{"_id":"@diegopetrucci/pi-web-access","_rev":"5-3addd0c1370360eb9da2e26ffa876f9d","name":"@diegopetrucci/pi-web-access","dist-tags":{"latest":"0.29.2"},"versions":{"0.10.8":{"name":"@diegopetrucci/pi-web-access","version":"0.10.8","keywords":["pi-package","pi","pi-coding-agent","extension","web-search","perplexity","fetch","scraping"],"author":{"name":"Nico Bailon"},"license":"MIT","_id":"@diegopetrucci/pi-web-access@0.10.8","maintainers":[{"name":"diegopetrucci","email":"baulei@icloud.com"}],"homepage":"https://github.com/diegopetrucci/pi-web-access#readme","bugs":{"url":"https://github.com/diegopetrucci/pi-web-access/issues"},"pi":{"video":"https://github.com/diegopetrucci/pi-web-access/raw/refs/heads/main/pi-web-fetch-demo.mp4","skills":["./skills"],"extensions":["./index.ts"]},"dist":{"shasum":"db3836e9f268666adcd362b17920c25d4fb0fc8c","tarball":"https://registry.npmjs.org/@diegopetrucci/pi-web-access/-/pi-web-access-0.10.8.tgz","fileCount":30,"integrity":"sha512-qzkUiyocK78th5jK1xbxMmqdJcEoPUj/eVsSZ2y1C7V6PsRJkLXJYH7xEnsoRiPMrGI2AADTVo+pZwld3lCYEA==","signatures":[{"sig":"MEUCIQCybLgi3gtR2icCsFWNnx4CxjDx+3xKfIAhc5ZfdW6OAwIgHmThGzz3q+5us5+40zkW7mb3jJk5cTClnAi4jtSOeBs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6848463},"type":"module","gitHead":"0d5e2f99e27d9a5687ab66714761d235b610cdbf","scripts":{"test":"node --test"},"_npmUser":{"name":"diegopetrucci","email":"baulei@icloud.com"},"repository":{"url":"git+https://github.com/diegopetrucci/pi-web-access.git","type":"git"},"_npmVersion":"11.17.0","description":"Web search, URL fetching, GitHub repo cloning, PDF extraction, YouTube video understanding, and local video analysis for Pi coding agent","directories":{},"_nodeVersion":"26.4.0","dependencies":{"unpdf":"^1.6.2","p-limit":"^6.1.0","linkedom":"^0.16.0","turndown":"^7.2.0","@mozilla/readability":"^0.5.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/pi-web-access_0.10.8_1782806252399_0.35518767964969467","host":"s3://npm-registry-packages-npm-production"}},"0.10.9":{"name":"@diegopetrucci/pi-web-access","version":"0.10.9","keywords":["pi-package","pi","pi-coding-agent","extension","web-search","perplexity","fetch","scraping"],"author":{"name":"Nico Bailon"},"license":"MIT","_id":"@diegopetrucci/pi-web-access@0.10.9","maintainers":[{"name":"diegopetrucci","email":"baulei@icloud.com"}],"homepage":"https://github.com/diegopetrucci/pi-web-access#readme","bugs":{"url":"https://github.com/diegopetrucci/pi-web-access/issues"},"pi":{"video":"https://github.com/diegopetrucci/pi-web-access/raw/refs/heads/main/pi-web-fetch-demo.mp4","skills":["./skills"],"extensions":["./index.ts"]},"dist":{"shasum":"6cc6a4ff008c626bbd3a722007bf30d209184ad7","tarball":"https://registry.npmjs.org/@diegopetrucci/pi-web-access/-/pi-web-access-0.10.9.tgz","fileCount":30,"integrity":"sha512-lwesETYHr7dnmARsranmwZdzeg9Z48nrnz4L/UmR8NZHghI2omQ2kNswQPMz6j/t6LVXgt5QGJHz1BPiF0IPpQ==","signatures":[{"sig":"MEUCIQDH+U0AFrR4iGaZCOlVxrIPC4byn6PuthO/j48r94LS/gIgJiTZnL77AF70DHlSP8RN/tLk56N9SKKsoBZzUBBbFb4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6855452},"type":"module","gitHead":"a6fa3904e63672b2854e796d851bf2010be81f61","scripts":{"test":"node --test"},"_npmUser":{"name":"diegopetrucci","email":"baulei@icloud.com"},"repository":{"url":"git+https://github.com/diegopetrucci/pi-web-access.git","type":"git"},"_npmVersion":"11.17.0","description":"Web search, URL fetching, GitHub repo cloning, PDF extraction, YouTube video understanding, and local video analysis for Pi coding agent","directories":{},"_nodeVersion":"26.4.0","dependencies":{"unpdf":"^1.6.2","p-limit":"^6.1.0","linkedom":"^0.16.0","turndown":"^7.2.0","@mozilla/readability":"^0.5.