Pi: libGDX Creator's AI Agent Toolkit Unifies 15+ LLM APIs, Agents Write Extensions

Pi is an open-source AI agent toolkit by libGDX author Mario Zechner that unifies 15+ LLM provider APIs, provides an agent runtime, terminal coding agent, and TUI library, deliberately omitting features like sub-agents and permission popups in favor of extensibility, while implementing rigorous supply chain security practices.

Architecture Digest
Architecture Digest
Architecture Digest
Pi: libGDX Creator's AI Agent Toolkit Unifies 15+ LLM APIs, Agents Write Extensions

One-Sentence Overview

Pi is an open-source AI agent toolkit: unified multi-vendor LLM API + agent runtime + terminal coding agent + TUI library, all in one monorepo.

Unlike typical products, Pi is a shell house : powerful defaults are pre-installed, but the core is deliberately minimal; the rest is up to you to extend.

Three Highlights

Highlight 1: Unified API for 15+ Model Providers

The foundational package pi-ai unifies Anthropic, OpenAI, Google, Azure, Bedrock, Mistral, Groq, Cerebras, xAI, Hugging Face, Kimi For Coding, MiniMax, NVIDIA, OpenRouter, Ollama — 15+ providers, hundreds of models — with API key or OAuth authentication.

Switch models mid-session with /model (or Ctrl+L); cycle favorite models with Ctrl+P. Custom providers and models are configured via models.json or extensions. Vendor lock-in is addressed at the base layer.

Highlight 2: The Art of Deliberate Omission

Pi's most distinctive philosophy is its What we didn't build list:

No sub-agents → spawn tmux Pi instances or build your own extension.

No plan mode → write plans to files or create an extension.

No permission popups → run in a container or use an extension with inline confirmation.

No built-in to-dos → use TODO.md.

No background bash → use tmux for full observability.

All these capabilities exist as official extension examples (50+ in the repo); install them if you want, or write your own. Notably, you can ask Pi to write its own extensions — after editing, /reload makes them effective immediately. The official site's interactive screenshot shows the agent reading its own extension docs and writing a greeting extension live. Extensions can go far: the community even added Doom, playable while the agent works.

Highlight 3: Supply-Chain Hardening Down to Dependency Locking

The README dedicates a section to Supply-chain hardening , treating npm dependency changes as code changes for review:

Direct dependencies are pinned to exact versions ; .npmrc sets save-exact=true + min-release-age=2 (skip packages published today to avoid poisoning windows).

Lockfile is the single source of truth ; pre-commit hooks block accidental lockfile commits.

Published CLI bundles include shrinkwrap to freeze transitive dependencies; lifecycle scripts have an explicit allowlist — new scripts fail until reviewed.

CI runs npm ci --ignore-scripts; scheduled jobs execute npm audit plus signature verification.

This combination is rare in similar projects and can be directly adopted by teams serious about supply-chain security.

Three Key Design Decisions

Decision 1: Layered monorepo, from model layer up to application layer. Seven packages each own a domain: pi-ai (unified LLM API) → pi-agent-core (tool-calling & state-management runtime) → pi-coding-agent (terminal CLI) → pi-tui (diff-rendering terminal UI library); plus chord (service/RPC/plugin composition runtime), pi-durable (persisted conversations/tasks/documents), pi-telemetry (vendor-neutral telemetry).

Layers are decoupled — you can use only pi-ai or take the full stack.

Decision 2: From rejecting MCP to built-in + Codemode. Pi initially said No MCP , then published a blog post you said no mcp admitting the change — MCP is now built in, and Codemode lets the agent compose tool calls inside a JS sandbox. Pragmatic stance: positions can change, user needs don't lie.

Decision 3: Security boundaries externalized, no false guardrails. The README states: Pi does not ship a permission system; it runs with the launching user's privileges by default. For strong isolation, the docs offer three modes — Gondolin micro-VM (Pi stays on host, tool calls routed into Linux micro-VM), plain Docker (entire process containerized), and OpenShell (policy-controlled sandbox, the NVIDIA project analyzed in late September). Security boundaries are clearly pushed outward; no illusion of built-in guardrails.

