Build1 distinct publisher3 min readUpdated
A review of v0.84.2 is blunt: no built-in sandbox, no permission layer. Three of the four default tools change the machine, and whatever sits between them and your repo is code you own.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Count the default tool set by what it does rather than how many entries it has. `read` observes. `write`, `edit` and `bash` change the machine, which puts three of the four defaults on the mutating side of the line [14]. The review's security position sits directly on top of that arithmetic: no built-in security sandbox, and no permission system of the kind a developer arriving from Claude Code would expect to find [3].
The one security measure the quickstart names is `--ignore-scripts` on the npm install, which suppresses dependency lifecycle scripts that Pi does not need and closes a familiar supply-chain hole [10]. That control fires once, at install time. Runtime tool execution, which is where a shell tool actually earns its risk, has nothing equivalent shipped with it [15].
So price the adoption properly. A team standardising on Pi is signing up to write four things other harnesses hand over: a sandbox, an approval path, subagents and a plan mode, the last two being extension or package territory by design [16][9]. None of that is hidden. The review is explicit that more control comes with correspondingly more responsibility, and that Pi is a harness rather than a finished environment: it exposes what context the model sees, which tools it can call, how results come back, how sessions persist and what happens between turns [11].
The awkward part is where your guardrail has to live. It lives in an extension, and the review advises checking configuration and extension APIs against a version before standardising them across a team, because Pi has been moving quickly [6]. That is the same project whose package scope changed from `@mariozechner` to `@earendil-works` when it moved to Earendil Works in May 2026, three months before the v0.84.2 release this review is pinned to [5][17]. An internal approval layer is therefore coupled to a surface that has recently been renaming itself.
Before writing any of it, use the lever the review mentions almost in passing: recent releases let the initial built-in tool selection be configured, and read-only tools such as `grep`, `find` and `ls` are available alongside the defaults [7]. Narrowing what the model can reach is cheaper than sandboxing what it can do, and it matches the stated rationale for the small default set, where every extra tool adds a decision for the model, more system prompt and another behaviour to debug [8].
Who this actually serves is where the review is most useful. It points at senior developers, platform engineers and AI tooling teams whose ceiling is the harness rather than the model, and says plainly that Pi is less convincing for anyone who wants to install an agent, approve some safe defaults and stop thinking about it [12]. If the harness is not your bottleneck, you are buying a bill without the benefit.
Two housekeeping items worth putting in your own install notes: older tutorials still show the stale `@mariozechner` packages [5], and the name collides with `oh-my-pi`, a community fork of Oh My Opencode that is a different project entirely [13].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Pi Coding Agent is a minimal, open-source terminal coding harness that ships with four default tools and leaves most behaviour to extensions, skills, packages and the user's own workflow.
Pi's default model-facing tool set is read, write, edit and bash.
Pi does not provide a built-in security sandbox or the kind of permission system developers may expect after using Claude Code or similar tools; the review frames this as more control and correspondingly more responsibility.
The review is aligned with Pi v0.84.2, released 14 August 2026.
Mario Zechner created Pi; the project moved to Earendil Works in May 2026, which is why current packages use the @earendil-works scope rather than the older @mariozechner names, and older tutorials showing the @mariozechner packages are stale for new installs.
Pi has been changing quickly, so configuration and extension APIs deserve a version check before a team standardises on them.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-source practitioner review
Everything traces to one dev.to review by one author. Its specifics are checkable and version-pinned (v0.84.2, 14 August 2026, exact install command, named tool set), which raises it above pure assertion, but no second publisher, vendor document, repository artefact or independent test corroborates the tool surface, the absence of a sandbox or the release timeline. Derived claims about state-changing tools and install-time-only controls follow cleanly from the source but inherit its single-source ceiling.
Release cadence only, no usage signal
The cluster shows a shipping project — a dated v0.84.2 release, a package-scope migration to @earendil-works, and recent releases adding configurable built-in tool selection — which is real but thin adoption evidence. There are no downloads, stars, deployments, team standardisations, benchmarks or named users anywhere in the supplied material, and the reviewer explicitly treats team standardisation as a prospective decision rather than an observed one.
Restrained relative to its own warnings
The narrative runs slightly below the evidence rather than above it: the review's headline framing is a limitation (no sandbox, no permission layer, more responsibility), it declines to claim feature superiority, and it explicitly names who Pi is wrong for. The mild negative rather than zero reflects that the operationally significant point — three of four default tools mutate machine state with only an install-time mitigation shipped — is stated calmly and left as reader homework. Offsetting that, audience-fit and 'comparable agents ship these four things' framing outrun any measured adoption, which keeps the gap close to aligned rather than strongly negative.
Community-platform review with cross-promotion pull
The author is not the project's vendor and criticises it openly, which limits promotional incentive. But this is a self-published community-platform review that routes readers to the author's or platform's adjacent content — an Oh My Opencode review, a Claude Code subagents guide, a llama.cpp quickstart and an LLM hosting guide — an audience-and-traffic incentive typical of tool-review posts. No sponsorship, affiliate or vendor relationship is disclosed either way in the supplied text, so the reading is structural rather than evidenced conflict.
Low-moderate: coherent account, one voice
Confidence is limited by structure, not internal quality. The single source is specific, version-pinned and self-consistent, and its architectural claims are the kind a reader could verify quickly, which supports moderate trust in the descriptive facts. But with one publisher, no primary project documentation, no adoption data and fast-moving APIs the reviewer himself flags, the durability of any claim beyond v0.84.2 is unestablished, and audience-fit judgements are untested opinion.
build
Claude Code's new default is a confession: the approval prompt was never a control1 distinct publisher
build
Existence checks are dead: attackers now register the packages your AI invents1 distinct publisher
build
Hash-anchored edits turn a lost race into an error, and that contract outranks the tool count1 distinct publisher
build
Resend is selling to the agent and handing the humans free templates1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 23, 2026