dsh-allow
DeepSeek Harness 文件系统权限插件:按 read/write/create/delete/execute 授权路径,而不是按命令名。 / Filesystem permissions for DSH shell calls, granted per path and capability instead of per command name. 适合需要精细控制文件系统读写执行权限的安全管理任务。
Install
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:DWJZ/dsh-allowREADME
Read the full README ↗Configuration
- id: dsh-allow
config:
rulesFile: /path/to/rules.json # default $DSH_HOME/dsh-allow.json
auditFile: /path/to/audit.ndjson # default $DSH_HOME/dsh-allow-audit.ndjson
audit: true # false turns the audit log off
sessionGrantTtlMs: 600000 # backstop lifetime of "allow once"
enforce: auto # auto | full | guarded | process | writes | off
autoReview: # optional: let the model answer "allow once"
enabled: false # the card stays in charge when off
timeoutMs: 10000
grants: # deployment grants, same shape as a stored rule
- path: /opt/homebrew
recursive: true
access: { read: true, execute: true }
A rules.json written by dsh-allow 0.1 (the command-prefix model) reads as empty and is kept as .v2.bak on the first write; those rules said nothing about filesystem capabilities and cannot be translated.