<img src="assets/preview.png" width="100%" alt="Token Phish Blocker">

Always-on anti-hedging policy for the Pi coding agent — auto-fix instead of caveat.

[![npm version](https://img.shields.io/npm/v/token-phish-blocker)](https://www.npmjs.com/package/token-phish-blocker)
[![pi.dev catalog](https://img.shields.io/badge/pi.dev-catalog-blue)](https://pi.dev/packages/token-phish-blocker)
[![MIT license](https://img.shields.io/badge/license-MIT-blue.svg)](./LICENSE)
[![CI](https://github.com/getdatasurge/token-phish-blocker/actions/workflows/ci.yml/badge.svg)](https://github.com/getdatasurge/token-phish-blocker/actions/workflows/ci.yml)

## Install

```
pi install npm:token-phish-blocker
```

Or browse it on the [pi.dev package catalog](https://pi.dev/packages/token-phish-blocker).

From git, if you're not using npm:

```
pi install git:github.com/getdatasurge/token-phish-blocker
```

Try it once without installing:

```
pi -e npm:token-phish-blocker
```

## What it does

Agents love to hedge: "one caveat — I didn't handle the empty-array case,"
"just a heads up, I didn't wire up error logging." That's a fixable gap
phrased as commentary instead of fixed.

Token Phish Blocker injects a 4-rule policy into the system prompt on every
turn: stop hedging, fix trivial and blocking issues before calling the task
done, stay inside the current task's blast radius, and log every such
auto-fix through a mandatory tool call. The log call drives a live counter in
the footer, so the policy being "on" is directly observable — not just
asserted.

That's the whole thing. 30 seconds, no config, no runtime deps.

## The four rules

| Rule | What it means |
| --- | --- |
| 1. No hedging | Banned caveat phrasing ("one thing I didn't do", "just a heads up", ...) — fix it instead of mentioning it. |
| 2. Auto-implement | Trivial fixes and fixes that block the task from actually working land before you say "done" — no permission-asking. |
| 3. Stay in scope | Auto-fixes are limited to the blast radius of the current task. Anything bigger still gets surfaced, plainly. |
| 4. Log every auto-fix | Every rule-2 fix calls `token_phish_blocker_log` with a one-line description — mandatory, and it's the audit trail. |

Full text: [docs/POLICY.md](./docs/POLICY.md).

## The audit trail

Every auto-fix appends a tab-separated line to `~/.pi/agent/token-phish-blocker.log`:

```
ISO-timestamp<TAB>cwd<TAB>description
```

Example:

```
2026-08-12T03:14:07.221Z	/home/user/projects/api	added missing null check in parseConfig() that would have crashed on empty input
```

## The status line

The moment a session starts, the footer shows the counter at zero — that's
your proof the policy is injected and active:

```
🎣 TPB · 0 fixes
```

Each `token_phish_blocker_log` call ticks it up live, so by the end of a
session you can see exactly how many caveats became fixes instead:

```
🎣 TPB · 3 fixes
```

| Situation | What you see |
| --- | --- |
| Fresh session | `🎣 TPB · 0 fixes` — policy injected, nothing logged yet |
| After auto-fixes | `🎣 TPB · N fixes`, updating the moment each fix lands |
| Headless (`pi -p "..."`) | No status line — the audit log still gets every entry |
| `TPB_NO_STATUS=1` | Counter hidden — policy and audit log keep working |

Nothing to install or configure — the status-line helper ships inside the
extension and registers itself on session start.

## Customizing the policy

Copy [docs/POLICY.md](./docs/POLICY.md) to `~/.pi/agent/token-phish-blocker-policy.md`
and edit it. The override file replaces the built-in policy verbatim. Delete
it to fall back to the built-in policy.

## FAQ

**Does it work in omp?** Yes — `omp install npm:token-phish-blocker`.

**Does it phone home?** No. Zero network calls, zero runtime dependencies.
The only writes are to the local log file.

**How do I turn it off?** `pi remove npm:token-phish-blocker`, or disable it
per-project via `pi config`.

**How do I hide the status counter?** Set `TPB_NO_STATUS=1` in your
environment. The policy injection and audit log keep working.

---

MIT © [getdatasurge](https://github.com/getdatasurge) · [issues](https://github.com/getdatasurge/token-phish-blocker/issues)
