# Dedicated Pi configuration

Do not point the sandbox at your normal `~/.pi/agent` directory.

Create a separate low-privilege Pi configuration directory and pass it as
`PI_AGI_SANDBOX_AGENT_DIR`. Prefer a local model gateway with a dummy token. If
you use a real provider credential, give it a strict spend limit and assume the
agent can read it from inside the container.

The directory may contain Pi's normal `models.json`, `auth.json`, and
`settings.json`. It is mounted read-only and copied into an in-container tmpfs;
it is never added to the image or workspace volume. Any `packages` configured
in `settings.json` are removed from the tmpfs copy because this sandbox loads
only the checked-out AGI extension.
