pibox
Install, configure, or run pi-coding-agent through the pibox wrapper, or connect to its HTTP, MCP, Telegram, or cron surfaces.
Rank
62
Safety
84
Downloads
1.7k
Updated
Oct 10, 2026
Version
0.19.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.7K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.7K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.19.0release · observed Oct 7, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17fq93tmpky791n7516jcn08n83sfn2:pibox- Install using `clawhub skill install s17fq93tmpky791n7516jcn08n83sfn2:pibox` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/psyb0t/pibox before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pibox/snapshot"
Documentation
CLAWHUB
148,393 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
name: pibox
description: "Install, configure, or run pi-coding-agent through the pibox wrapper, or connect to its HTTP, MCP, Telegram, or cron surfaces."
homepage: https://github.com/psyb0t/docker-pibox
user-invocable: true
metadata:
{ "openclaw": { "emoji": "🥧", "primaryEnv": "PIBOX_URL", "requires": { "bins": ["docker", "curl"] } } }
---
# pibox
[pi-coding-agent](https://github.com/earendil-works/pi-mono/tree/main/packages/coding-agent) inside an [aicodebox](https://github.com/psyb0t/docker-aicodebox) container. One image, seven ways in: interactive shell, one-shot exec, HTTP REST API, OpenAI-compatible endpoint, MCP server, Telegram bot, cron scheduler.
You talk to pibox, pibox talks to pi, and Pi talks to the configured upstream LLM. Use `PIBOX_PROVIDER_*` for Pi's documented custom HTTP APIs, including LiteLLM and Anthropic-compatible endpoints. `ANTHROPIC_*` remains a compatibility shortcut for existing Anthropic Messages deployments.
For installation and configuration, see [references/setup.md](references/setup.md).
## Agent execution
Use `pibox` when it is on `PATH`. Run it from the workspace the user named.
Do not assemble a new `docker run` command for routine interactive or one-shot
work. The wrapper owns the workspace mount, `~/.pi`, aicodebox state, SSH
state, image selection, and container lifecycle.
```bash
pibox # interactive Pi
pibox -p "inspect this workspace" # one-shot work
pibox -p "review this change" --thinking high
PIBOX_FULL=1 pibox -p "run the full suite"
```
Configure the Pi upstream before the first run with `PIBOX_PROVIDER_*` or the
supported `ANTHROPIC_*` compatibility variables. Use an HTTP or MCP endpoint
only when the user asks for a service or provides an already-running remote
URL. MCP plugins connect to a server. They do not replace the local wrapper.
Start a local API and MCP server only when the user asks for one. Set the
actual model identifiers and distinct bearer tokens:
```bash
PIBOX_DETACH=1 \
PIBOX_API_MODE=1 \
PIBOX_MCP_MODE=1 \
PIBOX_AVAILABLE_MODELS=your-model-id \
PIBOX_API_MODE_TOKEN=your-api-token \
PIBOX_MCP_MODE_TOKEN=your-mcp-token \
pibox
```
If `pibox`, `codexbox`, and `claudebox` were installed in the same command
directory, a box can invoke a sibling command directly. The parent wrapper
passes the real host paths and the sibling wrapper file. Do not set
`AICODEBOX_HOST_*`, copy wrapper files, or manually mount another box's state
directory. If the sibling command is absent, ask the user to install it or to
choose another approach.
## Security & safety
- **No auth when `PIBOX_API_MODE_TOKEN` is unset.** With it empty the REST/OpenAI-compatible API surface is UNAUTHENTICATED — anyone who can reach it gets full agent-execution and workspace file-read/write/delete access. NEVER expose such an instance on a network or to untrusted agents; set the token and bind to loopback / behind an authenticating proxy.
- **No auth when `PIBOX_meta.json
{
"ownerId": "kn79dhvmpjng4rp2jjk8k0v5xx80ccbk",
"slug": "pibox",
"version": "0.19.0",
"publishedAt": 1791393868183
}references/setup.md
# pibox setup
## Requirements
- Docker
- An LLM endpoint supported by Pi's custom HTTP provider configuration. `PIBOX_PROVIDER_*` accepts an endpoint URL, protocol, API key or token, and model. It covers LiteLLM, Anthropic Messages endpoints, and Google Generative AI. `ANTHROPIC_*` remains available for existing Anthropic-compatible deployments. Pi drives the model; pibox drives Pi.
- A target workspace. Run the wrapper from that directory so it mounts the path and preserves Pi state.
## Quick Install
### Host wrapper
Install the wrapper for interactive and one-shot use:
```bash
curl -fsSL https://raw.githubusercontent.com/psyb0t/docker-pibox/main/install.sh | bash
```
Install `pibox`, `codexbox`, and `claudebox` in the same command directory,
normally `/usr/local/bin`, when a box needs to launch another. Each wrapper
mounts sibling wrapper files read-only. The sibling wrapper then asks the host
Docker daemon to mount its own data directory.
### Interactive / one-shot (no server)
```bash
pibox
pibox -p "inspect this workspace"
PIBOX_FULL=1 pibox -p "run the full test suite"
```
Use the wrapper for normal interactive and one-shot work. It handles the
workspace mount, Pi state, aicodebox state, SSH state, image selection, and
nested launch context. Do not construct a `docker run` command unless the user
explicitly asks for a direct container deployment.