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/pi-web-access_0.10.9_1783115798421_0.9538068479921675","host":"s3://npm-registry-packages-npm-production"}},"0.10.10":{"name":"@diegopetrucci/pi-web-access","version":"0.10.10","keywords":["pi-package","pi","pi-coding-agent","extension","web-search","perplexity","fetch","scraping"],"author":{"name":"Nico Bailon"},"license":"MIT","_id":"@diegopetrucci/pi-web-access@0.10.10","maintainers":[{"name":"diegopetrucci","email":"baulei@icloud.com"}],"homepage":"https://github.com/diegopetrucci/pi-web-access#readme","bugs":{"url":"https://github.com/diegopetrucci/pi-web-access/issues"},"pi":{"video":"https://github.com/diegopetrucci/pi-web-access/raw/refs/heads/main/pi-web-fetch-demo.mp4","skills":["./skills"],"extensions":["./index.ts"]},"dist":{"shasum":"1f3ba37693da083a6e67610cefce5ab4349cec78","tarball":"https://registry.npmjs.org/@diegopetrucci/pi-web-access/-/pi-web-access-0.10.10.tgz","fileCount":30,"integrity":"sha512-clPT+9yrB9YERH4dvgTsYFdMviu2ciKu6po3Ue5oVI61gw1bMgsdPX9fAdKahzKM+GpEKmczKzlS/lYcMLfzAw==","signatures":[{"sig":"MEYCIQCORq5KQRs8kWMkHVIohPaiJD+4oFfm4XYAPP51WihqSQIhAKkG8XLctd0qWYSLN5KDdILXB+wwSlesy4HWoHxoO6YS","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":6856879},"type":"module","gitHead":"8ed0c19f40f91a2df3dea91a915a6d60eba40ba9","scripts":{"test":"node --test"},"_npmUser":{"name":"diegopetrucci","email":"baulei@icloud.com"},"repository":{"url":"git+https://github.com/diegopetrucci/pi-web-access.git","type":"git"},"_npmVersion":"11.17.0","description":"Web search, URL fetching, GitHub repo cloning, PDF extraction, YouTube video understanding, and local video analysis for Pi coding agent","directories":{},"_nodeVersion":"26.4.0","dependencies":{"unpdf":"^1.6.2","p-limit":"^6.1.0","linkedom":"^0.16.0","turndown":"^7.2.0","@mozilla/readability":"^0.5.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/pi-web-access_0.10.10_1783451067875_0.5668177963259766","host":"s3://npm-registry-packages-npm-production"}},"0.29.1":{"name":"@diegopetrucci/pi-web-access","version":"0.29.1","keywords":["pi-package","pi","pi-coding-agent","extension","web-search","fetch","scraping"],"author":{"name":"Nico Bailon"},"license":"MIT","_id":"@diegopetrucci/pi-web-access@0.29.1","maintainers":[{"name":"diegopetrucci","email":"baulei@icloud.com"}],"homepage":"https://github.com/diegopetrucci/pi-web-access#readme","bugs":{"url":"https://github.com/diegopetrucci/pi-web-access/issues"},"pi":{"extensions":["./index.ts"]},"dist":{"shasum":"2a31c1cd7857804807c14a1261a926ef9998b268","tarball":"https://registry.npmjs.org/@diegopetrucci/pi-web-access/-/pi-web-access-0.29.1.tgz","fileCount":17,"integrity":"sha512-xyJngVMdddaURPrGjRde9gRUhud1GN7SzcGMD8YPhesMRFb05dQ4B6x3aJlmsBGMv8crqFWqvQTg6eguvtsu/Q==","signatures":[{"sig":"MEYCIQDtHvaU6UQc1NmXAwu+4W2yMgyNtWGOxTC5IeoGChI8ZgIhANC0Tn2c02DCGwAv+XBoaNm/ognM2qzbQv2M1mU/G8jM","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIFcd3/Xq3lSkP0HaKEXSMoc6GCqhQLUzX0xdEX4EPVItAiB/DwpBXIhewmkvXY5vegpZqXJnaXcu5yywQ0OhIbmH9w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@diegopetrucci%2fpi-web-access@0.29.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":209102},"type":"module","engines":{"node":">=22.19.0"},"gitHead":"507362577708be408e5111807c2c99640f1ec625","scripts":{"test":"node --test","typecheck":"tsc","audit:runtime":"npm audit --omit=dev","package:check":"node --test test/package-shape.test.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:6ed7fe00-2ecd-44ac-8f64-ac6ccaad1e5c"}},"repository":{"url":"git+https://github.com/diegopetrucci/pi-web-access.git","type":"git"},"_npmVersion":"11.19.0","description":"Web search and URL fetching for the tlh coding agent (Exa provider)","directories":{},"_nodeVersion":"24.21.0","dependencies":{"undici":"^8.9.0","p-limit":"^6.1.0","typebox":"^1.1.38","defuddle":"0.19.3","linkedom":"^0.16.0","turndown":"^7.2.0","@mozilla/readability":"^0.6.