精选
为什么选中它
待人工精选——以下事实来自源码仓库。
它能做什么
Runtime tool policy, dangerous-command guard, and output redaction for DeepSeek Harness.
适合谁
想用 DSH 获得这项能力的用户;装前建议先看源码和文档。
风险提示
- 未发现明显风险信号;安装前仍建议查看源码。
Runtime tool policy, dangerous-command guard, and output redaction for DeepSeek Harness.
待人工精选——以下事实来自源码仓库。
Runtime tool policy, dangerous-command guard, and output redaction for DeepSeek Harness.
想用 DSH 获得这项能力的用户;装前建议先看源码和文档。
dsh plugin --profile web add github:lonelymoon87/dsh-guardian 作者没有声明支持的平台。
tools/pre-execute waterfall classifies dangerous shell, SQL, and structured file-write arguments as deny, ask, or unchanged. - standard, strict, and permissive profiles provide different approval levels while retaining non-negotiable deny rules. - Custom regular-expression rules add deployment-specific deny or ask decisions. - A tools/post-execute waterfall redacts common credentials from canonical JSON results, failures, rendered text, and block feedback. - Consecutive text blocks are scanned as one stream so splitting a credential across blocks does not bypass redaction. - /security-review loads a bundled, read-only security-review skill. The MVP is not a process sandbox, authorization system, data-loss-prevention service, or substitute for the provider policies mounted below it. ## Policy behavior The built-in rules deny recursive forced deletion of root or home paths, network-response pipes into shells, raw writes to /dev, and writes to /etc. Force pushes, destructive SQL, and other recursive forced deletions ask for approval. Strict mode additionally asks for sudo; permissive mode retains only deny rules. Guardian always delegates through next(). When another policy listener returns a decision, the most restrictive result wins: deny outranks ask, which outranks allow. ## Redaction behavior Built-in patterns cover AWS access-key IDs, GitHub tokens, sk- API keys, PEM private-key blocks, and common credential assignments. Redaction is applied to the canonical JSON value when one exists, preserving arrays, objects, numbers, booleans, and null values. This prevents Code Mode and downstream renderers from retaining an unredacted value behind safe-looking display text. Logs contain only the tool name, match count, and redaction labels. The plugin does not append custom session events because the current external plugin API does not expose an ignorable event envelope; emitting a required unknown event would make old sessions unreadable after uninstall. ## Install The package currently targets DSH 0.1.0-rc.6 plugin APIs and Node.js ^22.19 || >=24. sh dsh plugin --profile web add https://github.com/lonelymoon87/dsh-guardian/releases/download/v0.1.2/dsh-guardian-0.1.2.tgz The release tarball is prebuilt and needs no build allowance. A pinned source install is also supported: sh dsh plugin --profile web add github:lonelymoon87/dsh-guardian#v0.1.2 The source install runs this package's prepare build. pnpm 10 and later reject it until the profile allowlists the exact package key printed by the failed command; apply that instruction and rerun the same dsh plugin add command. Replace web with headless to install into the one-shot agent profile. To upgrade, rerun dsh plugin add with the newer release URL. To uninstall: sh dsh plugin --profile web remove dsh-guardian ## Configuration yaml - id: guardian name: dsh-guardian config: profile: standard rules: - name: production-host pattern: production\\.internal action: ask reason: production target requires review redaction: enabled: true patterns: - label: internal-token pattern: INT_[A-Z0-9]{12} Regular-expression flags may contain only i, m, s, and u. Invalid expressions and labels fail during plugin loading. ## Verification The tests cover positive and negative cases for every built-in rule, structured paths, profile behavior, downstream policy composition, nested canonical values, custom credentials, block feedback, split text blocks, disabled redaction, command dispatch, and invalid configuration. - The v0.1.2 tarball installs directly from its HTTPS release URL into a clean DSH profile. - The packed bundle and pinned GitHub source install both appear in dsh --dump-config. - CI covers Node 22.19 and Node 24; a scheduled workflow repeats the real install against @deepseek-ai/dsh@latest. - Bugs and compatibility reports are tracked in GitHub Issues. ## License MIT不看 Star,人工一条条挑的。
把 DSH 的 settings.yaml 做成可视化看板:所有已注册的 settings namespace——包括官方界面从未覆盖的第三方插件配置——都渲染成可编辑表单。项目还早,但方向很对:告别手改 YAML。
给 DSH 的 DIY 轨迹可视化:把 agent 的计划与执行画成图,不用翻原始日志也能看清它在干嘛。项目还早,但补上了「一眼看懂 agent 在做什么」这个真实缺口。
从 Claude Code / Codex 把活派给 DSH:在宿主内拉起带分级预设的 DSH agent 会话,看原生子代理进度,还能借它的多模态桥给纯文本的 DSH 补上视觉和生图。编排型插件,把 DSH 变成其他编码 agent 的后端。