Skip to content

BuildNot yet confirmed elsewhere1 publisher3 min readPublished

Pi ships four tools and no sandbox, so the guardrails are on your build list

A review of v0.84.2 is blunt: no built-in sandbox, no permission layer. Three of the four default tools change the machine, and whatever sits between them and your repo is code you own.

The Engineer · Build desk

How we use AISend a correction

Illustration accompanying Pi ships four tools and no sandbox, so the guardrails are on your build list
Generated illustration

What happened

  • Pi Coding Agent is an open-source terminal harness whose default agent starts with four tools and pushes the rest to extensions, skills and packages.
  • Subagents and a mandatory plan mode are deliberately not built in and are left to extensions or installed packages.
  • The project was created by Mario Zechner and moved to Earendil Works in May 2026, so current packages use the @earendil-works scope.

Why it matters

  • cost The safety layer becomes a funded engineering item for the adopting team rather than something inherited with the install.
  • exposure Between a model's shell command and the working machine there is nothing shipped, so the operator absorbs whatever a bad tool call reaches.
  • constraint Guardrails written as extensions ride an API the review says to version-check before standardising, which limits how durable a home-built permission layer can be.

Count the default tool set by what it does rather than how many entries it has. `read` observes. `write`, `edit` and `bash` change the machine, which puts three of the four defaults on the mutating side of the line [13]. The review's security position sits directly on top of that arithmetic: no built-in security sandbox, and no permission system of the kind a developer arriving from Claude Code would expect to find [3].

The one security measure the quickstart names is `--ignore-scripts` on the npm install, which suppresses dependency lifecycle scripts that Pi does not need and closes a familiar supply-chain hole [10]. That control fires once, at install time. Runtime tool execution, which is where a shell tool actually earns its risk, has nothing equivalent shipped with it [14].

So price the adoption properly. A team standardising on Pi is signing up to write four things other harnesses hand over: a sandbox, an approval path, subagents and a plan mode, the last two being extension or package territory by design [15][9]. None of that is hidden. The review is explicit that more control comes with correspondingly more responsibility, and that Pi is a harness rather than a finished environment: it exposes what context the model sees, which tools it can call, how results come back, how sessions persist and what happens between turns [11].

The awkward part is where your guardrail has to live. It lives in an extension, and the review advises checking configuration and extension APIs against a version before standardising them across a team, because Pi has been moving quickly [6]. That is the same project whose package scope changed from `@mariozechner` to `@earendil-works` when it moved to Earendil Works in May 2026, three months before the v0.84.2 release this review is pinned to [5][16]. An internal approval layer is therefore coupled to a surface that has recently been renaming itself.

Before writing any of it, use the lever the review mentions almost in passing: recent releases let the initial built-in tool selection be configured, and read-only tools such as `grep`, `find` and `ls` are available alongside the defaults [7]. Narrowing what the model can reach is cheaper than sandboxing what it can do, and it matches the stated rationale for the small default set, where every extra tool adds a decision for the model, more system prompt and another behaviour to debug [8].

Who this actually serves is where the review is most useful. It points at senior developers, platform engineers and AI tooling teams whose ceiling is the harness rather than the model, and says plainly that Pi is less convincing for anyone who wants to install an agent, approve some safe defaults and stop thinking about it [17]. If the harness is not your bottleneck, you are buying a bill without the benefit.

Two housekeeping items worth putting in your own install notes: older tutorials still show the stale `@mariozechner` packages [5], and the name collides with `oh-my-pi`, a community fork of Oh My Opencode that is a different project entirely [12].

What to watch

  • Whether a later release ships an opt-in sandbox or a permission API instead of leaving both to extensions.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence34
Adoption16
Hype gap−8
Incentives44
Confidence38
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Pi Coding Agent is a minimal, open-source terminal coding harness that ships with four default tools and leaves most behaviour to extensions, skills, packages and the user's own workflow.

    ReportedSupportedView cited source
  2. [2]

    Pi's default model-facing tool set is read, write, edit and bash.

    ReportedSupportedView cited source
  3. [3]

    Pi does not provide a built-in security sandbox or the kind of permission system developers may expect after using Claude Code or similar tools; the review frames this as more control and correspondingly more responsibility.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · August 23, 2026

    Pi Coding Agent Review: Minimal, Hackable AI Coding CLI

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories