Skip to content

security(pi): enforce runtime approval modes for interactive ACP tools #4

Description

@IanWorley

Problem

T3 currently exposes Supervised, Auto-accept edits, and Full access for Pi, but interactive pi-acp sessions execute Pi tools locally without sending session/request_permission first. The restricted modes therefore do not yet enforce the behavior promised by the composer.

Cursor review: #3 (comment)
Adapter-side prerequisite: IanWorley/pi-acp#1

Background title, branch, commit, and PR generation was separately made tool-free in 04f8aa6. This issue covers interactive sessions only.

Acceptance criteria

  • Supervised requests approval before execute and edit operations.
  • Auto-accept edits approves edit/write operations while still requesting approval for bash/execute operations.
  • Full access automatically selects an allow outcome.
  • Denied and cancelled requests block the Pi tool before any side effect.
  • Runtime-mode changes cannot leave an existing Pi session on stale permissions.
  • The UI does not advertise a restricted Pi mode until it is actually enforced.
  • Focused adapter tests cover each runtime mode and approval outcome.
  • An end-to-end test proves a denied Pi write or bash call produces no side effect.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions