configure-pi-safety-guards skillA
configure-pi-safety-guards is agent-read markdown (skill) from maplezzk/pi-extensions: 配置安全规则、规则动作和自定义匹配器。Use when configuring safety rules, rule actions or custom matchers..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# 配置安全规则 / Configure safety rules ## 配置位置 / Location `<pi-agent-dir>/extensions/pi-safety-guards/config.json` 遵守 `PI_CODING_AGENT_DIR`。首次运行时如果文件不存在,插件会把 4 条默认规则写进该文件;之后只读这个文件,没有隐藏的内置规则。`/config:safety-guards`(等价于 `show`)打印配置文件路径和当前生效规则,不打开菜单、不改文件;改完执行 `/reload`。 Respect `PI_CODING_AGENT_DIR`. On first run the extension writes four default rules into that file when it is missing, and reads only that file afterwards; no rules are hidden in code. `/config:safety-guards` (same as `show`) prints the file path and effective rules without opening a menu or writing files; reload after editing. ## 规则 / Rules - 顶层只有 `rules` 数组;数组为空就是没有任何保护。Only `rules` is accepted at the top level; an empty list means no protection. - 每条规则必须写 `id`、`action`、`match`;`message` 可选,`enabled: false` 表示保留但不执行(仍要写全 id/action/match)。Every rule needs `id`, `action` and `match`; `message` is optional and `enabled: false` keeps a rule without running it (it still needs a complete id/action/match). - ID 在列表内不能重复;未知字段直接报错,不静默忽略。IDs must be unique; unknown fields are rejected instead of silently ignored. - `action`:`warn`、`confirm`、`block`,优先级递增。Actions in increasing priority. …
Read the whole file at its exact version.
How to install
mdr add maplezzk/pi-extensions/configure-pi-safety-guards@git:20260915.451f7e6mdr add maplezzk/pi-extensions/configure-pi-safety-guards@sha256:b6a8efae7e36b1a7Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_n6mawlm4qxe3yeba)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260915.451f7e6 latest | 2026-09-15 | 451f7e6 | 3,901 B | A | view · diff |
| git:20260914.2ef6d3c | 2026-09-14 | 2ef6d3c | 3,656 B | A | view · diff |
| git:20260914.58389c2 | 2026-09-14 | 58389c2 | 3,548 B | A | view · diff |
| git:20260907.3bd68af | 2026-09-07 | 3bd68af | 2,947 B | A | view · diff |
| git:20260906.5bc2191 | 2026-09-06 | 5bc2191 | 2,980 B | A | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (3901 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
maplezzk/pi-extensions · 12 stars · license MIT · pushed 2026-09-22 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_n6mawlm4qxe3yeba GET https://markdownregistry.com/api/v1/resolve?ref=maplezzk/pi-extensions/configure-pi-safety-guards GET https://markdownregistry.com/api/v1/blob/b6a8efae7e36b1a7a2d5eda41da038e8514fb038912ddf405a15615ed0c35489
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.