
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
@cuzfrog/pi-module-gates
Advanced tools
pi extension that controls the entropy of the codebase by enforcing code module boundaries.
Experimental pi cli extension that controls the entropy of the codebase by enforcing code module boundaries. It helps combat slop generation and code architecture degradation.
AI coding agents produce edits with limited context knowledge (myopia) — their changes may leak implementation details, and break architectural contracts (slop).
Module contracts as guardrails. Each directory can contain a descriptor file that declares:
readonly — files and directories the agent must not touchno-new-exports — files where no new exports are allowed (body still editable)visible — the set of exports allowed to be added or modified in that moduleThe extension intercepts agent write/edit operations and enforces these contracts. Violations are blocked with a clear reason.
The attempt to add 2 public helper functions is blocked, forcing the agent to re-think the design.

no-new-exports list?visible list?index.ts or mod.rs. A child module may import from a parent module's internal files (not recommended but allowed). (Only Typescript/JavaScript and Rust are supported)pi install npm:@cuzfrog/pi-module-gates
Or load directly for a single session:
pi -e npm:@cuzfrog/pi-module-gates
A module descriptor is a Markdown file (default name: MODULE.md) placed in a directory. You can piggy-back on your module context file for example CONTEXT.md.
---
readonly: [mod.rs]
---
Any prose for the agent to better understand the module.
no-new-exports: [mod.rs]
No-new-exports files cannot change their surface size: no new exports or public entries are allowed. The file body is still editable.
A skill module-no-new-exports-all has been included to populate no-new-exports entries in modules.
visible:
- greet # equivalent to `path: ./greet`
- sub/mod1/Foo
or:
visible:
- path: my_function
modifier: pub(crate) # (optional) demands an exact match
| Scenario | Behavior |
|---|---|
visible key absent or no MODULE.md | Module is unconstrained — exports are not gated. Equivalent to null internally. |
visible: [] | Module is fully closed — no new exports may be added. Editing existing exports is still allowed. |
| Malformed YAML frontmatter | The module is left unguarded and an info notification is emitted. |
project/
MODULE.md visible: [Foo, Bar]
src/
MODULE.md visible: [Bar, Baz]
app.ts ← checked against `src/MODULE.md` only
A MODULE.md only enforces exports within its immediate directory.
# parent/MODULE.md
visible:
- sub/Tool # type Tool is allowed to be imported from parent
# parent/sub/MODULE.md (before complement pass)
visible:
- Bar # type Bar is allowed to be imported from parent/sub within parent, but not outside parent
A MODULE.md semantically gates exposures at the module level it resides.
Add a module-gates entry to .pi/settings.json:
{
"module-gates": {
"moduleDescriptorFileName": "MODULE.md",
"moduleDescriptorReadonly": "file",
"sourceRoots": ["src/"],
"outputModuleProseOnBlock": false
}
}
| Option | Default | Description |
|---|---|---|
moduleDescriptorFileName | MODULE.md | File name used for module descriptors (case-insensitive) |
moduleDescriptorReadonly | "frontmatter" | "file" makes the whole descriptor readonly; "frontmatter" locks only the YAML frontmatter (body prose stays editable); "off" disables descriptor readonly. true/false are also accepted for backward compatibility. |
sourceRoots | ["src/"] | Directories to scan for descriptor files and enforce gates. Pass a single string for one root, or an array for multiple roots (e.g. monorepos with ["packages/app/src/", "packages/lib/src/"]). Use [""] to scan from the project root. Legacy singular sourceRoot (string) is still accepted. |
disableModuleInterfaceImportGate | false | When true, imports will not be forced to be from module interface. |
disableSystemPrompt | false | When true, skip injecting the module-gates hint into the agent's system prompt. |
outputModuleProseOnBlock | false | When true, the violating module descriptor's prose is appended to the block message so the agent sees the contract context. Disabled by default to keep the error message concise. |
When no settings file exists or no module-gates key is present, defaults apply.
Add the following to .claude/settings.json in the current project, pointing the PreToolUse hook at the installed binary.
{
"hooks": {
"PreToolUse": [
{
"matcher": "Edit|MultiEdit|Write",
"hooks": [
{
"type": "command",
"command": "bun ${CLAUDE_PROJECT_DIR}/node_modules/@cuzfrog/pi-module-gates/src/claude/pre-tool-use.ts",
"statusMessage": "Module gate checking edit..."
}
]
}
]
}
}
If pi-module-gates is already installed in pi global dir, you can use below path instead:
~/.pi/agent/npm/node_modules/@cuzfrog/pi-module-gates/src/claude/pre-tool-use.ts
You need to add system-prompt.md manually to your context.
Claude Code uses the same .pi/settings.json#module-gates block as the pi extension. See the Configuration section above.
Prompt:
Check if PreToolUse hook `pi-module-gates` is triggered and runs expectedly.
MIT
Cause Chung (cuzfrog@gmail.com)
FAQs
pi extension that controls the entropy of the codebase by enforcing code module boundaries.
The npm package @cuzfrog/pi-module-gates receives a total of 9 weekly downloads. As such, @cuzfrog/pi-module-gates popularity was classified as not popular.
We found that @cuzfrog/pi-module-gates demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.