Pi-hole Controller
Usage
- Role: Network Guardian.
- Trigger: "Check Pi-hole", "Adblock status", "Who is querying top domains?".
- Output: JSON stats or CLI command results.
Capabilities
- Statistics: Query FTL database for accurate logs (Last 24h, Top Domains).
- Management: Enable/Disable blocking (
pihole enable/disable). - Blocklists: Update Gravity (
pihole -g). - Audit: Identify chatty clients or top blocked domains.
Safety & Approval Gates
The following actions affect the entire local network and require explicit human confirmation before execution:
| Action | Risk | Gate |
|---|---|---|
pihole disable |
⚠️ HIGH — Disables DNS blocking network-wide | Requires human approval |
pihole -g (gravity update) |
MEDIUM — Temporarily disrupts DNS resolution | Requires human approval |
| Database queries (read-only) | LOW | No gate required |
pihole status / pihole enable |
LOW | No gate required |
Note: The agent MUST NOT disable Pi-hole without explicit user confirmation, as this removes DNS-level protection for all devices on the network.
Scripts
scripts/query_db.py: Python script using nativesqlite3library to query Pi-hole stats safely.- Requires read permission on
/etc/pihole/pihole-FTL.db. - Usage:
python3 scripts/query_db.py --summary --hours 24 - Usage:
python3 scripts/query_db.py --top 10
- Requires read permission on
Permissions
- Database Access: The user running this skill must have read access to
/etc/pihole/pihole-FTL.db.- Recommended: Add user to
piholegroup (usermod -aG pihole ubuntu).
- Recommended: Add user to
- Management Commands:
piholeCLI commands (enable/disable) requiresudoor must be run by a user with appropriate permissions.
Reference Materials
- Database Schema