{"_id":"@burneikis/pi-nolo","_rev":"4-ddc570a53ac0bb7e057857d9467c245c","name":"@burneikis/pi-nolo","dist-tags":{"latest":"1.2.0"},"versions":{"1.0.0":{"name":"@burneikis/pi-nolo","version":"1.0.0","keywords":["pi-package"],"author":{"name":"burneikis"},"license":"MIT","_id":"@burneikis/pi-nolo@1.0.0","maintainers":[{"name":"burneikis","email":"alexburneikis@gmail.com"}],"homepage":"https://github.com/burneikis/pi-nolo#readme","bugs":{"url":"https://github.com/burneikis/pi-nolo/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"344a97bc92889911197dc2e37895451c6a98f781","tarball":"https://registry.npmjs.org/@burneikis/pi-nolo/-/pi-nolo-1.0.0.tgz","fileCount":4,"integrity":"sha512-EBbVBmtIECeZ0FTDrEC2DJucy3oNC4d3YJkQkJb1neiVu7f1ho/PXza/kealHJpVKvCDIbJs/Eu09+9oJnA3Iw==","signatures":[{"sig":"MEYCIQCjF2Kpt4++NtMEy3OoklhdhxeImYHTcFOSppKGuDDkdgIhAOusNkOfGvtnYQZ9cOprsezzdkvbCl8xnF3xRAvradDW","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":13967},"gitHead":"ec52cb2115845fed9353162f48bf862f91c29c35","_npmUser":{"name":"burneikis","email":"alexburneikis@gmail.com"},"repository":{"url":"git+https://github.com/burneikis/pi-nolo.git","type":"git"},"_npmVersion":"11.8.0","description":"No-YOLO mode for pi — gates write, edit, and bash tool calls behind user confirmation with configurable safe-command allowlists and YOLO override modes.","directories":{},"_nodeVersion":"22.22.0","_hasShrinkwrap":false,"peerDependencies":{"@mariozechner/pi-coding-agent":"*"},"_npmOperationalInternal":{"tmp":"tmp/pi-nolo_1.0.0_1774553215116_0.17175595023724033","host":"s3://npm-registry-packages-npm-production"},"deprecated":"moved to pi-nolo (rather than @burneikis/pi-nolo)"},"1.1.0":{"name":"@burneikis/pi-nolo","version":"1.1.0","keywords":["pi-package"],"author":{"name":"burneikis"},"license":"MIT","_id":"@burneikis/pi-nolo@1.1.0","maintainers":[{"name":"burneikis","email":"alexburneikis@gmail.com"}],"homepage":"https://github.com/burneikis/pi-nolo#readme","bugs":{"url":"https://github.com/burneikis/pi-nolo/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"a963de19260768f5e0b29e38c658dd92d9763707","tarball":"https://registry.npmjs.org/@burneikis/pi-nolo/-/pi-nolo-1.1.0.tgz","fileCount":12,"integrity":"sha512-DK0SCegJC2kYs7I/Lty9m2EXROKYZ1I6gdpHkVSJF7LoSclfyiTiuOO4ZYuRLrtwrHhfcxeMYt/+O+6gBgoMdA==","signatures":[{"sig":"MEYCIQDOQFuPjct14GsmA4dRteXcmA4/Gl2h47Tb0zHS6p2dNwIhAMv2Eyc/Qyt0sqAyVSiIaE9R8dBCoAXL0t2wMI17BkMS","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":62361},"gitHead":"2d9272ce053bf0d6b37a3684f3332d8c4ee440b3","scripts":{"test":"tsx --test tests/*.test.ts"},"_npmUser":{"name":"burneikis","email":"alexburneikis@gmail.com"},"repository":{"url":"git+https://github.com/burneikis/pi-nolo.git","type":"git"},"_npmVersion":"11.8.0","description":"No-YOLO mode for pi — gates write, edit, and bash tool calls behind user confirmation with configurable safe-command allowlists and YOLO override modes.","directories":{},"_nodeVersion":"22.22.0","dependencies":{"diff":"^8.0.4"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","@types/diff":"^7.0.2"},"peerDependencies":{"@mariozechner/pi-coding-agent":"*"},"_npmOperationalInternal":{"tmp":"tmp/pi-nolo_1.1.0_1775769446931_0.42209888622521197","host":"s3://npm-registry-packages-npm-production"},"deprecated":"moved to pi-nolo (rather than @burneikis/pi-nolo)"},"1.2.0":{"name":"@burneikis/pi-nolo","version":"1.2.0","keywords":["pi-package"],"author":{"name":"burneikis"},"license":"MIT","_id":"@burneikis/pi-nolo@1.2.0","maintainers":[{"name":"burneikis","email":"alexburneikis@gmail.com"}],"homepage":"https://github.com/burneikis/pi-nolo#readme","bugs":{"url":"https://github.com/burneikis/pi-nolo/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"e3dfc37d537b51e0f7b3e6e4ff81428ade04c2a8","tarball":"https://registry.npmjs.org/@burneikis/pi-nolo/-/pi-nolo-1.2.0.tgz","fileCount":12,"integrity":"sha512-rJswx/dt5JrjcVNiGlVoFnDdAt8R3HDt8LaMefjAYPJM6w5MOB0GprPe1GRpgrYE8vUBovACf7YM5FMh2kpMqw==","signatures":[{"sig":"MEUCIEPtYam6GaPQoF54PzrkL3NBWtY14Dfb9IdOxFzjYjIfAiEAk84AFjxWskhQO/6i/BFcNQxfFp+iepi59tnsfxMzr2o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":62384},"gitHead":"a7ae241f0bd37f9c30cae626069db955dab036e0","scripts":{"test":"tsx --test tests/*.test.ts"},"_npmUser":{"name":"burneikis","email":"alexburneikis@gmail.com"},"repository":{"url":"git+https://github.com/burneikis/pi-nolo.git","type":"git"},"_npmVersion":"11.8.0","description":"No-YOLO mode for pi — gates write, edit, and bash tool calls behind user confirmation with configurable safe-command allowlists and YOLO override modes.","directories":{},"_nodeVersion":"22.22.0","dependencies":{"diff":"^8.0.4"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","@types/diff":"^7.0.2"},"peerDependencies":{"@mariozechner/pi-coding-agent":"*"},"_npmOperationalInternal":{"tmp":"tmp/pi-nolo_1.2.0_1781814051245_0.3021716864195372","host":"s3://npm-registry-packages-npm-production"},"deprecated":"moved to pi-nolo (rather than @burneikis/pi-nolo)"}},"time":{"created":"2026-03-26T19:26:54.913Z","modified":"2026-06-18T20:24:21.265Z","1.0.0":"2026-03-26T19:26:55.242Z","1.1.0":"2026-04-09T21:17:27.079Z","1.2.0":"2026-06-18T20:20:51.367Z"},"bugs":{"url":"https://github.com/burneikis/pi-nolo/issues"},"author":{"name":"burneikis"},"license":"MIT","homepage":"https://github.com/burneikis/pi-nolo#readme","keywords":["pi-package"],"repository":{"url":"git+https://github.com/burneikis/pi-nolo.git","type":"git"},"description":"No-YOLO mode for pi — gates write, edit, and bash tool calls behind user confirmation with configurable safe-command allowlists and YOLO override modes.","maintainers":[{"name":"burneikis","email":"alexburneikis@gmail.com"}],"readme":"# pi-nolo\n\nNo-YOLO mode for [pi-coding-agent](https://github.com/nichochar/pi-mono). Gates `write`, `edit`, and `bash` tool calls behind user confirmation — press Enter to allow, Escape to block.\n\nRead-safe bash commands (`ls`, `grep`, `git status`, etc.) are auto-approved via a configurable allowlist, so you only get prompted for commands that could mutate state.\n\n## Install\n\n```bash\npi install npm:@burneikis/pi-nolo\n```\n\nOr from git:\n\n```bash\npi install https://github.com/burneikis/pi-nolo\n```\n\n### Note:\n\nThere will be a keybing conflict with `ctrl+y` for cycling yolo mode, and `tui.editor.yank`, so I recommend changing `~/.pi/agent/keybindings.json` to include `\"tui.editor.yank\": \"ctrl+shift+y\"`.\n\n## What it does\n\nEvery time the agent tries to:\n\n- **Write a file** — confirms with the file path and line count\n- **Edit a file** — confirms with the file path; shows a pre-rendered diff preview before the tool finishes executing\n- **Run a bash command** — auto-approves safe read-only commands; confirms everything else\n\nYou get a dialog: Enter to allow, Escape to block.\n\nIn non-interactive mode (no UI), all mutations are blocked by default.\n\n## Pre-rendered edit diffs\n\nAs of pi ~0.63.0, the built-in edit tool only shows diffs after execution. This extension includes a built-in pre-renderer (ported from [pi-pre-render-edit](https://github.com/burneikis/pi-pre-render-edit)) that computes and displays the diff as soon as the tool arguments are complete -- before the edit is applied. This means you can see exactly what will change while the confirmation dialog is open.