BuildNot yet confirmed elsewhere1 publisher3 min readPublished
Pi ships four tools and no sandbox, so the guardrails are on your build list
A review of v0.84.2 is blunt: no built-in sandbox, no permission layer. Three of the four default tools change the machine, and whatever sits between them and your repo is code you own.
The Engineer · Build desk

What happened
- Pi Coding Agent is an open-source terminal harness whose default agent starts with four tools and pushes the rest to extensions, skills and packages.
- Subagents and a mandatory plan mode are deliberately not built in and are left to extensions or installed packages.
- The project was created by Mario Zechner and moved to Earendil Works in May 2026, so current packages use the @earendil-works scope.
Why it matters
- cost The safety layer becomes a funded engineering item for the adopting team rather than something inherited with the install.
- exposure Between a model's shell command and the working machine there is nothing shipped, so the operator absorbs whatever a bad tool call reaches.
- constraint Guardrails written as extensions ride an API the review says to version-check before standardising, which limits how durable a home-built permission layer can be.
Count the default tool set by what it does rather than how many entries it has. `read` observes. `write`, `edit` and `bash` change the machine, which puts three of the four defaults on the mutating side of the line [13]. The review's security position sits directly on top of that arithmetic: no built-in security sandbox, and no permission system of the kind a developer arriving from Claude Code would expect to find [3].
The one security measure the quickstart names is `--ignore-scripts` on the npm install, which suppresses dependency lifecycle scripts that Pi does not need and closes a familiar supply-chain hole [10]. That control fires once, at install time. Runtime tool execution, which is where a shell tool actually earns its risk, has nothing equivalent shipped with it [14].
So price the adoption properly. A team standardising on Pi is signing up to write four things other harnesses hand over: a sandbox, an approval path, subagents and a plan mode, the last two being extension or package territory by design [15][9]. None of that is hidden. The review is explicit that more control comes with correspondingly more responsibility, and that Pi is a harness rather than a finished environment: it exposes what context the model sees, which tools it can call, how results come back, how sessions persist and what happens between turns [11].
The awkward part is where your guardrail has to live. It lives in an extension, and the review advises checking configuration and extension APIs against a version before standardising them across a team, because Pi has been moving quickly [6]. That is the same project whose package scope changed from `@mariozechner` to `@earendil-works` when it moved to Earendil Works in May 2026, three months before the v0.84.2 release this review is pinned to [5][16]. An internal approval layer is therefore coupled to a surface that has recently been renaming itself.
Before writing any of it, use the lever the review mentions almost in passing: recent releases let the initial built-in tool selection be configured, and read-only tools such as `grep`, `find` and `ls` are available alongside the defaults [7]. Narrowing what the model can reach is cheaper than sandboxing what it can do, and it matches the stated rationale for the small default set, where every extra tool adds a decision for the model, more system prompt and another behaviour to debug [8].
Who this actually serves is where the review is most useful. It points at senior developers, platform engineers and AI tooling teams whose ceiling is the harness rather than the model, and says plainly that Pi is less convincing for anyone who wants to install an agent, approve some safe defaults and stop thinking about it [17]. If the harness is not your bottleneck, you are buying a bill without the benefit.
Two housekeeping items worth putting in your own install notes: older tutorials still show the stale `@mariozechner` packages [5], and the name collides with `oh-my-pi`, a community fork of Oh My Opencode that is a different project entirely [12].
What to watch
- Whether a later release ships an opt-in sandbox or a permission API instead of leaving both to extensions.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence34
- Adoption16
- Hype gap−8
- Incentives44
- Confidence38
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Pi Coding Agent is a minimal, open-source terminal coding harness that ships with four default tools and leaves most behaviour to extensions, skills, packages and the user's own workflow.
- [2]
Pi's default model-facing tool set is read, write, edit and bash.
- [3]
Pi does not provide a built-in security sandbox or the kind of permission system developers may expect after using Claude Code or similar tools; the review frames this as more control and correspondingly more responsibility.
- [4]
The review is aligned with Pi v0.84.2, released 14 August 2026.
- [5]
Mario Zechner created Pi; the project moved to Earendil Works in May 2026, which is why current packages use the @earendil-works scope rather than the older @mariozechner names, and older tutorials showing the @mariozechner packages are stale for new installs.
- [6]
Pi has been changing quickly, so configuration and extension APIs deserve a version check before a team standardises on them.
- [7]
Additional read-only tools including grep, find and ls are available, and recent Pi releases allow the initial built-in tool selection to be configured.
- [8]
The stated rationale for the small default set is that every additional tool increases the number of decisions the model has to make, expands the system prompt and creates another behavioural surface that may need debugging.
- [9]
Pi deliberately does not make built-in subagents or a mandatory plan mode central to the product; those behaviours can be implemented through extensions or installed packages instead.
- [10]
The install instruction is npm install -g --ignore-scripts @earendil-works/pi-coding-agent; --ignore-scripts disables dependency lifecycle scripts, which Pi does not need for a normal npm install, and skipping them reduces a common supply-chain risk.
- [11]
Pi is described as an agent harness rather than a finished coding environment: the harness decides what context the model sees, which tools it can call, how tool results return, how sessions persist and what happens between turns, and Pi makes almost all of those layers accessible.
- [12]
The name collides with oh-my-pi, a community fork of the Oh My Opencode harness, which is unrelated to the Pi coding agent.
- [13]
Three of Pi's four default tools (write, edit and bash) can change state on the machine; only read cannot.
- [14]
The only security control named in Pi's quickstart acts at install time (skipping npm dependency lifecycle scripts); runtime tool execution has no equivalent shipped control, since there is no built-in sandbox or permission system.
- [15]
A team adopting Pi must supply four things itself that comparable agents ship: a security sandbox, a permission or approval layer, subagents and a plan mode.
- [16]
The package scope move to Earendil Works happened about three months before the v0.84.2 release the review is pinned to.
- [17]
The review says Pi is particularly attractive to senior developers, platform engineers and AI tooling teams whose limitations come from the harness rather than the model, and less convincing for someone who wants to install an agent, approve a few safe defaults and never think about its architecture again.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toPi Coding Agent Review: Minimal, Hackable AI Coding CLI
1 article · August 23, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Open Source Project GovernanceFollow
- AI Coding AgentsFollow
- Agent Sandboxing and PermissionsFollow
- Developer Tool Supply-Chain RiskFollow
Entities
- piFollow
- Earendil WorksFollow
- Mario ZechnerFollow
- Claude CodeFollow
- Oh-My-PiFollow
- Oh My OpencodeFollow
- npm registryFollow
- llama.cppFollow