{"_id":"@edmundmiller/pi-scurl","name":"@edmundmiller/pi-scurl","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.1":{"name":"@edmundmiller/pi-scurl","version":"0.1.1","type":"module","description":"Secure web fetch for pi – HTML-to-markdown via mdream, secret scanning, prompt injection detection","main":"./index.ts","keywords":["pi","pi-extension","web-fetch","markdown","scurl","mdream","prompt-injection","pi-package"],"author":{"name":"Edmund Miller","email":"edmundmiller@hey.com"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/edmundmiller/dotfiles.git","directory":"packages/pi-scurl"},"peerDependencies":{"@mariozechner/pi-coding-agent":"*"},"dependencies":{"@sinclair/typebox":"^0.34.0","mdream":"^0.16.0"},"devDependencies":{"@types/bun":"^1.3.8","@types/node":"^22.0.0","typescript":"^5.0.0"},"pi":{"extensions":["./index.ts"]},"_id":"@edmundmiller/pi-scurl@0.1.1","gitHead":"36ee91198779d95cceda4b850f6c9409f6a5003e","bugs":{"url":"https://github.com/edmundmiller/dotfiles/issues"},"homepage":"https://github.com/edmundmiller/dotfiles#readme","_nodeVersion":"22.22.0","_npmVersion":"10.9.4","dist":{"integrity":"sha512-jaxNwwbYOnzcnm8zoNZj9vLNPBWHTQF9kHxaf7XTjFWk5IXzDG1suC+qmoLU7OiXO2Q4IcV1S2N4Oxrewmr4hw==","shasum":"3ef3b49f9c5e6f2b5f610e2611a12b2bd192f466","tarball":"https://registry.npmjs.org/@edmundmiller/pi-scurl/-/pi-scurl-0.1.1.tgz","fileCount":6,"unpackedSize":30213,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIC2ptwip/TU8uCfbuxjFaP7iX0O3fjxgrsnS8bn1uiLbAiEA1JD6HrPrIOxcJzg1OAKTWc8ri0b7eXqwG6fd5vYhvhg="}]},"_npmUser":{"name":"emiller88","email":"edmund.a.miller@gmail.com"},"directories":{},"maintainers":[{"name":"emiller88","email":"edmund.a.miller@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/pi-scurl_0.1.1_1771908846759_0.9788964785159808"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-24T04:54:06.696Z","0.1.1":"2026-02-24T04:54:06.928Z","modified":"2026-02-24T04:54:07.110Z"},"maintainers":[{"name":"emiller88","email":"edmund.a.miller@gmail.com"}],"description":"Secure web fetch for pi – HTML-to-markdown via mdream, secret scanning, prompt injection detection","homepage":"https://github.com/edmundmiller/dotfiles#readme","keywords":["pi","pi-extension","web-fetch","markdown","scurl","mdream","prompt-injection","pi-package"],"repository":{"type":"git","url":"git+https://github.com/edmundmiller/dotfiles.git","directory":"packages/pi-scurl"},"author":{"name":"Edmund Miller","email":"edmundmiller@hey.com"},"bugs":{"url":"https://github.com/edmundmiller/dotfiles/issues"},"license":"MIT","readme":"# pi-scurl\n\nSecure web fetch extension for [pi](https://github.com/badlogic/pi-mono). Fetches URLs and returns clean, LLM-optimized markdown.\n\nInspired by [scurl](https://github.com/sibyllinesoft/scurl), rebuilt in TypeScript with [mdream](https://github.com/harlan-zw/mdream) for HTML-to-markdown conversion.\n\n## Features\n\n- **HTML → Markdown** via mdream (~50-99% token reduction)\n- **Secret scanning** — blocks outgoing requests containing API keys, tokens, private keys\n- **Prompt injection detection** — regex-based detection with configurable actions (warn/redact/tag)\n- **Output truncation** — stays within pi's context limits\n\n## Tool: `web_fetch`\n\n```\nweb_fetch(url, options?)\n```\n\n| Parameter          | Type    | Default  | Description                                       |\n| ------------------ | ------- | -------- | ------------------------------------------------- |\n| `url`              | string  | required | URL to fetch                                      |\n| `raw`              | boolean | false    | Skip HTML-to-markdown conversion                  |\n| `minimal`          | boolean | true     | Use mdream minimal preset (strips nav, ads, etc.) |\n| `headers`          | object  | {}       | Custom request headers                            |\n| `timeout`          | number  | 30000    | Request timeout in ms                             |\n| `injection_action` | enum    | \"warn\"   | Action on injection: warn, redact, tag, none      |\n\n## Secret Patterns\n\nDetects 25+ secret formats: AWS, GitHub, GitLab, Slack, Stripe, Google, npm, PyPI, OpenAI, Anthropic, and more. Authorization headers are excluded (expected to contain tokens).\n\n## Injection Detection\n\nPattern categories: instruction override, role injection, system manipulation, prompt leak, jailbreak keywords, encoding markers, suspicious delimiters.\n\nActions:\n\n- **warn** — wraps in `<suspected-prompt-injection>` + `<untrusted>` tags\n- **redact** — masks matched patterns with █ characters\n- **tag** — wraps in `<untrusted>` tags only\n- **none** — disabled\n\n## Install\n\nReferenced as a local package in `config/pi/settings.jsonc`:\n\n```jsonc\n\"~/.config/dotfiles/packages/pi-scurl\"\n```\n\nDeps installed automatically by nix activation.\n","readmeFilename":"README.md","_rev":"1-10e902dab84d97ae22a5b7e8df4b6ae5"}