dsh-file-shield
DeepSeek Harness 插件:在 Web GUI 里点选文件或目录,屏蔽 agent 对它们的读取、搜索、写入与编辑,使机密内容与敏感词不进入对话(含敏感词导致请求 400 的场景)。Blocks an agent from reading, searching, writing, or editing chosen files and directories, keeping their contents out of the conversation. 适合需要保护本地机密内容、防止敏感词进入模型对话的安全任务。
설치
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:Yazzyk/dsh-file-shield怎么配置
从插件页面(日常用法)
侧边栏 Plugins → Installed → dsh-file-shield:
- 选择文件… 打开插件自带的浏览器,逐层进入目录并点选文件;
- 系统目录选择器… 调用 dsh 自己的目录选择器(需要装载 workspace UI);
- 也可以直接输入路径或 glob;
- 保存 把规则写进
file-shield设置命名空间(用户层),恢复部署默认 清掉用户层。
写进设置层的规则立即对下一次工具调用生效,不需要重启。因为宿主没有暴露列文件的接口(目录选择器只列目录、workspaceFiles.list 限于会话工作区),选文件用的是一条插件自己的只读路由 GET /file-shield/browse?path=:只接受 GET、只列目录内容、Cache-Control: no-store,并且每个请求都先过 ctx.connection.requestRejection()——Host/Origin 围栏挡 DNS rebinding 与跨站请求,浏览器会话 Cookie 挡未认证调用。该路由只在同时装配了 webServer 与 connection 的组合里挂载;缺其中任一时文件浏览器不可用,而不是以无认证方式开放目录列举。
从 cordis.patch.yml(部署默认)
profile 的 patch 层可以整段替换该行的 config:
- insert:
- id: file-shield
name: dsh-file-shield
config:
deny:
- '**/.env'
- '**/.env.*'
- '**/*.pem'
- '~/.dsh/.credentials.yaml'
matchCase: false
guidance: true
extraPathArgs:
some_reader_tool:
- target
extraCommandArgs:
some_shell_tool: script
| 字段 | 默认 | 含义 |
|---|---|---|
deny | [] | 规则列表。空列表是合法状态:新装插件不自己发明规则 |
matchCase | false | 是否区分大小写 |
guidance | true | 是否注入一条系统提示,说明被拒绝是策略而不是故障 |
extraPathArgs | {} | 其它插件的读文件工具:工具名 → 路径参数名数组 |
extraCommandArgs | {} | 其它插件的 shell 工具:工具名 → 命令参数名 |
设置层的用户规则会覆盖(而不是叠加)这一层的 deny;matchCase、guidance、extraPathArgs、extraCommandArgs 只在这一层。