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^7.0.2","@types/turndown":"^5.0.6","@earendil-works/pi-ai":"0.86.1","@earendil-works/pi-tui":"0.86.1","@earendil-works/pi-coding-agent":"0.86.1"},"_npmOperationalInternal":{"tmp":"tmp/pi-web-access_0.29.1_1790144841456_0.6551231543895466","host":"s3://npm-registry-packages-npm-production"}},"0.29.2":{"pi":{"extensions":["./index.ts"]},"_id":"@diegopetrucci/pi-web-access@0.29.2","bugs":{"url":"https://github.com/diegopetrucci/pi-web-access/issues"},"dist":{"shasum":"3d72261f7e19a9472ea3a925a5f3f56c1850c7de","tarball":"https://registry.npmjs.org/@diegopetrucci/pi-web-access/-/pi-web-access-0.29.2.tgz","fileCount":18,"integrity":"sha512-OBp5u19I6xXi4k/lLEp536Wad/pXFX4gXMeoPixzx7jtUDkV2DsEtNtH4uJUZUcMPHAkau5YifGKS1GDNX4ImQ==","signatures":[{"sig":"MEUCIHyCpiCCx/WHkMKUgadd0Ditpj46L3sAVXmFmfDjQKdWAiEAxiNn1dp/IKWiS4F5uW5+LtYEUppisDT1ddRWkf9SwQg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDmY43oG86WKIpqN2vPT0ZsQ28f3PgzYvU6nim1hr6tSwIgcHFsRK0/l0bNW2zXI+5tGYEvmanz6vN9hy1xtvCKqL8="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@diegopetrucci%2fpi-web-access@0.29.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":213423},"name":"@diegopetrucci/pi-web-access","type":"module","author":{"name":"Nico Bailon"},"engines":{"node":">=22.19.0"},"gitHead":"527a626eb93c8e1e50a1d150a547adf186e5e773","license":"MIT","scripts":{"test":"node --test","typecheck":"tsc","audit:runtime":"npm audit --omit=dev","package:check":"node --test test/package-shape.test.mjs"},"version":"0.29.2","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"6ed7fe00-2ecd-44ac-8f64-ac6ccaad1e5c"}},"homepage":"https://github.com/diegopetrucci/pi-web-access#readme","keywords":["pi-package","pi","pi-coding-agent","extension","web-search","fetch","scraping"],"repository":{"url":"git+https://github.com/diegopetrucci/pi-web-access.git","type":"git"},"_npmVersion":"11.19.0","description":"Web search and URL fetching for the tlh coding agent (Exa provider)","directories":{},"maintainers":[{"name":"diegopetrucci","email":"baulei@icloud.com"}],"_nodeVersion":"24.21.0","dependencies":{"undici":"^8.11.2","p-limit":"^6.1.0","defuddle":"0.19.3","linkedom":"^0.16.0","turndown":"^7.2.0","@mozilla/readability":"^0.6.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typebox":"1.3.27","typescript":"^7.0.2","@types/turndown":"^5.0.6","@earendil-works/pi-ai":"0.86.1","@earendil-works/pi-tui":"0.86.1","@earendil-works/pi-coding-agent":"0.86.1"},"peerDependencies":{"typebox":"*"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/pi-web-access_0.29.2_1790971959362_0.9201183165533229"}}},"time":{"created":"2026-06-30T07:57:32.275Z","modified":"2026-10-02T20:12:39.751Z","0.10.8":"2026-06-30T07:57:32.629Z","0.10.9":"2026-07-03T21:56:38.702Z","0.10.10":"2026-07-07T19:04:28.170Z","0.29.1":"2026-09-23T06:27:21.556Z","0.29.2":"2026-10-02T20:12:39.443Z"},"bugs":{"url":"https://github.com/diegopetrucci/pi-web-access/issues"},"author":{"name":"Nico Bailon"},"license":"MIT","homepage":"https://github.com/diegopetrucci/pi-web-access#readme","keywords":["pi-package","pi","pi-coding-agent","extension","web-search","fetch","scraping"],"repository":{"url":"git+https://github.com/diegopetrucci/pi-web-access.git","type":"git"},"description":"Web search and URL fetching for the tlh coding agent (Exa provider)","maintainers":[{"name":"diegopetrucci","email":"baulei@icloud.com"}],"readme":"# The Last Harness Web Access\n\n`@diegopetrucci/pi-web-access@0.29.2` is a **The Last Harness (tlh)** selective fork for the compatible upstream Pi coding-agent runtime. It is a security and token-efficiency port based on upstream `nicobailon/pi-web-access@192ac18` (the upstream v0.29.0 release-preparation commit). It is **not** feature parity with upstream v0.29.0.