a5557/dsh-agent-guard ↗★ 0

dsh-agent-guard

DeepSeek Harness guardrail plugin: evidence-first read-only inspection plus write-time protection of DSH private storage. One command captures authoritative state - workspace registration, session identity headers, directory layout, host running state - so a count difference is never mistaken for data loss; writes to protected paths are intercepted before dispatch, backed up first, and never allowed while the host may still be running. No network, no telemetry, zero runtime dependencies. 适合需要防止数据丢失、审计操作状态并拦截非安全写入的系统防护任务。

Package
dsh-agent-guard
Compatibility
Unverified
Version
0.1.0
License
MIT
Last updated
Oct 3, 2026

Install

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:a5557/dsh-agent-guard

Usage

As tools (installed)

guard_inspect(scope?, workspace?, maxSessions?, includeHeaders?, redact?)
guard_journal(action?, limit?, snapshot?)

guard_inspect produces the evidence report (read-only, writes nothing anywhere). guard_journal reports the guard's own state: whether it is enabled, whether the journal is writable and its hash chain intact, the rollback points, and the most recent protected operations. action: "trace" shows one operation in detail; the rollback action returns human rollback instructions — there is no automatic rollback.

Interception (automatic, once installed)

Protected writes are decided at tools/pre-execute, where deny short-circuits before the tool body runs. That is the difference between blocking and warning after the fact. Defaults:

  • a write to DSH core data while DSH is not known to be stopped → refused (fail-closed: "cannot determine" counts as running);
  • a permitted protected write → backup first, then ask; if the backup fails or exceeds the budget (8 MiB per file by default) → refused, never allowed unbacked;
  • two consecutive writes on one path whose checksum changed → circuit breaker, handed to a human through the approval channel;
  • a generated .bat/.cmd/.ps1/.sh that references a protected path → flagged as emit-script and never silently allowed.

In the UI

The plugin ships a client half, so it has a native seat in the interface:

  • a sidebar icon (the sidebar.panellist seat, currently unoccupied by official plugins) that opens a main panel showing guard status, rollback points, and recent protected operations;
  • a settings page ("环境护栏") under Settings, showing the same status plus exactly how to disable the guard.

Both views are strictly read-only: no repair, no migration, and no rollback button. The client half is a hand-written window.__ModuleLoader__.load bundle, so this package needs no build step and adds no devDependencies. An equivalent same-origin HTTP panel is also served at /agent-guard as a fallback for hosts without a client bundle path.

The official client bundles are built with tsdown; this package hand-writes the same contract (React.createElement instead of JSX), and unit tests execute the bundle in a controlled sandbox, asserting all three seat registrations and the absence of any write path.