Just published pi-automode-classifier, an auto mode plugin for the Pi coding agent that uses Jev or Kev/Laya (running locally) to classify commands. Pi runs every tool call without asking for approval. This plugin checks each shell command before it runs: Built-in rules decide most commands. For example ls, builds and tests run, rm -rf ~ is blocked, and git push and sudo need my approval. Commands the rules do not know are sent to the model. It returns the probability that the command is risky. If the probability is above a threshold, I get a confirm prompt. The model never blocks a command by itself. The models I tested: Jev 1.13 (hosted, from TypeSafe) through OpenRouter: about 270 ms per check and about 1.5 cents per 1,000 checks. The commands are sent to OpenRouter and TypeSafe. Kev-0.8B on CPU with llama.cpp: about 170 ms per check and 1.1 GB of RAM. This is what I use. Nothing leaves the machine. Laya typed-decisions on CPU with llama.cpp: about 100 ms per check and about 550 MB of RAM. In my test with 50 commands (25 safe, 25 risky), all safe commands ran without a prompt and no risky command did. I wrote the test commands myself, so this is only a rough check. The plugin is not a sandbox. pi install npm:pi-automode-classifier Code and docs: https://github.com/deepu105/pi-automode-classifier Let me know if it allows or blocks something it should not.   submitted by   /u/deepu105 [link]   [comments]