ChaoJie0/dsh-tm-guard ↗★ 0

dsh-tm-guard

Time-Machine-backed autonomous agent permission gate for DeepSeek Harness (dsh). Allows TM-rollback-able operations, blocks everything else. 适合需要限制智能体写操作、网络及系统权限,并支持自动快照回滚的安全任务。

パッケージ
dsh-tm-guard
互換性
未検証
Harness ピア範囲
>=0.1.0-rc.1 <0.1.0 || >=0.1.0-rc.1 <0.2.0-0
Cordis ピア範囲
>=4.0.0
バージョン
0.1.1
ライセンス
MIT
最終更新
2026/09/20

インストール

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:ChaoJie0/dsh-tm-guard

ドキュメント

README 全文を読む ↗

Configuration

The plugin accepts a Partial on its inserted row. Users normally override fields from their own profile's cordis.patch.yml (later patch layers win per row; a patch replaces the whole row config).

FieldTypeDefaultMeaning
protectedPathsstring[][process.cwd()]Absolute path prefixes writable by the agent.
snapshotCooldownSecondsnumber30Min seconds between automatic pre-write APFS snapshots. 0 snapshots before every write; negative disables auto-snapshot.
denyNetworkbooleantrueDeny classified network operations.
denySystembooleantrueDeny process/system-management commands.
denyReadPathsstring[]credential/keychain paths listed aboveAbsolute or ~-prefixed paths the agent may not read. Empty list disables the restriction.
extraAllowToolsstring[][]Tool names that bypass classification and are always allowed.
extraDenyToolsstring[][]Tool names that are always denied.
verbosebooleantrueLog every gate decision to the host console.
requireTaskSnapshotbooleantrueSystem-prompt guidance requires a checkpoint before multi-step tasks.
failClosedbooleantrueBlock writes when no rollback net exists (git baseline uncreatable and Time Machine unhealthy).
failClosedBlockReadsbooleanfalseAlso block reads when the backstop is unhealthy. Left false so the agent can diagnose.
turnReportsbooleantrueWrite the per-turn Markdown report + acceptance check.
blockingBackupBeforeWritebooleanfalseRun a blocking full TM backup before each write (slow, SD-card-heavy) instead of an instant local snapshot.
requireGitBaselinebooleantrueRequire a committed local-git baseline (auto-created) for file writes.
autoApprovebooleantrueAnswer DSH approval requests allowed-once for calls already passed by the prepended gate. Set false to let approval asks reach the user / fail closed.

Example — your profile's cordis.patch.yml (the shipped bundle itself inserts a bare row; this is how a user configures it):

- insert:
    - id: tm-guard
      name: dsh-tm-guard
      config:
        protectedPaths:
          - '/Users/you/projects'
        denyReadPaths:
          - '~/.ssh'
          - '~/.aws'
          - '~/Library/Keychains'
        snapshotCooldownSeconds: 30
        denyNetwork: true
        denySystem: true
        failClosed: true
        requireGitBaseline: true
        turnReports: true