julescules/dsh-windows-workspace-guard ↗★ 0
dsh-windows-workspace-guard
适用于 DeepSeek Harness 的 Windows 工作区、不可变路径、Git 风险、审批和审计防护插件。
AI 分析
核心用于 Windows 环境下 DSH 的安全防护。通过拦截和审查 pwsh 命令,保护工作区、限制敏感路径修改并拦截高危 Git 操作。适合对自动化执行安全性要求高的 Windows 用户。
安装
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:julescules/dsh-windows-workspace-guard说明文档
阅读完整 README ↗dsh-windows-workspace-guard
中文 | English
[!IMPORTANT] Unofficial community plugin. Independently developed and maintained; not reviewed or endorsed by DeepSeek.
Safety policy for DeepSeek Harness on Windows. It checks model-issued pwsh calls before execution and protects workspaces, original files, and Git history.
What it does
- keeps destructive PowerShell targets inside trusted workspace roots;
- makes
original/, signing files, or any configured path immutable; - reviews risky Git commands such as
reset --hard,clean -fdx, and force push; - supports
block, one-timeask, and audit-onlyreportmodes; - writes optional append-only JSONL audit records with redacted previews and command hashes;
- permanently blocks disk operations, broad roots, encoded execution,
System.IObypasses, and protected paths.
Install
dsh plugin --profile web add github:julescules/dsh-windows-workspace-guard#v0.2.0
dsh --profile web --dump-config
Restart DSH after installation.
Recommended config
- id: windows-workspace-guard
name: dsh-windows-workspace-guard
config:
mode: ask
workspaceRoots:
- 'D:\projects\current-project'
protectedPaths:
- 'D:\projects\current-project\original'
guardGit: true
auditPath: 'D:\projects\current-project\operation_logs\dsh-guard.audit.jsonl'
| Result | block | ask | report |
|---|---|---|---|
| Safe | allow | allow | allow |
| Needs review | deny | ask once | allow + audit |
| Hard block | deny | deny | deny |
Hard blocks cannot be bypassed by allowExact or report mode.
Check without running
The plugin registers windows_workspace_guard_check. The agent can inspect a command and receive stable PASS, REVIEW, or FAIL JSON without executing it.
Verified
- 20/20 unit and adversarial tests pass;
- official
dsh.bundle.patchpackage shape; - official
tools/pre-executeallow/deny/ask contract; - package contains no install-time build step;
- UTF-8 append-only audit with common secret redaction.
npm run check
npm pack --dry-run
Limits
- Static inspection is not a complete PowerShell parser or OS sandbox.
- Only the DSH tool named
pwshis intercepted. - Junction/symlink targets are not resolved against the live filesystem.
- DeepSeek Harness is in developer preview; pin a reviewed release or commit.