Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 8 additions & 6 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -27,12 +27,14 @@ From Bash, bootstrap the profile with one command:
(tmp=$(mktemp -d) && git clone --depth 1 https://github.com/eggmasonvalue/secstack "$tmp" && node "$tmp/scripts/bootstrap.mjs"; status=$?; rm -rf "$tmp"; [ "$status" -eq 0 ])
```

The bootstrap is safe to rerun. It installs the unpinned top-level Pi package sources,
merges only SecStack-managed package entries, shell-path configuration, and `quietStartup`
preference into the SecStack profile's `settings.json` and creates a profile-local Python environment. It links the
profile's `SYSTEM.md` to the installed SecStack package, so `pi update --extensions` updates the
research-agent identity and prompt envelope. It does not install coding-task guidance or link
global `AGENTS.md` or `APPEND_SYSTEM.md` files into the profile.
The bootstrap is safe to rerun. It configures `allowScripts` for `agent-browser` in the
profile's npm root (`~/.pi/secstack-agent/npm/package.json`), installs the unpinned top-level
Pi package sources, merges only SecStack-managed package entries, shell-path configuration,
and `quietStartup` preference into the SecStack profile's `settings.json` and creates a
profile-local Python environment. It links the profile's `SYSTEM.md` to the installed SecStack
package, so `pi update --extensions` updates the research-agent identity and prompt envelope.
It does not install coding-task guidance or link global `AGENTS.md` or `APPEND_SYSTEM.md` files
into the profile.

It does not overwrite the profile's `auth.json`, `models.json`, provider settings,
model selections, UI preferences, sessions, or unrelated settings.
Expand Down
32 changes: 29 additions & 3 deletions scripts/bootstrap.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,9 @@
* Install SecStack and its independently managed Pi packages into the isolated
* SecStack profile.
*
* This script deliberately changes only the SecStack profile's package list,
* shell command prefix, quietStartup setting, and optional Bash launcher.
* This script deliberately changes the SecStack profile's package list,
* shell command prefix, quietStartup setting, allowScripts in the profile's npm
* root, and optional Bash launcher.
*/
import { execFileSync } from "node:child_process";
import {
Expand All @@ -25,7 +26,9 @@ import { dirname, join, relative, resolve } from "node:path";

const agentDir = resolve(join(homedir(), ".pi", "secstack-agent"));
const settingsPath = join(agentDir, "settings.json");
const npmBin = join(agentDir, "npm", "node_modules", ".bin");
const npmDir = join(agentDir, "npm");
const npmPackageJsonPath = join(npmDir, "package.json");
const npmBin = join(npmDir, "node_modules", ".bin");
const venvDir = join(agentDir, ".venv");
const systemPromptPath = join(agentDir, "SYSTEM.md");
const bashrcPath = join(homedir(), ".bashrc");
Expand Down Expand Up @@ -299,8 +302,31 @@ async function offerLauncher() {
}
}

function ensureNpmAllowScripts() {
mkdirSync(npmDir, { recursive: true });
let pkg = { name: "pi-extensions", private: true };
if (existsSync(npmPackageJsonPath)) {
try {
pkg = JSON.parse(readFileSync(npmPackageJsonPath, "utf8"));
} catch {
// Keep default
}
}
const allowScripts =
pkg.allowScripts && typeof pkg.allowScripts === "object"
? pkg.allowScripts
: {};
if (!allowScripts["agent-browser"]) {
pkg.allowScripts = { ...allowScripts, "agent-browser": true };
const temp = join(npmDir, `.package.${process.pid}.tmp`);
writeFileSync(temp, `${JSON.stringify(pkg, null, 2)}\n`, "utf8");
renameSync(temp, npmPackageJsonPath);
}
}

async function main() {
console.log(`Configuring SecStack Pi under ${agentDir}`);
ensureNpmAllowScripts();
for (const source of managedSources) {
runPi(["install", source]);
}
Expand Down
Loading