dsh-tm-guard
Time-Machine-backed autonomous agent permission gate for DeepSeek Harness (dsh). Allows TM-rollback-able operations, blocks everything else. 适合需要限制智能体写操作、网络及系统权限,并支持自动快照回滚的安全任务。
インストール
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:ChaoJie0/dsh-tm-guardドキュメント
README 全文を読む ↗Configuration
The plugin accepts a Partial on its inserted row. Users normally override fields from their own profile's cordis.patch.yml (later patch layers win per row; a patch replaces the whole row config).
| Field | Type | Default | Meaning |
|---|---|---|---|
protectedPaths | string[] | [process.cwd()] | Absolute path prefixes writable by the agent. |
snapshotCooldownSeconds | number | 30 | Min seconds between automatic pre-write APFS snapshots. 0 snapshots before every write; negative disables auto-snapshot. |
denyNetwork | boolean | true | Deny classified network operations. |
denySystem | boolean | true | Deny process/system-management commands. |
denyReadPaths | string[] | credential/keychain paths listed above | Absolute or ~-prefixed paths the agent may not read. Empty list disables the restriction. |
extraAllowTools | string[] | [] | Tool names that bypass classification and are always allowed. |
extraDenyTools | string[] | [] | Tool names that are always denied. |
verbose | boolean | true | Log every gate decision to the host console. |
requireTaskSnapshot | boolean | true | System-prompt guidance requires a checkpoint before multi-step tasks. |
failClosed | boolean | true | Block writes when no rollback net exists (git baseline uncreatable and Time Machine unhealthy). |
failClosedBlockReads | boolean | false | Also block reads when the backstop is unhealthy. Left false so the agent can diagnose. |
turnReports | boolean | true | Write the per-turn Markdown report + acceptance check. |
blockingBackupBeforeWrite | boolean | false | Run a blocking full TM backup before each write (slow, SD-card-heavy) instead of an instant local snapshot. |
requireGitBaseline | boolean | true | Require a committed local-git baseline (auto-created) for file writes. |
autoApprove | boolean | true | Answer DSH approval requests allowed-once for calls already passed by the prepended gate. Set false to let approval asks reach the user / fail closed. |
Example — your profile's cordis.patch.yml (the shipped bundle itself inserts a bare row; this is how a user configures it):
- insert:
- id: tm-guard
name: dsh-tm-guard
config:
protectedPaths:
- '/Users/you/projects'
denyReadPaths:
- '~/.ssh'
- '~/.aws'
- '~/Library/Keychains'
snapshotCooldownSeconds: 30
denyNetwork: true
denySystem: true
failClosed: true
requireGitBaseline: true
turnReports: true