{"_id":"@aneviaro/pi-safe-rm","name":"@aneviaro/pi-safe-rm","dist-tags":{"latest":"0.0.1"},"versions":{"0.0.1":{"name":"@aneviaro/pi-safe-rm","version":"0.0.1","description":"A Pi extension that validates recursive-force rm commands before execution.","type":"module","license":"MIT","engines":{"node":">=20"},"keywords":["pi-package","pi","pi-coding-agent","rm","safety"],"scripts":{"test":"node --import tsx --test","typecheck":"tsc --noEmit","pack:check":"npm pack --dry-run"},"pi":{"extensions":["./extensions/safe-rm.ts"]},"peerDependencies":{"@earendil-works/pi-coding-agent":"*","typebox":"*"},"peerDependenciesMeta":{"@earendil-works/pi-coding-agent":{"optional":true}},"devDependencies":{"@types/node":"^24.0.0","tsx":"^4.19.3","typebox":"^1.1.38","typescript":"^5.8.3"},"publishConfig":{"access":"public"},"gitHead":"10c05d58c886ebd7dca1028271933e08048593aa","_id":"@aneviaro/pi-safe-rm@0.0.1","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-HDLJb96d5nUKjhF9pDZ79hoG52feKF2eBquuXq/Se5lOtTamW9eEk1BkG2dga6+nJllbe1RJbwCJW27b0mZ1MA==","shasum":"6556a22caca103e0e0abcac5d1d71b85507c22ee","tarball":"https://registry.npmjs.org/@aneviaro/pi-safe-rm/-/pi-safe-rm-0.0.1.tgz","fileCount":4,"unpackedSize":40236,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDM/j+s6m8wes7yst1hKSY6+9qcC7s7CiMO4dwkp24tOAIgaiZK8ot257dA/7vpDhPvx0hQvXEDXIYg6yRBQEGilW8="}]},"_npmUser":{"name":"aneviaro","email":"aliaksandra.neviarouskaya@gmail.com"},"directories":{},"maintainers":[{"name":"aneviaro","email":"aliaksandra.neviarouskaya@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/pi-safe-rm_0.0.1_1788810158114_0.27103381109626357"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-07T19:42:37.903Z","0.0.1":"2026-09-07T19:42:38.282Z","modified":"2026-09-07T19:42:38.655Z"},"maintainers":[{"name":"aneviaro","email":"aliaksandra.neviarouskaya@gmail.com"}],"description":"A Pi extension that validates recursive-force rm commands before execution.","keywords":["pi-package","pi","pi-coding-agent","rm","safety"],"license":"MIT","readme":"# @aneviaro/pi-safe-rm\n\nPi extension that intercepts model-issued `bash` calls containing recursive-force `rm` commands (`rm -rf`, `rm -fr`, `rm --recursive --force`, etc.). The first call is blocked with no deletion. The model must call `validate_rm` using the provided request ID, inspect the deletion summary, then retry the exact same command once to approve execution.\n\n## Behavior\n\n- Blocks only model-issued `bash` tool calls; direct user `!`/`!!` shell commands are out of scope.\n- Requires both recursive and force behavior before guarding a command.\n- Binds approval to the exact command bytes, working directory, session, deletion snapshot, and a five-minute TTL.\n- Revalidates immediately before the retry and consumes the approval before the shell runs.\n- Rewrites approved invocations to concrete, safely quoted existing roots after `--`; missing literals and unmatched globs are omitted.\n- Permanently denies `/`, your home directory, the working directory, and any ancestor of the working directory.\n- Supports literal path operands and standard `*`, `?`, and bracket-expression globs.\n- Rejects dynamic targets such as variables, command substitution, process substitution, `eval`, `xargs rm -rf`, `find -exec rm -rf`, brace expansion, extglob, and unsupported nested shell rewrites.\n- Traverses with `lstat`, does not follow symlinks, reads no file contents, and fails closed above 10,000 discovered entries. An over-cap validation creates no approval and deletes no files; do not split the same directory tree into child deletion commands or manual batches.\n\n## Install\n\n```bash\npi install npm:@aneviaro/pi-safe-rm\n```\n\nFor local development from this repo:\n\n```bash\npi -e ./packages/safe-rm\n```\n\n## Important limitations\n\nThis reduces accidental deletion risk; it is not a security boundary against a malicious model with unrestricted shell access. Other deletion mechanisms (`find -delete`, language APIs, trash tools, external scripts) are intentionally not covered. A small residual race remains between final revalidation and process execution.\n\n## Development\n\n```bash\ncd packages/safe-rm\nnpm test\nnpm run typecheck\nnpm run pack:check\n```\n","readmeFilename":"README.md","_rev":"1-ddda4ccdb4d40ccc516cd057e7b0443d"}