I wrote a piece about this here: https://ptgamr.substack.com/p/a-pi-setup-with-permission-san...
It is a combination of 3 extensions.
I managed to get the sandbox working, and the option to break out of sandbox (with approval).
The network sandboxing doesn't work yet (I don't want malicious script to be execute and exfiltrate the data), I created an issue here: https://github.com/erichll/pi-packages/issues/1 - might submit a PR once I get a reply.
If YOLO MODE causes pi to destroy my workstation (it hasn't yet) I'll just nuke the thing from orbit and spin up a new one.
Its very easy to use and has a pre-made profile for pi. Just do something like `alias pi="nono run -v --profile pi --allow-cwd -- /opt/homebrew/bin/pi"` in your shell.
For example, it comes with a bash tool built that you cannot disable. This is not minimal, it's the full kitchen sink. If I want to build a custom agent I have to literally stop using pi.dev and switch to something else.
So yeah, I fully disagree with the title. "Pi’s Minimalism Is Its Advantage" No. full stop. It's too bloated for me already. It's not minimal enough. If it's minimalism was its strength. it might not even need a sandbox, because it can't run bash commands or update files to begin with.
opencode has never done that.
I'm allured by the minimalism, so I didn't quit there, but I'm not keen on letting it loose with vague instructions, that's for sure.
I launch with `srt pi` and get file system and network isolation. There is a seemingly infinite risk surface area to protect, but I think does a reasonable job of balancing security and convenience.
I've also heard good things about nono [1] from colleagues, but I haven't personally tried it out yet.
[0] https://github.com/anthropic-experimental/sandbox-runtime
Think about why a sandbox is needed: Your permissions have been too loose. You now need to deal with the fallout of your decision externally. If all the agent was allowed to do is read your files and run cargo test, you wouldn't need a sandbox at all, the agent is the sandbox.
Now you might say, but what if it needs to modify files? If you wanted to build a sandbox or approval workflow here, you'd put it right into your custom write tool. It could be an extension you just download so you can pick your favorite write tool. Instead, the authors of pi.dev chose the worst possible defaults.
You have a wildly different understanding of what a power user is...
It's not like there isn't competition in this space.
Like I said, it's okay if you need those things. Pi might not be for your use-case and that's okay, too.
It is actually a combination of 3 extensions