@pi-harness/plugin-anchored-standard
v0.1.32
Published
Audit agent trajectories against an explicit tool-call allowlist and flag activity outside the anchored run.
Maintainers
Readme
@pi-harness/plugin-anchored-standard
Anchored Standard — Audit agent trajectories against an explicit tool-call allowlist and flag activity outside the anchored run.
Install
npm install --save-exact @pi-harness/plugin-anchored-standardEnable
Add the entry to the Cordis profile the harness starts from:
- id: anchored-standard
name: "@pi-harness/plugin-anchored-standard"
config: {}The Pi Harness plugin marketplace installs and enables this package for you; the steps above are the manual equivalent.
Audit semantics
trajectory_anchor_check {} returns a complete JSON report in both model-visible text and UI details: status, auditOnly: true, scope: "since-plugin-load", event count, tool-call count, configured budget, allowed tools, and violation codes/messages.
- This is a read-only audit, not enforcement: disallowed tools and over-budget calls still execute.
- Events and violations accumulate across sessions for the plugin's lifetime. Only the first finding of each of the five violation codes is retained. Reloading the plugin clears this history.
toolCallscounts the current or last run and resets onagent_start; a historicalviolatedstatus does not mean the current run introduced another violation.maxToolCallsdefaults to 64 (bounded to 1–512); an emptyallowedToolslist allows any tool. The allowlist contains at most 512 names of 128 UTF-16 code units each.- Diagnostic tool names are clipped to 128 code units with an ellipsis; allowlist matching uses the full original name. The complete serialized UTF-8 report stays within 512 KiB, including worst-case JSON escaping.
