{"_id":"@aizigao/pi-vibeguard","_rev":"2-52bd3ee7dd0b8ebf351d4e2491c2030d","name":"@aizigao/pi-vibeguard","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.1":{"name":"@aizigao/pi-vibeguard","version":"0.1.1","keywords":["pi-package","pi-extension","vibeguard"],"license":"MIT","_id":"@aizigao/pi-vibeguard@0.1.1","maintainers":[{"name":"aizigao","email":"weixiangzhe@live.com"}],"homepage":"https://github.com/aizigao/pi-vibeguard#readme","bugs":{"url":"https://github.com/aizigao/pi-vibeguard/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"a6ad0a85a44fab56fc170b9d543b435fa2494be1","tarball":"https://registry.npmjs.org/@aizigao/pi-vibeguard/-/pi-vibeguard-0.1.1.tgz","fileCount":4,"integrity":"sha512-JlMJoGHvc8PctmVtffa+RqnEENMzGzELD6S88KrOYPEfTIgVdRupfYcU9R3mL0bqUfTHZ9/QIkDvY5ylLTXJfA==","signatures":[{"sig":"MEQCIF6gNDUUzeXcatRiDQHwsbkUsrK9BkNfFAEI1M7+az4MAiBi9nW+F7BP/orKnDyzSjXEt14Qq3JrsQ89SPRABQ8o2w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":30134},"type":"module","engines":{"node":">=20"},"gitHead":"ac94b3448b0b076a032a018fb601509688eb03a6","scripts":{"lint":"eslint .","check":"tsc --noEmit","lint:fix":"eslint . --fix"},"_npmUser":{"name":"aizigao","email":"weixiangzhe@live.com"},"repository":{"url":"git+https://github.com/aizigao/pi-vibeguard.git","type":"git"},"_npmVersion":"10.9.4","description":"Pi extension that replaces sensitive strings with placeholders before LLM requests (inspired by VibeGuard).","directories":{},"_nodeVersion":"22.21.1","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.39.1","@eslint/js":"^9.39.1","typescript":"^5.9.3","@types/node":"^24.10.1","typescript-eslint":"^8.46.4","@earendil-works/pi-coding-agent":"*"},"peerDependencies":{"@earendil-works/pi-coding-agent":"*"},"_npmOperationalInternal":{"tmp":"tmp/pi-vibeguard_0.1.1_1779633189276_0.06594461265260443","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@aizigao/pi-vibeguard","version":"0.1.2","description":"Pi extension that replaces sensitive strings with placeholders before LLM requests (inspired by VibeGuard).","type":"module","license":"MIT","homepage":"https://github.com/aizigao/pi-vibeguard#readme","repository":{"type":"git","url":"git+https://github.com/aizigao/pi-vibeguard.git"},"bugs":{"url":"https://github.com/aizigao/pi-vibeguard/issues"},"keywords":["pi-package","pi-extension","vibeguard"],"engines":{"node":">=20"},"publishConfig":{"access":"public"},"scripts":{"check":"tsc --noEmit","lint":"eslint .","lint:fix":"eslint . --fix"},"pi":{"extensions":["./index.ts"]},"peerDependencies":{"@earendil-works/pi-coding-agent":"*"},"devDependencies":{"@earendil-works/pi-coding-agent":"*","@types/node":"^24.10.1","@eslint/js":"^9.39.1","eslint":"^9.39.1","typescript":"^5.9.3","typescript-eslint":"^8.46.4"},"_id":"@aizigao/pi-vibeguard@0.1.2","gitHead":"672121246907a60e646bb3d2e8a1940371f4c904","_nodeVersion":"22.21.1","_npmVersion":"10.9.4","dist":{"integrity":"sha512-T+ZszJlfebpnhzf42UAccRBZfyCXTazwGgD/KrZ1yx8W75ViuzNlDgjCT4aKLnUTTzglLCabLkNZNDXwkIZD3A==","shasum":"87f9f48ff593f05a1f424e030bfc6201c9856200","tarball":"https://registry.npmjs.org/@aizigao/pi-vibeguard/-/pi-vibeguard-0.1.2.tgz","fileCount":4,"unpackedSize":30134,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCogHZsjZZ+sUTiQFG/T1ekw58JsoVSWcp8v2+4whYkOgIgIGva0mDVDwKjsyav4pbrdii3dkgWYGkUEmy2WOcfxz0="}]},"_npmUser":{"name":"aizigao","email":"weixiangzhe@live.com"},"directories":{},"maintainers":[{"name":"aizigao","email":"weixiangzhe@live.