kovey/dsh-engineering-suite--packages-dsh-role-guard ↗★ 0
dsh-role-guard
Role and permission layer for DeepSeek Harness: one Markdown file per agent role (persona + model + tool whitelist), least-privilege delegation through team_delegate, and a strict write/read-only split. 适合需要对子Agent进行精细化角色定义和权限最小化管控的场景。
Other repositories with this package name
Install
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:kovey/dsh-engineering-suite#4a618ac4376c4a075c99c92b69895163bb21b0ce&path:packages/dsh-role-guardREADME
Read the full README ↗配置
| 键 | 默认 | 说明 |
|---|---|---|
enabled | true | |
logFile | ~/.dsh/role-guard.log | |
includeBuiltin | true | 是否加载包内角色 |
roleDirs | [] | 额外角色目录(相对会话工作区解析) |
roles | [] | 内联角色(最高优先级) |
provider | 'spawn' | ctx.subagents 的 provider 名 |
defaultRole | 'developer' | team_delegate 省略 role 时使用 |
readonlyDeny | ['write','edit','str_replace_editor'] | 只读角色强制剥离的工具 |
maxOutputChars | 6000 | 子 Agent 产出回传上限 |
allowModelOverride | true | 是否允许 team_delegate 按调用覆盖角色路由(model / reasoningEffort / maxTokens);false = 忽略并在结果里说明(成本决策由宿主把关) |
injectSpec | true | 是否把 mission 规格注入子 Agent prompt |
enforceSkillWhitelist | true | 是否在调用时强制角色的技能白名单 |
skillTools | ['skill'] | 会加载技能的工具名(只有这些工具被上面的开关检查) |
prompt.enabled / prompt.order | true / 610 |