# Bug Report — port-pi-guard ## Review Scope Pi dev guard plugin (guard.ts, package.json), integration in register-guards.sh and harness-integration.md. ## Findings ### No Critical Bugs Found The guard.ts properly implements the pi ExtensionAPI pattern with `pi.on("tool_call", ...)`. It correctly intercepts edit/write/bash tools, calls status.py, and returns block responses. The fallback to allowing when status.py is unavailable is reasonable (fail-open for offline scenarios). ### Minor Observations - Lines 38-40 contain unreachable dead code (the import is shadowed by the child_process import below) - The bash tool regex check (`\b(write|tee|cp|mv|sed\b.*-i|dd\b.*of=)\b`) could miss some write patterns ## Verdict No blocking bugs. Ready for adversarial review.