### REST / OpenAI-compatible / MCP server
```bash
docker run -d --name pibox --network host \
-e PIBOX_API_MODE=1 \
-e PIBOX_API_MODE_TOKEN=your-secret \
-e PIBOX_AVAILABLE_MODELS=glm-4.6,glm-4.5-air \
-e PIBOX_MCP_MODE=1 \
-e PIBOX_MCP_MODE_TOKEN=your-mcp-secret \
-e ANTHROPIC_AUTH_TOKEN=your-token \
-e ANTHROPIC_BASE_URL=https://api.z.ai/api/anthropic \
-e ANTHROPIC_MODEL=glm-4.6 \
-v "$PWD/workspace:/workspace" \
psyb0t/pibox:latest
```
`--network host` is convenient for local use; for anything else publish the port explicitly (`-p 8080:8080`) instead.
**Verify:** `curl http://localhost:8080/healthz` returns `{"ok": true, "adapter": "pi"}`.
### Telegram bot
```bash
docker run -d --name pibox-tg \
-e PIBOX_TELEGRAM_MODE=1 \
-e PIBOX_TELEGRAM_MODE_TOKEN=your-bot-token \
-e ANTHROPIC_AUTH_TOKEN=your-token \
-e ANTHROPIC_BASE_URL=https://api.z.ai/api/anthropic \
-e ANTHROPIC_MODEL=glm-4.6 \
-v "$PWD/workspace:/workspace" \
-v "$PWD/telegram.yml:/home/aicode/.aicodebox/telegram.yml:ro" \
psyb0t/pibox:latest
```
Requires a `telegram.yml` with at least `allowed_chats` set (see [Telegram bot mode](../SKILL.md#telegram-bot-mode)) — the bot ignores messages from chats not on the allowlist.
### Cron scheduler
```bash
docker run -d --name pibox-cron \
-e PIBOX_CRON_MODE=1 \
-e PIBOX_CRON_MODE_FILE=/config/cron.yaml \
-e ANTHROPIC_AUTH_TOKEN=your-token \
-e ANTHROPIC_BASE_URL=https://api.z.ai/api/anthropic \
-e ANTHROPIC_MODEL=glm-4.6 \
-v "$PWD/workspace:/workspace" \
-v "$PWD/cron.yaml:/config/cron.yaml:ro" \
psyb0t/pibox:latest
```
###skill-card.md
## Description: Install, configure, or run pi-coding-agent through the pibox wrapper, or connect to its HTTP, MCP, Telegram, or cron surfaces. This skill is ready for commercial/non-commercial use. ## Publisher: [psyb0t](https://clawhub.ai/user/psyb0t) ### License/Terms of Use: MIT-0 ## Use Case: Developers use pibox to run pi-coding-agent against selected workspaces and connect it to scripts, HTTP clients, MCP tools, Telegram, or scheduled jobs. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: An exposed API or MCP service without its own bearer token can grant agent execution and workspace file access to anyone who can reach it. Mitigation: Set distinct API and MCP tokens and bind ports to loopback; add stronger access controls before any shared or public exposure. Risk: Piping an installer into a shell, using an unpinned image, or deploying with host networking increases installation and exposure risks. Mitigation: Inspect the installer first, pin the Docker image by digest, and prefer explicit loopback port bindings to host networking. Risk: Agent access to broad workspace mounts and destructive file or run operations can cause irrecoverable data loss. Mitigation: Mount only necessary workspaces, back up important data, and require explicit confirmation of a specific target before deletion. ## Reference(s): - [pibox setup guide](artifact/references/setup.md) - [pibox project homepage](https://github.com/psyb0t/docker-pibox) - [pi-coding-agent](https://github.com/earendil-works/pi-mono/tree/main/packages/coding-agent) - [pibox on ClawHub](https://clawhub.ai/psyb0t/skills/pibox) ## Skill Output: **Output Type(s):** [Text, Code, Shell commands, Configuration instructions] **Output Format:** [Markdown with code and shell examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [May run an agent that reads and changes files in a selected workspace.] ## Skill Version(s): 0.19.0 (source: ClawHub release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/psyb0t/skills/pibox",
"sourceUrl": "https://clawhub.ai/psyb0t/skills/pibox",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T04:58:14.784Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pibox/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pibox/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T04:58:14.784Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.7K downloads",
"href": "https://clawhub.ai/psyb0t/pibox",
"sourceUrl": "https://clawhub.ai/psyb0t/pibox",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T04:58:14.784Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.19.0",
"href": "https://clawhub.ai/psyb0t/pibox",
"sourceUrl": "https://clawhub.ai/psyb0t/pibox",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-07T17:24:28.183Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pibox/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-pibox/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.19.0",
"description": "pibox 0.19.0 - Updated REST API MCP server route: now mounted at `/mcp/` (with trailing slash); slashless `/mcp` still supported. - Documentation updates in SKILL.md to reflect API path changes and clarify security/safety details. - Removed obsolete skill-card.md file. - Minor clarifications and corrections in setup and usage instructions.",
"href": "https://clawhub.ai/psyb0t/pibox",
"sourceUrl": "https://clawhub.ai/psyb0t/pibox",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-07T17:24:28.183Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