\n\nIf you previously installed `pi-pre-render-edit` separately, you can remove it -- the functionality is now bundled here.\n\n## YOLO modes\n\nUse `/yolo` to cycle through three modes at any time during a session:\n\n| Mode            | Footer label | Write/Edit     | Bash                              |\n| --------------- | ------------ | -------------- | --------------------------------- |\n| `off` (default) | `nolo`       | confirm        | confirm (safe cmds auto-approved) |\n| `writes`        | `writes`     | **auto-allow** | confirm (safe cmds auto-approved) |\n| `full`          | `yolo`       | **auto-allow** | **auto-allow**                    |\n\nEach `/yolo` invocation advances to the next mode and wraps back around:\n\n```\noff → writes-yolo → full-yolo → off → …\n```\n\nThe current mode is shown in the footer status bar. It is also persisted in the session so it survives a `/reload`.\n\n### When to use each mode\n\n- **`writes`** — you trust the edits but still want a gate on shell commands.\n- **`full`** — you want the agent to run completely hands-free. Use with caution.\n\n## Bash Command Allowlist\n\nSafe commands are auto-approved without a confirmation dialog. A command is considered safe when:\n\n1. It starts with a recognized safe prefix (e.g., `ls`, `grep`, `git status`)\n2. It does **not** contain any dangerous patterns (pipes, chaining, redirects, etc.)\n\n### Default safe prefixes\n\n```\nls, cat, head, tail, wc, find, grep, rg, fd, tree,\nfile, stat, du, df, which, whoami, pwd, echo, date, uname,\nenv, printenv, git status, git log, git diff, git show,\ngit branch, git remote, git tag, git rev-parse,\nnpm list, npm outdated, npm view, node --version,\npython --version, cargo --version, rustc --version, go version\n```\n\n### Dangerous pattern guard\n\nEven if a command starts with a safe prefix, it will still require confirmation if it contains:\n\n- Pipes (`|`), chaining (`&&`, `||`, `;`)\n- Command substitution (`` ` ``, `$()`)\n- Redirections (`>`, `>>`)\n- Dangerous commands (`rm`, `sudo`, `eval`, `exec`, `source`, `sh`, `bash`)\n\nFor example, `ls` is auto-approved but `ls; rm -rf /` will prompt for confirmation.\n\n## Configuration\n\nYou can customize the allowlist with a `nolo.json` config file:\n\n- **Project-level:** `.pi/nolo.json` (takes precedence)\n- **Global:** `~/.pi/agent/nolo.json`\n\n### Config format\n\n```json\n{\n  \"safePrefixes\": [\"make build\", \"docker ps\", \"kubectl get\"],\n  \"dangerousPatterns\": [\"\\\\|\", \"&&\", \"\\\\brm\\\\b\"]\n}\n```\n\n### Merge behavior\n\n- **`safePrefixes`** — merged (union of defaults + global + project)\n- **`dangerousPatterns`** — overridden (project overrides global overrides defaults)\n\nIf no config files exist, the hardcoded defaults are used. See [`nolo.example.json`](nolo.example.json) for the full default configuration.\n\n### Example: add custom safe commands\n\nCreate `.pi/nolo.json` in your project:\n\n```json\n{\n  \"safePrefixes\": [\"make build\", \"docker ps\", \"kubectl get pods\"]\n}\n```\n\nThese will be added to the defaults — you don't need to re-list the built-in prefixes.\n\n### Example: relax dangerous patterns\n\nIf you want to allow piped commands (at your own risk):\n\n```json\n{\n  \"dangerousPatterns\": [\n    \"&&\",\n    \"\\\\|\\\\|\",\n    \";\",\n    \"`\",\n    \"\\\\$\\\\(\",\n    \">\\\\s\",\n    \">>\",\n    \"\\\\brm\\\\b\",\n    \"\\\\bsudo\\\\b\",\n    \"\\\\beval\\\\b\",\n    \"\\\\bexec\\\\b\"\n  ]\n}\n```\n\nThis replaces the defaults entirely, so the `\\\\|` (pipe) pattern is no longer checked.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}