\n\nOnly Exa search and bounded local URL extraction are included. The package registers exactly three tools, requires an isolated `PI_CODING_AGENT_DIR`, and does not provide the broader upstream provider, media, repository, browser-cookie, curator, or summary workflows.\n\n## Install\n\nIn the compatible upstream Pi coding-agent runtime:\n\n```bash\npi install npm:@diegopetrucci/pi-web-access@0.29.2\n```\n\nRequires Node.js **>=22.19.0**. Set an absolute profile path before using any tool:\n\n```bash\nexport PI_CODING_AGENT_DIR=/absolute/path/to/tlh-profile\n```\n\nThe variable is mandatory. There is no fallback to `~/.pi`, `XDG_CONFIG_HOME`, or a legacy profile path.\n\n### Host compatibility\n\nThe package declares `typebox` as a host-provided peer (`*`) so the compatible host loader can alias it to the host's own runtime module. The exact `typebox@1.3.27` entry is development-only for reproducible typechecking; it is not bundled or installed as a private runtime copy. The direct `undici` dependency requires `8.11.2` or newer.\n\n## Tools\n\n### `web_search`\n\nSearches Exa and returns bounded source titles and URLs. Provider snippets are stored for explicit `get_search_content` retrieval when a response ID is provided. It accepts one `query` or up to four `queries`, returns 1–10 results per query (default 5), and supports `recencyFilter` (`day`, `week`, `month`, or `year`) and hostname `domainFilter`. Search output is capped at 16,000 characters. It never performs automatic page fetching or hidden model calls.\n\n### `fetch_content`\n\nFetches up to six `http://` or `https://` URLs and extracts readable Markdown locally. It supports only the `url` and `urls` parameters. Git repositories, PDFs, images, audio/video, local files, browser cookies, and hosted extraction services are not special-cased or included.\n\n### `get_search_content`\n\nRetrieves stored search or fetch material using a `responseId` and a query/URL selector. For a stored fetch with one URL, `url` and `urlIndex` may be omitted; multiple stored URLs still require an explicit selector. It supports bounded, line-aware continuation with `offset` and `limit`, or one case-insensitive literal `findText` match. A response ID is exposed only when stored material was omitted or truncated from the preceding tool result.\n\n## Isolated settings and cache\n\nThe only supported settings file is:\n\n```text\n$PI_CODING_AGENT_DIR/extensions/pi-web-access/settings.json\n```\n\nThe only supported fetched-content cache is:\n\n```text\n$PI_CODING_AGENT_DIR/cache/pi-web-access/\n```\n\nThe settings file is optional; the absolute `PI_CODING_AGENT_DIR` is not. Settings are read for each request. Supported settings are exactly:\n\n```json\n{\n  \"exaApiKey\": \"exa-...\",\n  \"fetch\": {\n    \"timeout\": 30\n  },\n  \"fetchContent\": {\n    \"domainPolicy\": {\n      \"allow\": [\"docs.example.com\"],\n      \"deny\": [\"private.example.com\"]\n    }\n  },\n  \"maxInlineContentChars\": 12000\n}\n```\n\n- `exaApiKey` is a non-empty Exa API key. Precedence is isolated `exaApiKey`, then `EXA_API_KEY`, then keyless Exa MCP. An empty setting falls through to the environment; invalid values fail closed.\n- `fetch.timeout` is an integer number of seconds from 1 through 120; the default is 30. It is the outbound request and extraction timeout.\n- `fetchContent.domainPolicy` contains optional hostname arrays `allow` and `deny`. An `allow` list restricts fetches to matching domains; `deny` wins, and subdomains match. Wildcards are not accepted. This policy applies to `fetch_content`, not Exa's fixed provider endpoints.