Pi coding agent gets an auto-mode plugin that locally classifies risky shell commands
deepu105 · reddit · 2026-10-08
Developer deepu105 released pi-automode-classifier, an open-source plugin for the Pi coding agent that adds a safety layer to its auto mode, where every tool call otherwise runs without approval.
How it works, in three layers:
- Built-in rules handle most commands: ls, builds, and tests run automatically; rm -rf is blocked outright; git push and sudo require manual approval.
- Unrecognized commands go to a classifier model that returns a risk probability; above a threshold, the user gets a confirm prompt — the model itself never blocks a command.
The author benchmarked three classifier models:
- Jev 1.13 (hosted by TypeSafe via OpenRouter): 270 ms per check, 1.5 cents per 1,000 checks
- Kev-0.8B running locally on CPU with llama.cpp: 170 ms, 1.1 GB RAM, nothing leaves the machine (the author's pick)
- Laya typed-decisions locally: 100 ms, 550 MB RAM
In a self-written test of 50 commands (25 safe, 25 risky), all safe commands ran without prompts and no risky command slipped through — though the author cautions this is a rough check and the plugin is not a sandbox. Install with pi install npm:pi-automode-classifier.
More from coding & agent
- The best part of her agent workflow: an AI-to-human handoff built into the prompt email — alliekmiller · 2026-10-08
- Two lawyers agreed on only 45% of 500 contract edits — how Crosby builds legal AI evals — graceisford · 2026-10-08
- She chained Instinct and Codex via email to autonomously execute a 19-item task list — alliekmiller · 2026-10-08
- Crosby's founding engineer explains how to build evals for non-verifiable legal reasoning — graceisford · 2026-10-08
- Code is the only workflow form agents can natively run and extend, not apps — _AustinCalvert_ · 2026-10-08
- GitHub adds settings to disable PRs entirely or restrict them to collaborators — jedisct1 · 2026-10-08