluated against both the supplied path and its canonical filesystem destination. Existing symlinks and Windows junctions therefore cannot redirect access into a denied directory; for new files, the nearest existing ancestor is canonicalized before matching.

A copy also ships in this package as path-permissions.example.json.

Install

Install from npm:

pi install npm:@aefree/pi-safety-rails

For local development:

pi install <path-to-pi-safety-rails>

License

MIT. See LICENSE.