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/pi-vibeguard_0.1.2_1780061541799_0.694420504888354"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-24T14:33:09.099Z","modified":"2026-05-29T13:32:22.036Z","0.1.1":"2026-05-24T14:33:09.428Z","0.1.2":"2026-05-29T13:32:21.929Z"},"bugs":{"url":"https://github.com/aizigao/pi-vibeguard/issues"},"license":"MIT","homepage":"https://github.com/aizigao/pi-vibeguard#readme","keywords":["pi-package","pi-extension","vibeguard"],"repository":{"type":"git","url":"git+https://github.com/aizigao/pi-vibeguard.git"},"description":"Pi extension that replaces sensitive strings with placeholders before LLM requests (inspired by VibeGuard).","maintainers":[{"name":"aizigao","email":"weixiangzhe@live.com"}],"readme":"# pi-vibeguard\n\n[English](README.md) | [中文](README-CN.md)\n\nInspired by [VibeGuard](https://github.com/inkdust2021/VibeGuard) and [opencode-vibeguard](https://github.com/inkdust2021/opencode-vibeguard).\n\nA pi extension that:\n\n- Replaces configured sensitive strings with placeholders **before requests are sent to the LLM provider** (the provider never sees plaintext)\n- Restores placeholders back to the original text **after the model output completes** (more natural local display/persistence)\n- Restores placeholders **before tool execution** (e.g. `bash` / `write` / `edit`) so local tools run with real values\n\nPlaceholder format (aligned with VibeGuard):\n\n- Prefix: `__VG_`\n- Shape: `__VG_<CATEGORY>_<hash12>__` or `__VG_<CATEGORY>_<hash12>_<N>__`\n- `hash12` is the first 12 hex chars of `HMAC-SHA256(session-random secret, original)`, stable within a session and irreversible to the provider\n\n## Install\n\n### Local (project)\n\n1. Copy `index.ts` to `.pi/extensions/vibeguard.ts`\n2. Put `vibeguard.config.json` in your project root\n3. Restart pi or run `/reload`\n\n### npm (global)\n\n```bash\npi install npm:@aizigao/pi-vibeguard\n```\n\n## Configuration\n\nConfig lookup order (first match wins):\n\n1. Path specified by env var `PI_VIBEGUARD_CONFIG`\n2. Project root: `./vibeguard.config.json`\n3. Project `.pi` dir: `./.pi/vibeguard.config.json`\n4. Global dir: `~/.pi/agent/vibeguard.config.json`\n\nSee `vibeguard.config.json.example` for a complete example.\n\n```jsonc\n{\n  \"enabled\": true,\n  \"debug\": false,\n  \"placeholder_prefix\": \"__VG_\",\n  \"session\": {\n    \"ttl\": \"1h\",\n    \"max_mappings\": 100000\n  },\n  \"patterns\": {\n    \"keywords\": [\n      { \"value\": \"my-api-key-123\", \"category\": \"API_KEY\" }\n    ],\n    \"regex\": [\n      { \"pattern\": \"sk-[A-Za-z0-9]{48}\", \"category\": \"OPENAI_KEY\" },\n      { \"pattern\": \"(ghp|gho|ghu|ghs|ghr)_[A-Za-z0-9]+\", \"category\": \"GITHUB_TOKEN\" },\n      { \"pattern\": \"AKIA[0-9A-Z]{16}\", \"category\": \"AWS_ACCESS_KEY\" }\n    ],\n    \"builtin\": [\"email\", \"china_phone\", \"china_id\", \"uuid\", \"ipv4\", \"mac\"],\n    \"exclude\": [\"example.com\", \"localhost\", \"127.0.0.1\", \"0.0.0.0\"]\n  }\n}\n```\n\n> Safety note: if the config file is missing or `enabled=false`, the extension becomes a no-op.\n\n## Behavior\n\nWhen a sensitive value is matched, it is replaced with a placeholder (e.g. `sk-a0d309c77dd44d57be0f1a675c0zzzzz`). The LLM only sees the placeholder and may echo it back.\n\nExample session:\n\n```\nUser: Echo this value back verbatim: sk-a0d309c77dd44d57be0f1a675c0zzzzz\n\nLLM:  sk-a0d309c77dd44d57be0f1a675c0zzzzz\n\nUser: Now output it as a character array\n\nLLM:  ['_', '_', 'V', 'G', '_', 'O', 'P', 'E', 'N', 'A', 'I', '_', 'K', \n       'E', 'Y', '_', 'c', '1', '1', '3', 'f', '0', '6', 'b', 'c',\n       '5', '0', 'a', '_', '_']\n```\n\nThe LLM provider **never receives the original value** — it only sees placeholders. The LLM's output also contains placeholders, which is expected and harmless.\n\n## Debug\n\nSet `PI_VIBEGUARD_DEBUG=1` environment variable or `\"debug\": true` in config.\n\n```bash\nPI_VIBEGUARD_DEBUG=1 pi\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md"}