{"_id":"@anton-kochev/pithos.aegis","_rev":"2-b1a1f4973e89dea9bf79f2ea317dd9a0","name":"@anton-kochev/pithos.aegis","dist-tags":{"bootstrap":"0.0.0","latest":"0.1.0"},"versions":{"0.0.0":{"name":"@anton-kochev/pithos.aegis","version":"0.0.0","keywords":["pi-package","pi-extension","pithos","aegis","permissions","shell"],"license":"MIT","_id":"@anton-kochev/pithos.aegis@0.0.0","maintainers":[{"name":"anton-kochev","email":"anton.kochev@gmail.com"}],"homepage":"https://github.com/anton-kochev/pithos-kit#readme","bugs":{"url":"https://github.com/anton-kochev/pithos-kit/issues"},"pi":{"extensions":["./extensions"]},"dist":{"shasum":"7d354b4b1dfd313703545978bdba9684a0ad4507","tarball":"https://registry.npmjs.org/@anton-kochev/pithos.aegis/-/pithos.aegis-0.0.0.tgz","fileCount":3,"integrity":"sha512-YDV/YGoOqncfNb2w0IK9kMYx/usCeEOogGfdgK/i4j44+IcTpocyOmWhHnYUuX0ZveEH8MP3nXVEX903axxdbw==","signatures":[{"sig":"MEYCIQCM6x+zBuTyUKg28MRbWqAITrR0KwL+IYTb+RRATTNPHwIhAOeyhkRAWZFX3QktwaT0Nu2vvyTXC1JrLf7iVIsVZFsY","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":15873},"type":"module","scripts":{"test":"node --test test/*.test.ts"},"_npmUser":{"name":"anton-kochev","email":"anton.kochev@gmail.com"},"repository":{"url":"git+https://github.com/anton-kochev/pithos-kit.git","type":"git","directory":"pithos.aegis"},"_npmVersion":"10.9.2","description":"Protect Pi agent shell commands and file mutations with configurable block and confirmation rules.","directories":{},"_nodeVersion":"22.14.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"peerDependencies":{"@earendil-works/pi-coding-agent":"*"},"_npmOperationalInternal":{"tmp":"tmp/pithos.aegis_0.0.0_1786363685398_0.3478050234997243","host":"s3://npm-registry-packages-npm-production"}},"0.1.0":{"name":"@anton-kochev/pithos.aegis","version":"0.1.0","description":"Protect Pi agent shell commands and file mutations with configurable block and confirmation rules.","keywords":["pi-package","pi-extension","pithos","aegis","permissions","shell"],"license":"MIT","type":"module","repository":{"type":"git","url":"git+https://github.com/anton-kochev/pithos-kit.git","directory":"pithos.aegis"},"publishConfig":{"access":"public"},"scripts":{"test":"node --test test/*.test.ts"},"peerDependencies":{"@earendil-works/pi-coding-agent":"*"},"pi":{"extensions":["./extensions"]},"gitHead":"14e32cc67fc85c72b7588bf1c31b78361f1eaa8c","_id":"@anton-kochev/pithos.aegis@0.1.0","bugs":{"url":"https://github.com/anton-kochev/pithos-kit/issues"},"homepage":"https://github.com/anton-kochev/pithos-kit#readme","_nodeVersion":"24.18.0","_npmVersion":"12.0.2","dist":{"integrity":"sha512-efKuR6xXA4bTW2ylY12wSgfmo6q5nLEw8eIcnOw/74DYnAlaOidLe7SajPsYa3XR2xikvYuvigLN1DBU5ll8Tw==","shasum":"b44931f882f5e409727662f3a95bffdcd7093f68","tarball":"https://registry.npmjs.org/@anton-kochev/pithos.aegis/-/pithos.aegis-0.1.0.tgz","fileCount":3,"unpackedSize":15873,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@anton-kochev%2fpithos.aegis@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCO6P8gZigIeswHbGs5teKl0HI9g3xD+eueWah7gLqLuwIhAIlSQGzTVaCsu2oyvkoi+PbqH9WvGIVW6dch726/KPHY"}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:54da065e-b91f-4a0e-aca4-abd6b60f1577"}},"directories":{},"maintainers":[{"name":"anton-kochev","email":"anton.kochev@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/pithos.aegis_0.1.0_1786376307864_0.41691411036368864"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-10T12:08:05.244Z","modified":"2026-08-10T15:38:28.377Z","0.0.0":"2026-08-10T12:08:05.544Z","0.1.0":"2026-08-10T15:38:28.001Z"},"bugs":{"url":"https://github.com/anton-kochev/pithos-kit/issues"},"license":"MIT","homepage":"https://github.com/anton-kochev/pithos-kit#readme","keywords":["pi-package","pi-extension","pithos","aegis","permissions","shell"],"repository":{"type":"git","url":"git+https://github.com/anton-kochev/pithos-kit.git","directory":"pithos.aegis"},"description":"Protect Pi agent shell commands and file mutations with configurable block and confirmation rules.","maintainers":[{"name":"anton-kochev","email":"anton.kochev@gmail.com"}],"readme":"# Aegis\n\nProtect Pi agent shell commands and file mutations with configurable block and confirmation rules.