Skip to content
This repository was archived by the owner on Aug 8, 2026. It is now read-only.
 
 

Repository files navigation

pi logo

Discord npm

This is cheetahbyte/pi, a fork of earendil-works/pi. See Differences from upstream below.

Pi Agent Harness

This is the home of the Pi agent harness project including our self extensible coding agent.

To learn more about Pi:

Differences from upstream

This fork tracks earendil-works/pi closely and regularly merges upstream, but publishes under the @cheetahbyte npm scope and carries its own set of additions on top:

  • Built-in code-navigation and session toolsoutline, symbol, and recall are enabled by default in normal agent sessions, unless overridden with tool options:
    • outline — a compact, signature-only preview of a file's top-level declarations (classes, functions, types, …), with methods nested under their class/impl/trait. Covers JS/TS, Python, Go, Rust, Java, and C#.
    • symbol — exact-name symbol search across the source tree that returns the real declaration and its extracted body instead of raw grep matches, using per-extension parsing with string/comment-aware brace matching.
    • recall — case-insensitive search over the full session history, including entries evicted from the live context by compaction, so the model can recover details that were summarized away.
  • Edit tool syntax guardrail — after an edit, a lightweight dependency-free check (JSON parsing, brace/paren/bracket and string-literal balance) flags likely syntax breakage as an advisory warning; it never blocks the edit.
  • Constraint re-surfacing after compaction — instructions and constraints that would otherwise get lost in a context compaction are re-inserted near the end of context so the agent keeps honoring them.
  • Compact interactive rendering — consecutive tool activity is grouped into compact, collapsible summaries in the TUI.
  • Thinking-block controls — thinking blocks are hidden by default, with settings to show or suppress them.
  • Memory/rendering efficiency fixes for tools and the TUI's differential renderer.
  • setRenderedSession extension API for rendering an externally-managed AgentSession from an extension.
  • Checked-in model catalog data so CI and offline builds do not require a live provider-catalog fetch.
  • Automated upstream sync workflow (.github/workflows/upstream-release-sync.yml) that watches upstream releases and opens sync PRs, so the fork doesn't drift far from earendil-works/pi.
  • Package names and npm publishing target the @cheetahbyte scope instead of @earendil-works; the auto-close-new-contributor-issues behavior from upstream is disabled here.

For the day-to-day feature set, docs, and package layout, everything below is otherwise the same as upstream.

All Packages

Package Description
@cheetahbyte/pi-telemetry Vendor-neutral telemetry contracts, reference adapter, conformance tests, and typed schemas
@cheetahbyte/pi-ai Unified multi-provider LLM API (OpenAI, Anthropic, Google, etc.)
@cheetahbyte/pi-agent-core Agent runtime with tool calling and state management
@cheetahbyte/pi-coding-agent Interactive coding agent CLI
@cheetahbyte/pi-tui Terminal UI library with differential rendering

For Slack/chat automation and workflows see earendil-works/pi-chat.

Permissions & Containerization

Pi does not include a built-in permission system for restricting filesystem, process, network, or credential access. By default, it runs with the permissions of the user and process that launched it.

If you need stronger boundaries, containerize or sandbox Pi. See packages/coding-agent/docs/containerization.md for three patterns:

  • Gondolin extension: keep pi and provider auth on the host while routing built-in tools and ! commands into a local Linux micro-VM.
  • Plain Docker: run the whole pi process in a local container for simple isolation.
  • OpenShell: run the whole pi process in a policy-controlled sandbox.

Contributing

See CONTRIBUTING.md for contribution guidelines and AGENTS.md for project-specific rules (for both humans and agents). Longer term plans for Pi can also be found in RFCs.

Development

npm install --ignore-scripts  # Install all dependencies without running lifecycle scripts
npm run build         # Refresh model data, then build all packages
npm run build:offline # Rebuild using existing model data without network access
npm run check         # Lint, format, and type check
./test.sh            # Run tests (skips LLM-dependent tests without API keys)
./pi-test.sh         # Run pi from sources (can be run from any directory)

Building standalone binaries from release source

GitHub releases include a versioned source archive covered by the release's SHA256SUMS file. Extract it and run the same build script used for the official standalone binaries:

VERSION="<release-version>"
tar -xzf "pi-${VERSION}-source.tar.gz"
cd "pi-${VERSION}"
./scripts/build-binaries.sh --offline-model-data --platform linux-x64 --out "$PWD/out"

The source archive includes the generated provider model data used for the release. --offline-model-data builds with that snapshot instead of refreshing it from live provider catalogs. The script still installs dependencies, builds the monorepo, compiles the Bun executable, and stages its runtime assets. Package maintainers who provide dependencies separately can pass --skip-install --skip-deps.

Supply-chain hardening

We treat npm dependency changes as reviewed code changes.

  • Direct external dependencies are pinned to exact versions. Internal workspace packages remain version-ranged.
  • .npmrc sets save-exact=true and min-release-age=2 to avoid same-day dependency releases during npm resolution.
  • package-lock.json is the dependency ground truth. Pre-commit blocks accidental lockfile commits unless PI_ALLOW_LOCKFILE_CHANGE=1 is set.
  • npm run check verifies pinned direct deps, native TypeScript import compatibility, and the generated coding-agent shrinkwrap.
  • The published CLI package includes packages/coding-agent/npm-shrinkwrap.json, generated from the root lockfile, to pin transitive deps for npm users.
  • Release smoke tests use npm run release:local to build, pack, and create isolated npm and Bun installs outside the repo before tagging a release.
  • Local release installs, documented npm installs, and pi update --self use --ignore-scripts where supported.
  • CI installs with npm ci --ignore-scripts, and a scheduled GitHub workflow runs npm audit --omit=dev plus npm audit signatures --omit=dev.
  • Shrinkwrap generation has an explicit allowlist for dependency lifecycle scripts; new lifecycle-script deps fail checks until reviewed.

Share your OSS coding agent sessions

If you use Pi or other coding agents for open source work, please share your sessions.

Public OSS session data helps improve coding agents with real-world tasks, tool use, failures, and fixes instead of toy benchmarks.

For the full explanation, see this post on X.

To publish sessions, use badlogic/pi-share-hf. Read its README.md for setup instructions. All you need is a Hugging Face account, the Hugging Face CLI, and pi-share-hf.

You can also watch this video, where I show how I publish my pi-mono sessions.

I regularly publish my own pi-mono work sessions here:

License

MIT

pi.dev domain graciously donated by

Exy mascot
exe.dev

About

AI agent toolkit: unified LLM API, agent loop, TUI, coding agent CLI

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages