← Back to context

Comment by imtringued

7 hours ago

The developers of pi.dev are geniuses.

They add a --tools flag, which can only add tools onto the built-in tools, so if you wanted to sandbox pi.dev by adding sandboxed versions of the existing tools you will have to run pi.dev via

    pi --no-tools --tools tool1, tool2, tool3

except..., that's not enough to sandbox pi.dev, because remember, it's a minimalist coding agent! So what does a minimalist coding agent do? Of course! It loads extensions by default and do you know what extensions can do? they can add default tools that bypass --no-tools!

So if you want to sandbox your agent, guess what you'll have to do? Yep, you have to supply --no-extensions.

Here is how to run pi.dev under its most minimal configuration under a sandbox:

    pi --no-tools --no-extensions --tools tool1, tool2, tool3 -e ./your-sandboxing-extension

Pretty neat, huh?

Sources: https://github.com/earendil-works/pi/issues/555