3 ms·
This is also by design. Pi assumes you’re a power user and you know what you you’re doing and what you want. If sandboxing and the security that Claude and code
by josh_p 2mo ago
This is also by design. Pi assumes you’re a power user and you know what you you’re doing and what you want. If sandboxing and the security that Claude and codex offer is something you truly need, pi might not be for you and that’s okay.
- imtringued 2mo agoThis is backwards. If you're a power user you want full control over all the tools granted to the agent and not let the agent bypass them by using bash. It's the people who don't want to customize anything that don't care about letting the agent go haywire and just run whatever bash commands it needs in a sandbox. Think about why a sandbox is needed: Your permissions have been too loose. You now need to deal with the fallout of your decision externally. If all the agent was allowed to do is read your files and run cargo test, you wouldn't need a sandbox at all, the agent is the sandbox. Now you might say, but what if it needs to modify files? If you wanted to build a sandbox or approval workflow here, you'd put it right into your custom write tool. It could be an extension you just download so you can pick your favorite write tool. Instead, the authors of pi.dev chose the worst possible defaults.
- BoiledCabbage 2mo agoPower users don't want sandboxing and security?? You have a wildly different understanding of what a power user is...
- josh_p 2mo agoOr you could do any of the things they suggest in their documentation: https://pi.dev/docs/latest/security#running-untrusted-or-unmonitored-work https://pi.dev/docs/latest/security#running-untrusted-or-unm... It's not like there isn't competition in this space. Like I said, it's okay if you need those things. Pi might not be for your use-case and that's okay, too.