\n- `maxInlineContentChars` is an integer from 512 through 30,000; the default is 12,000. It bounds inline fetch and retrieval pages.\n\nNo other configuration keys, custom provider endpoints, credential commands, or proxy settings are supported.\n\n## Provider and network behavior\n\nWith a key, `web_search` sends bounded search requests to Exa's fixed `https://api.exa.ai/search` endpoint. Without a key, it sends JSON-RPC search requests to `https://mcp.exa.ai/mcp` without credentials. Keyless MCP still requires outbound network access; it is not an offline mode. The implementation does not use Exa `/answer`, other providers, automatic content retrieval, or local usage accounting.\n\n`HTTP_PROXY`, `HTTPS_PROXY`, `ALL_PROXY`, and `NO_PROXY` are not interpreted. There is no proxy or environment-proxy support. Requests use direct transport through the package's guarded HTTP path.\n\n## Privacy and security limits\n\n- Search queries and filters go to Exa; a configured API key is sent only to Exa's API endpoint. Keyless requests contain no Exa API key.\n- Requested page URLs go to their origins. Page extraction and Defuddle fallback run locally; this package sends no page to an LLM or hosted extraction service and has no telemetry or hidden model turn.\n- API keys are not included in tool output or diagnostics. Fetched content is kept in memory and in the local cache, not uploaded by the package.\n- Remote requests allow only HTTP(S), reject credentials in URLs, block loopback/private/reserved addresses and local hostname suffixes, resolve DNS before connecting, and pin the checked public address at connection time.\n- Redirects are manual, limited to five hops, and revalidated on every hop. `Authorization` and `x-api-key` headers are removed on cross-origin redirects.\n- A shared budget permits six provider/page operations per agent run and resets at `agent_start`. Each response is capped at 5 MiB; extraction output is capped at 1,000,000 characters; search output is capped at 16,000 characters.\n- Fetched-content cache entries expire after one hour and are limited to 128 entries and 128 MiB aggregate. The cache directory is mode 0700 and cache files are mode 0600.\n\n## Removed workflows\n\nThis release does not register or ship `code_search`, `source_check`, aliases, curator or `/websearch` flows, summary-review/result-review workflows, background `includeContent` fetching, provider fallbacks, GitHub/PDF/video workflows, browser-cookie access, bundled research skills, or media assets. The only registered tools are the three listed above.\n\n## Remove or undo\n\nTo undo the installation, remove `@diegopetrucci/pi-web-access@0.29.2` from the compatible host runtime using its package manager. Then remove only the package-owned profile data if it is no longer needed:\n\n```bash\nrm -f \"$PI_CODING_AGENT_DIR/extensions/pi-web-access/settings.json\"\nrm -rf \"$PI_CODING_AGENT_DIR/cache/pi-web-access\"\n```\n\nUnset `PI_CODING_AGENT_DIR` or remove the extension through the host runtime if the profile should no longer load it. These steps do not alter any external service or shared profile data outside the two package-owned paths.\n\n## Release handoff\n\nThe intended tag is `tlh-v0.29.2`. This repository does not change the external tlh repository, its package pin, or its obsolete curator/search documentation. After publication, update that external repository in a separately authorized follow-up to pin `@diegopetrucci/pi-web-access@0.29.2` and remove or correct those obsolete docs.\n\nSee [`SECURITY.md`](SECURITY.md) for reporting guidance and the [repository release procedure](https://github.com/diegopetrucci/pi-web-access/blob/main/docs/RELEASING.md) for the trusted-publishing handoff.\n","readmeFilename":"README.md"}