Installation and Configuration

Three installation options: curl script

powershell -c "irm https://pi.dev/install.ps1 | iex"
npm install -g @earendil-works/pi-coding-agent

Four modes cover different workflows:

Interactive : full TUI experience (shown in screenshots).

Print/JSON : pi -p "query" for scripting, --mode json for event streams.

RPC : JSON protocol over stdin/stdout for non-Node integrations.

SDK : embed in your own app (OpenClaw is a real-world example).

Session history is a tree structure : /tree jumps back to any historical node to fork a new branch; all branches stored in a single file. /export produces HTML, /share pushes to a GitHub gist for a shareable link. Context engineering includes full tooling: AGENTS.md project instructions, SYSTEM.md to replace system prompt, automatic compaction, on-demand Skills, and /name -expanded prompt templates.

Mid-task intervention: Enter sends a steering message (interrupts after current tool finishes), Alt+Enter sends a follow-up (executes after the agent finishes).

Team Adoption Guide

Phase 1 · Unified model access layer. Use pi-ai to consolidate team LLM calls: one config manages 15+ providers; when a model raises prices, throttles, or goes down, switch via config without touching business code. Combined with pi-telemetry 's vendor-neutral telemetry, cost and usage have a single pane of glass.

Phase 2 · Sandbox isolation first. Pi runs with the launching user's permissions by default. Before team rollout, pick an isolation strategy: lightweight → Docker; policy control → OpenShell sandbox; Gondolin micro-VM for a compromise where host keeps credentials but tools run isolated. Treat bare-metal pi as prohibited in policy.

Phase 3 · Supply-chain governance by copying the playbook. Pi's hardening checklist ports directly to any npm project: save-exact + min-release-age, lockfile as truth + pre-commit block, shrinkwrap + lifecycle-script allowlist, scheduled npm audit in CI. Low cost, prevents real incidents.

Phase 4 · Knowledge systematization. Project conventions in AGENTS.md, system prompt customization via SYSTEM.md, reusable prompts as template library; encourage members to share OSS work sessions with pi-share-hf — real task trajectories beat toy benchmarks.

Suitable Scenarios

Developers who want a terminal coding agent but find mainstream products too opinionated : Pi gives you control; the agent can even modify itself.

Teams locked into a single model vendor : pi-ai one API, swap providers without changing business code.

Teams prioritizing supply-chain security : Pi's hardening practices are worth adopting wholesale.

Engineers building custom toolchains on an agent runtime : pi-agent-core + four modes + 50+ extension examples provide a high starting point.

Pros and Cons

Pros

Led by libGDX author Mario Zechner; high engineering quality, GitHub API shows 111,562★, MIT licensed, commits still landing today.

Primitives not features philosophy + 50+ official extensions + four modes = extensibility ceiling for this category.

15+ provider unification + tree-structured session history + complete context-engineering hooks.

Transparent, public supply-chain security practices ready to copy.

Potential Drawbacks

⚠️ No built-in permission system — runs with launching user's privileges by default; isolation requires self-configured Gondolin / Docker / OpenShell.

⚠️ Monorepo with 7 packages, complex structure — onboarding requires reading docs (though you can ask Pi itself).

⚠️ New contributors' issues/PRs auto-closed by default — maintainers manually review daily; unique collaboration barrier, read CONTRIBUTING.md before PR.

⚠️ Pure TypeScript ecosystem — non-TS developers face a learning curve.

Final Thoughts

If you're tired of agent products that make decisions for you, Pi's shell house is worth renovating. Remember two things: configure the sandbox before doing real work, and check the auto-close rules before submitting a PR.

GitHub repository:

https://github.com/earendil-works/pi
Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

TypeScriptAI agentPisupply chain securityagent runtimeLLM API unification
Architecture Digest
Written by

Architecture Digest

Focusing on Java backend development, covering application architecture from top-tier internet companies (high availability, high performance, high stability), big data, machine learning, Java architecture, and other popular fields.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.