{"_id":"@agenticcontrolplane/prime-agent","_rev":"2-3f4e107d5b01f4b4cb40fbaebcd7025c","name":"@agenticcontrolplane/prime-agent","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@agenticcontrolplane/prime-agent","version":"0.1.0","keywords":["prime-agent","prime-agent-extension","prime-intellect","agentic-control-plane","agent-security","tool-call-policy","coding-agent"],"license":"MIT","_id":"@agenticcontrolplane/prime-agent@0.1.0","maintainers":[{"name":"davidcrowe","email":"reducibl@gmail.com"}],"homepage":"https://agenticcontrolplane.com/controls/prime-agent","bugs":{"url":"https://github.com/agentic-control-plane/prime-agent-acp-plugin/issues"},"dist":{"shasum":"d597286d5a77c42108840dfb06a56471eb0dd453","tarball":"https://registry.npmjs.org/@agenticcontrolplane/prime-agent/-/prime-agent-0.1.0.tgz","fileCount":4,"integrity":"sha512-UQDW9S1I0M7XJAU8zmNuq9wEf5RgafBc45nU1oZccwHUmxJ9lpiNch8SFQ6tvZMwo3VFtA6Rxe6Q2kvOCV8LkA==","signatures":[{"sig":"MEUCIQDepxCQrYSFnfKv2a0b/dg7m5EIfg/xlJquvLxckyP6lgIgMdgCtTyEnNpDpR4Obhmv+UrkXTc8eOlMycgISBunaj0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":29413},"main":"index.ts","type":"module","types":"index.ts","gitHead":"5d477720ea3a9b1a279d7fd3c571b53a529a8967","scripts":{"test":"node --test test/*.test.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"davidcrowe","email":"reducibl@gmail.com"},"repository":{"url":"git+https://github.com/agentic-control-plane/prime-agent-acp-plugin.git","type":"git"},"_npmVersion":"11.19.0","description":"Agentic Control Plane for Prime Agent (PrimeIntellect-ai) — check every tool call against your policies before it runs, and keep a durable record of what was allowed and why.","directories":{},"_nodeVersion":"20.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.6.0","@types/node":"^22.0.0","@earendil-works/pi-coding-agent":">=0.84.0"},"peerDependencies":{"@earendil-works/pi-coding-agent":">=0.8.0"},"peerDependenciesMeta":{"@earendil-works/pi-coding-agent":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/prime-agent_0.1.0_1787769013191_0.9285586535253232","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"pi":{"extensions":["./dist/index.js"]},"_id":"@agenticcontrolplane/prime-agent@0.1.1","bugs":{"url":"https://github.com/agentic-control-plane/prime-agent-acp-plugin/issues"},"dist":{"shasum":"e3c3bfc4e6e0978167b2007cafeed4bbd8039473","tarball":"https://registry.npmjs.org/@agenticcontrolplane/prime-agent/-/prime-agent-0.1.1.tgz","fileCount":5,"integrity":"sha512-DJTG9X8qYYPqabndQPRsplQNCncaAYKasvSkGv/BBA1yvAva8JVa+Kw7nd0muNeYAmzaDigCrFZh6/8HAK8Ohg==","signatures":[{"sig":"MEUCIBN9PFkM7+LQ5JB/6p9ic8elnT1rU9VwH5PiSu5iQ3BxAiEAjQFohKqNW7/Fi0ey6bSwaD9cDbb7CoORO8stWQROIk8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDNQC2qJMyNpLX6n91qgTO3XDDKzDpKRJrfBewnFtoDwwIhAKN5PFWe2SRSLyZyl18xr6UZ/GMwAJW/gM2E8dF9IkQ3"}],"unpackedSize":34009},"main":"./dist/index.js","name":"@agenticcontrolplane/prime-agent","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"d1fc04a550d9dbbff8f9eea1489cad78826f3dd7","license":"MIT","scripts":{"test":"node --test test/*.test.ts","build":"tsc","clean":"rm -rf dist","prepack":"npm run clean && npm run build","typecheck":"tsc --noEmit"},"version":"0.1.1","_npmUser":{"name":"davidcrowe","email":"reducibl@gmail.com"},"homepage":"https://agenticcontrolplane.com/controls/prime-agent","keywords":["prime-agent","prime-agent-extension","prime-intellect","agentic-control-plane","agent-security","tool-call-policy","coding-agent"],"repository":{"url":"git+https://github.com/agentic-control-plane/prime-agent-acp-plugin.git","type":"git"},"_npmVersion":"10.9.8","description":"Agentic Control Plane for Prime Agent (PrimeIntellect-ai) — check every tool call against your policies before it runs, and keep a durable record of what was allowed and why.","directories":{},"maintainers":[{"name":"davidcrowe","email":"reducibl@gmail.com"}],"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.6.0","@types/node":"^22.0.0","@earendil-works/pi-coding-agent":">=0.84.0"},"peerDependencies":{"@earendil-works/pi-coding-agent":">=0.8.0"},"peerDependenciesMeta":{"@earendil-works/pi-coding-agent":{"optional":true}},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/prime-agent_0.1.1_1789605934347_0.40516458240625286"}}},"time":{"created":"2026-08-26T18:30:12.989Z","modified":"2026-09-17T00:45:34.657Z","0.1.0":"2026-08-26T18:30:13.319Z","0.1.1":"2026-09-17T00:45:34.440Z"},"bugs":{"url":"https://github.com/agentic-control-plane/prime-agent-acp-plugin/issues"},"license":"MIT","homepage":"https://agenticcontrolplane.com/controls/prime-agent","keywords":["prime-agent","prime-agent-extension","prime-intellect","agentic-control-plane","agent-security","tool-call-policy","coding-agent"],"repository":{"url":"git+https://github.com/agentic-control-plane/prime-agent-acp-plugin.git","type":"git"},"description":"Agentic