Repository navigation
Release v1.4.1
Follow-up to #18, which added the pi adapter. Completes the source support.
The gap
Pi persists !command — a shell command typed at its own prompt — with the
role bashExecution. The adapter skipped that role, so a session spent driving
a build or a test run by hand reported no human involvement at all beyond
its session edges.
The model cannot produce one of these. It reaches the shell through the bash
tool, which is persisted as a tool result and is already treated as agent
activity. So bashExecution is unambiguous keyboard evidence — more direct
than the session edges that were carrying these sessions.
It is counted in a foreground session only: inside a subagent the command
was issued by the agent driving it, not typed by anyone. !!command, which
keeps output out of the model's context, counts the same — someone still typed
it.
Measured
A session holding one typed !npm run lint:
| Binary | prompts | human work |
|---|---|---|
| v1.4.0 (shipped) | 0 | 1800 s |
| this PR | 1 | 1810 s |
Real local history is unchanged (203 prompts either way), because the bash
tool — not ! — is what an agent-driven session uses. This affects people who
drive Pi from the keyboard.
Privacy
The command and its output are still never read. They reach the deserializer as
ignored fields, exactly like a response body, so nothing about them can appear
in a report or the cache. A test asserts that a token placed in a command and
in its output is absent from the serialized result.
Verification
cargo fmt --all -- --check,cargo clippy --all-targets --locked -D warnings,cargo test --locked— all clean- 228 unit + 9 integration tests pass, including 2 new tests covering the
foreground and delegated cases