xyzzing/dsh-captain-guard ↗★ 0
dsh-captain-guard
Runtime-toggleable tool allowlist guard for the DSH Captain agent 适合需要限制或审计Captain Agent可用工具以提升安全性的用户。
インストール
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:xyzzing/dsh-captain-guardドキュメント
README 全文を読む ↗Configuration
Mount it in the profile's cordis.patch.yml:
- insert:
- id: captain-guard
name: dsh-captain-guard
config:
enabled: true # default state when no state file exists
captainPreset: captain # the preset ID to match (case-sensitive)
allowlist: # optional override of the built-in list
- graft_map
- graft_skeleton
- graft_ask
- fs_read_range
- agent_teams_create
- agent_teams_add_member
- agent_teams_status
- agent_teams_task_create
- agent_teams_task_list
- agent_teams_task_get
- agent_teams_task_update
- agent_teams_message
| Field | Default | Purpose |
|---|---|---|
enabled | true | Initial state when no runtime state file exists |
captainPreset | "captain" | The agentPreset value to match in the session header |
allowlist | 12 tools | The exact set of tools the Captain may see |