Control Plane for Prime Agent (PrimeIntellect-ai) — check every tool call against your policies before it runs, and keep a durable record of what was allowed and why.","maintainers":[{"name":"davidcrowe","email":"reducibl@gmail.com"}],"readme":"# @agenticcontrolplane/prime-agent\n\n[![tests](https://img.shields.io/badge/tests-18%20passing-brightgreen)](#test) [![license](https://img.shields.io/badge/license-MIT-blue)](./LICENSE)\n\n[Agentic Control Plane](https://agenticcontrolplane.com) for [Prime Agent](https://github.com/PrimeIntellect-ai/prime-agent): every tool call is checked against your policies before it runs, and every decision is recorded — what ran, what was blocked, and why.\n\nPrime Agent ships one model-facing tool (`ipython` — code **is** the action), long-running autonomous sessions, and [no built-in permission framework](https://agenticcontrolplane.com/controls/prime-agent) — its own docs list the permission gate as the canonical extension to write. This extension is that extension, backed by a workspace policy plane instead of a hardcoded list:\n\n```\n┌─ ipython / custom & extension tools ────────┐\n│                                             │\n│   tool_call  ──►  allow · ask · deny        │   your policy, before the code runs\n│   tool_result ─►  audit · redact · block    │   DLP + the record, after\n└─────────────────────────────────────────────┘\n```\n\nBecause Prime Agent is a hard fork of pi-mono that kept pi's typed extension API, this is the [pi extension](https://github.com/agentic-control-plane/pi-acp-plugin) retargeted at Prime Agent's paths and posture — same events, same decision mapping, plus two Prime-specific fixes (below).\n\n## Install\n\n```sh\ncurl -sf https://agenticcontrolplane.com/install.sh | bash\n```\n\nThat detects Prime Agent, drops this extension at `~/.prime/agent/extensions/acp.ts`, opens your browser once to sign in, and saves the key to `~/.acp/credentials` — which the extension reads on its own. There is no token to copy and nothing to export.\n\n<details>\n<summary>Manual install</summary>\n\nDrop `index.ts` into the global extensions directory as `acp.ts`:\n\n```sh\nmkdir -p ~/.prime/agent/extensions\ncurl -sf https://raw.githubusercontent.com/agentic-control-plane/prime-agent-acp-plugin/main/index.ts \\\n  -o ~/.prime/agent/extensions/acp.ts\n```\n\nGet a key at [cloud.agenticcontrolplane.com](https://cloud.agenticcontrolplane.com) and save it to `~/.acp/credentials`, or set `ACP_BEARER_TOKEN`. Restart Prime Agent (`/reload` also works).\n\nConfirm it loaded — the first governed call shows up in your [activity log](https://cloud.agenticcontrolplane.com/logs), and every session ends with a one-line `[ACP] Session receipt`.\n\n</details>\n\nThe extension imports only a **type** from Prime Agent (erased at runtime) and Node built-ins — zero dependencies, no build step. It runs as-is the moment Prime Agent discovers it.\n\n## How it works\n\nPrime Agent dispatches every tool through two typed events, and this extension registers on both:\n\n| event | ACP endpoint | What happens |\n|---|---|---|\n| `tool_call` | `POST /govern/tool-use` | Server returns `allow` / `ask` / `deny`. Deny blocks the call with the reason in the transcript; ask prompts you (see below). |\n| `tool_result` | `POST /govern/tool-output` | Output scanning. A server block turns the result into corrective feedback; a redact replaces the content the model reads. |\n\nCoverage is complete because Prime Agent routes everything through these events: `ipython` (its sole built-in model-facing tool — shell, files, and Python all run as code in the persistent kernel) and any custom or extension-registered tool. MCP integrations arrive as Python skills, which execute *inside* ipython — so they're covered too, not a second path.\n\n## Approvals and the empty chair\n\n- **Attended** (interactive TUI, RPC hosts with a working UI): an `ask` decision prompts you inline via Prime Agent's own confirm dialog. Approve and the call proceeds; decline and it's blocked.\n- **Unattended** (`-p` / `--print`, `--mode json`): an `ask` becomes a **deny** — an agent with nobody watching cannot self-approve, and the request is surfaced in the console for later review. No timeouts, no hangs, no silent auto-yes.