JimChen-g/dsh-action-outbox ↗★ 2

dsh-action-outbox

为工具副作用提供持久化批量审核与提交安全控制。 适合需审批高风险工具调用的用户;需配置包含与强制规则。

包名
dsh-action-outbox
兼容性
待验证
Harness 依赖范围
>=0.1.0-rc.6 <0.2.0
版本
0.3.0
许可证
MIT
最近更新
2026年8月18日

同名包的其他仓库

安装

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:JimChen-g/dsh-action-outbox

Configuration

- id: action-outbox
  name: dsh-action-outbox
  config:
    include: ['github_*', 'slack_*', 'deploy_*']
    exclude: ['github_get_*', 'github_list_*']
    enforce: ['github_create_*', 'github_update_*', 'slack_send', 'deploy_*']
    requireApproval: true
    rejectDuplicateActions: true
    persistPending: true
    stateFile: ''
    maxPendingMs: 1800000
    maxActions: 20
    maxArgumentBytes: 65536
    resultPreviewChars: 2000
    approvalPreviewChars: 4000
  • include: wildcard patterns for tools that may be staged.
  • exclude: wildcard exceptions to both staging and enforcement.
  • enforce: wildcard patterns that reject direct calls and require the outbox route. Empty by default for compatibility.
  • requireApproval: ask once for the exact reviewed digest/nonce. Without an approval service, commit fails closed.
  • rejectDuplicateActions: reject repeated target-name/argument pairs. Replacement is checked too.
  • persistPending: persist bounded drafts and recovery receipts. Enabled by default.
  • stateFile: optional absolute or relative override. Empty uses $DSH_HOME/action-outbox/state.json, or ~/.dsh/action-outbox/state.json when DSH_HOME is unset.
  • maxPendingMs: expire an uncommitted batch after this many milliseconds; 0 disables expiry.
  • maxActions / maxArgumentBytes: bound durable state.
  • resultPreviewChars: bound model-facing result receipts.
  • approvalPreviewChars: compact approval-card limit. If exceeded, commit requires full Inbox acknowledgement. A headless/TUI deployment without the Inbox must raise this limit enough to show the full review or it will correctly fail closed.

* is the only wildcard. Every other regular-expression character is literal.