Yazzyk/dsh-file-shield ↗★ 0

dsh-file-shield

DeepSeek Harness 插件:在 Web GUI 里点选文件或目录,屏蔽 agent 对它们的读取、搜索、写入与编辑,使机密内容与敏感词不进入对话(含敏感词导致请求 400 的场景)。Blocks an agent from reading, searching, writing, or editing chosen files and directories, keeping their contents out of the conversation. 适合需要保护本地机密内容、防止敏感词进入模型对话的安全任务。

Package
dsh-file-shield
Compatibility
Unverified
Cordis peer range
^4.0.2
Version
0.1.0
License
MIT
Last updated
Sep 19, 2026

Install

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:Yazzyk/dsh-file-shield

怎么配置

从插件页面(日常用法)

侧边栏 Plugins → Installed → dsh-file-shield:

  • 选择文件… 打开插件自带的浏览器,逐层进入目录并点选文件;
  • 系统目录选择器… 调用 dsh 自己的目录选择器(需要装载 workspace UI);
  • 也可以直接输入路径或 glob;
  • 保存 把规则写进 file-shield 设置命名空间(用户层),恢复部署默认 清掉用户层。

写进设置层的规则立即对下一次工具调用生效,不需要重启。因为宿主没有暴露列文件的接口(目录选择器只列目录、workspaceFiles.list 限于会话工作区),选文件用的是一条插件自己的只读路由 GET /file-shield/browse?path=:只接受 GET、只列目录内容、Cache-Control: no-store,并且每个请求都先过 ctx.connection.requestRejection()——Host/Origin 围栏挡 DNS rebinding 与跨站请求,浏览器会话 Cookie 挡未认证调用。该路由只在同时装配了 webServer 与 connection 的组合里挂载;缺其中任一时文件浏览器不可用,而不是以无认证方式开放目录列举。

从 cordis.patch.yml(部署默认)

profile 的 patch 层可以整段替换该行的 config:

- insert:
    - id: file-shield
      name: dsh-file-shield
      config:
        deny:
          - '**/.env'
          - '**/.env.*'
          - '**/*.pem'
          - '~/.dsh/.credentials.yaml'
        matchCase: false
        guidance: true
        extraPathArgs:
          some_reader_tool:
            - target
        extraCommandArgs:
          some_shell_tool: script
字段默认含义
deny[]规则列表。空列表是合法状态:新装插件不自己发明规则
matchCasefalse是否区分大小写
guidancetrue是否注入一条系统提示,说明被拒绝是策略而不是故障
extraPathArgs{}其它插件的读文件工具:工具名 → 路径参数名数组
extraCommandArgs{}其它插件的 shell 工具:工具名 → 命令参数名

设置层的用户规则会覆盖(而不是叠加)这一层的 deny;matchCase、guidance、extraPathArgs、extraCommandArgs 只在这一层。