\n\nAegis intercepts agent `bash`, `write`, and `edit` tool calls before they run. It has no command blacklist by default and one built-in protected path: editing `.pi/aegis.json` requires confirmation. Add project rules in `.pi/aegis.json`. For confirmation rules, **No** is the first/default option; any result other than selecting `Yes` blocks the operation.\n\nUser-entered `!` and `!!` shell commands are not protected because they already represent explicit user intent.\n\n## Install\n\n```bash\npi install npm:@anton-kochev/pithos.aegis\n```\n\nPin to a version:\n\n```bash\npi install npm:@anton-kochev/pithos.aegis@<version>\n```\n\nFor local development from a checkout of [`pithos-kit`](https://github.com/anton-kochev/pithos-kit):\n\n```bash\npi install ./pithos.aegis\n```\n\nProject-local install:\n\n```bash\npi install ./pithos.aegis -l\n```\n\nTemporary test run:\n\n```bash\npi -e ./pithos.aegis\n```\n\n## Pithos `.pithos` config\n\n```yaml\npi:\n  extensions:\n    \"@anton-kochev/pithos.aegis\": \"npm:0.1.0\"\n```\n\n## Default behavior\n\nThere are no built-in command blacklist rules. The only built-in protection rule requires confirmation before an agent `write` or `edit` operation changes `.pi/aegis.json`.\n\nWhen an agent operation matches a configured `confirm` rule, Aegis shows an interactive prompt with these options:\n\n```text\nNo\nYes\n```\n\nThe operation is allowed only when `Yes` is selected. `No`, Escape/cancel, or non-interactive modes block the operation.\n\n## Configuration\n\nCreate `.pi/aegis.json` in your project to add rules:\n\n```json\n{\n  \"commands\": [\n    {\n      \"name\": \"git push\",\n      \"pattern\": \"\\\\bgit\\\\s+push\\\\b\",\n      \"action\": \"confirm\"\n    },\n    {\n      \"name\": \"recursive remove\",\n      \"pattern\": \"\\\\brm\\\\s+(-rf|-fr|--recursive)\\\\b\",\n      \"action\": \"block\"\n    }\n  ],\n  \"paths\": [\n    {\n      \"name\": \"protect .pi\",\n      \"pattern\": \"(^|/)\\\\.pi(/|$)\",\n      \"action\": \"confirm\"\n    }\n  ]\n}\n```\n\nTop-level fields:\n\n- `commands`: rules matched against the full agent-run shell command for `bash` tool calls.\n- `paths`: rules matched against normalized project-relative paths for `write` and `edit` tool calls.\n- `rules`: an alternate field for command rules; entries are combined with `commands`.\n\nRule fields:\n\n- `name`: human-readable rule name shown in prompts and status output.\n- `pattern`: JavaScript regular expression string matched case-insensitively.\n  - Command patterns match the full shell command.\n  - Path patterns match normalized project-relative paths such as `.pi/settings.json`.\n- `action`: either:\n  - `confirm` — ask the user before allowing the operation; block when no UI is available.\n  - `block` — always block the operation.\n\nIf multiple rules match, `block` takes precedence over `confirm`. Invalid project configuration does not break the extension; Aegis reports warnings and continues with valid rules.\n\n## Commands\n\nInside Pi:\n\n```text\n/aegis status\n/aegis list\n/aegis reload\n/aegis toggle\n/aegis help\n```\n\n- `status` — show the config path, whether it was found, and the rule count.\n- `list` — show effective rules.\n- `reload` — reload `.pi/aegis.json` from disk.\n- `toggle` — enable or disable Aegis for the current Pi session; the state survives `/reload`.\n- `help` — show usage and a copy-paste example configuration.\n\n`/aegis` with no argument is the same as `/aegis status`.\n\nAegis is a clean-break identity: it does not register prior commands, read prior configuration paths, or restore prior session-state entries.\n\n## Development\n\n```bash\ncd pithos.aegis\nnpm test\nnpm pack --dry-run\n```\n\n## Notes\n\nThis package imports `@earendil-works/pi-coding-agent` as a peer dependency. Pi provides it at runtime; do not bundle it.\n","readmeFilename":"README.md"}