v0.4.0
Highlights
pi-experiment-ops 0.4.0 adds interactive approval controls for Pi tools, shell commands, and direct MCP tools using pi-permission-system 0.8.0.
Unmatched tool calls now ask for approval by default:
- Allow once approves the current call.
- Allow for session remembers approval for that tool during the current session.
- Deny rejects the call.
Use /permissions auto, /permissions ask, or /permissions status to control approval behavior in the TUI. Pattern-based policies can be configured in .pi-experiment-ops/agent/pi-permissions.jsonc.
MCP and CodeMode
- Direct MCP tools pass through the shared permission gate.
- Existing
approveToolssettings in.pi/mcp.jsonremain an optional, independent MCP-adapter gate. - MCP adapter script mode is disabled by default, making CodeMode the bundled scripted tool-call interface.
- Permission policy gates the
codemode_executelaunch. Calls made inside an accepted CodeMode cell are not prompted separately.
Workspace configuration
New workspaces receive:
.pi-experiment-ops/agent/permission-system.json.pi-experiment-ops/agent/pi-permissions.jsonc
Initialization preserves existing files and configuration.
Validation
The release was validated with:
- Real Pi 0.85.1 sessions
- Direct MCP tools
- Allow-once and session approval flows
- Session-only auto-allow behavior
- CodeMode background execution
- Standalone tarball installation and package acceptance