\n\n**Prime-specific fix:** Prime Agent 0.8.x reports `ctx.hasUI = true` even in headless print mode (its docs say false; the runtime disagrees — verified against 0.8.1). Worse, *every* CLI session — TUI and `-p` alike — runs inside a daemon worker process, where `hasUI` can't distinguish an attached human from an empty chair. This extension resolves attendance in two layers:\n\n- **The prompt is the probe.** An `ask` always attempts Prime Agent's confirm dialog: an attached TUI client gets a real prompt; the headless no-op UI cannot approve, so the ask resolves to deny. Verified live: an `ask` in `-p` mode ends as `Denied at approval prompt` and the code never runs.\n- **Conservative tier.** Worker processes (`PRIME_AGENT_INTERNAL_DAEMON_WORKER=1` / `--mode daemon`) and headless argv (`-p`, `--print`, `--mode json`) are labeled `background` unless `ACP_AGENT_TIER` overrides — a mislabel toward stricter policy is answerable at the prompt; a mislabel toward `interactive` would fail open with nobody watching.\n\n## Failure posture\n\nAn outage of the control plane must not brick the harness, and a lapse in coverage must never be silent:\n\n- **Provably attended sessions fail open, loudly.** Gateway unreachable → the call proceeds, a `[ACP] ⚠ UNGOVERNED` warning is shown, and a line lands in `~/.acp/lapse.log`.\n- **Ambiguous worker sessions get the confirm-probe.** Gateway unreachable inside a daemon worker → a real TUI user is asked *\"proceed ungoverned?\"* (never bricked, and loud by construction); the headless no-op UI can't say yes, so the empty chair fails closed.\n- **Unattended runs fail closed.** With nobody watching, the block is the safety net — that includes Prime Agent's `/autonomous` mode and daemon-scheduled sessions, which is exactly where you want it.\n- Policy denies are unaffected — this posture only covers the inability to *ask* the policy. One transport retry precedes the fail posture, because the slow answers are cold starts.\n\n## Configuration\n\nEnvironment variables (all optional):\n\n| Variable | Default | Purpose |\n|---|---|---|\n| `ACP_BEARER_TOKEN` | `~/.acp/credentials` | Workspace key. |\n| `ACP_GOVERN_BASE` | `https://govern.agenticcontrolplane.com` | Gateway, or your self-hosted one. |\n| `ACP_AGENT_TIER` | attended ? `interactive` : `background` | Override the attended/unattended tier. |\n| `ACP_SHADOW` | on | `off` silences shadow-mode counterfactual notices. |\n\nNo key? The extension says so loudly at session start and stays out of the way — it never bricks a session.\n\n## Add the cost X-ray\n\nPrime Agent's model calls can route through the ACP proxy for metering via its provider-override seam — a one-file extension:\n\n```ts\n// ~/.prime/agent/extensions/acp-proxy.ts\nimport type { ExtensionAPI } from \"@earendil-works/pi-coding-agent\";\nexport default function (pi: ExtensionAPI) {\n  pi.registerProvider(\"anthropic\", { baseUrl: \"https://api.agenticcontrolplane.com/v1\" });\n}\n```\n\nThe proxy is multi-provider (routes `gpt-*`, `claude-*`, `gemini-*` by model id) and forwards unchanged — same responses, now metered, joined to the tool-audit rows for the same session.\n\n## Three things to know\n\n- Prime Agent requires **Node 22.8+** and enforces it with a clear error (use `fnm`/`nvm`).\n- Only the **global** directory (`~/.prime/agent/extensions/`) loads without a project-trust prompt; the installer uses it so governance is on before any repo is opened.\n- Prime Agent runs a **resident daemon** (supervisor + session workers, sockets under `$TMPDIR/prime-agent-<uid>/`). Extensions load per worker, so `/reload` or a fresh session picks up changes. If you `kill -9` workers while testing, clear that socket dir — a stale socket hangs the next CLI start.\n\n## Learn more\n\n- [What ACP can see and control in Prime Agent](https://agenticcontrolplane.com/controls/prime-agent) — the living controls reference\n- [Which coding agent has the best native controls?](https://agenticcontrolplane.com/controls) — the cross-harness comparison\n- [The pi extension](https://github.com/agentic-control-plane/pi-acp-plugin) — the upstream sibling of this plugin\n\n## Test\n\n```sh\nnpm test        # 18 tests: decision mapping, fail posture, empty chair (argv + worker detection), receipt\nnpm run typecheck\nnpm run build   # emits dist/ (JS + .d.ts); prepack runs this from clean\n```\n\nMIT\n","readmeFilename":"README.md"}