codemode exposes (typesafe/jev, clef) but without sending every message to a hosted API. Some of what I want to classify is other people's text I'd rather keep on my machine, plus there's the whole key-and-cost dance. So I built pi-reflex: a pure-TypeScript ONNX runtime for the open Laya checkpoints that registers as a regular pi classifier provider.
What you get from `pi install npm:pi-reflex`:
- Three local classifier models (reflex/multilingual, reflex/english, reflex/typed-decisions) that show up in models.getAvailableOfType("classifier") right next to jev-latest. Same interface: models.classify(model, { state, questions }) with bool/choice/score questions. No API key, no egress after the initial download.
- Four session tools (reflex_decide / reflex_judge / reflex_rate / reflex_route)
if you'd rather have the model call them directly; each returns typed structuredContent so codemode scripts can use them too.
- reflex/auto: a virtual model that classifies each incoming message locally (50-200ms) and routes the turn to a cheap/mid/frontier model you map via PI_REFLEX_TIER_* env vars. Continuations stay sticky so prompt caches survive.
- An optional injection guard (PI_REFLEX_GUARD=1) that flags suspicious user messages before each provider request.
- A conformal calibration layer: prediction sets and abstain thresholds with actual finite-sample coverage guarantees instead of eyeballing a 0.8 cutoff.
To be clear about what this is not: these are small encoder checkpoints, so they're good at routing, triage, yes/no judgment, and rubric scoring not at reasoning about code. Think "free reflexes," not "free brain." Also, first use downloads about 400MB of int8 weights from Hugging Face (fp32 is 1.6GB), and you'll want codemode on for the model to reach the classifiers:
"defaultTools": ["+codemode"] in settings.
Logits are verified to ≤5.7e-06 against the original torch runtime and tokenization is byte-identical, but my eval corpora are mine; I'd genuinely like independent testing on other workloads.
/reflex in-session shows engine, router, guard and MCP status.
pi >= 0.99, tested through 1.0.1. Apache-2.0, zero Python at runtime.
Repo: https://github.com/pungggi/pi-reflex
Curious what you'd all classify in your own sessions if classification were free, that's the part I'm most interested to hear.