ChaoJie0/dsh-tm-guard ↗★ 0

dsh-tm-guard

基于时间机器备份的智能体权限网关 适合需要限制智能体写操作、网络及系统权限,并支持自动快照回滚的安全任务。

套件
dsh-tm-guard
相容性
待驗證
Harness 依賴範圍
>=0.1.0-rc.1 <0.1.0 || >=0.1.0-rc.1 <0.2.0-0
Cordis 依賴範圍
>=4.0.0
版本
0.1.1
授權
MIT
最近更新
2026年9月20日

安裝

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:ChaoJie0/dsh-tm-guard

Configuration

The plugin accepts a Partial on its inserted row. Users normally override fields from their own profile's cordis.patch.yml (later patch layers win per row; a patch replaces the whole row config).

FieldTypeDefaultMeaning
protectedPathsstring[][process.cwd()]Absolute path prefixes writable by the agent.
snapshotCooldownSecondsnumber30Min seconds between automatic pre-write APFS snapshots. 0 snapshots before every write; negative disables auto-snapshot.
denyNetworkbooleantrueDeny classified network operations.
denySystembooleantrueDeny process/system-management commands.
denyReadPathsstring[]credential/keychain paths listed aboveAbsolute or ~-prefixed paths the agent may not read. Empty list disables the restriction.
extraAllowToolsstring[][]Tool names that bypass classification and are always allowed.
extraDenyToolsstring[][]Tool names that are always denied.
verbosebooleantrueLog every gate decision to the host console.
requireTaskSnapshotbooleantrueSystem-prompt guidance requires a checkpoint before multi-step tasks.
failClosedbooleantrueBlock writes when no rollback net exists (git baseline uncreatable and Time Machine unhealthy).
failClosedBlockReadsbooleanfalseAlso block reads when the backstop is unhealthy. Left false so the agent can diagnose.
turnReportsbooleantrueWrite the per-turn Markdown report + acceptance check.
blockingBackupBeforeWritebooleanfalseRun a blocking full TM backup before each write (slow, SD-card-heavy) instead of an instant local snapshot.
requireGitBaselinebooleantrueRequire a committed local-git baseline (auto-created) for file writes.
autoApprovebooleantrueAnswer DSH approval requests allowed-once for calls already passed by the prepended gate. Set false to let approval asks reach the user / fail closed.

Example — your profile's cordis.patch.yml (the shipped bundle itself inserts a bare row; this is how a user configures it):

- insert:
    - id: tm-guard
      name: dsh-tm-guard
      config:
        protectedPaths:
          - '/Users/you/projects'
        denyReadPaths:
          - '~/.ssh'
          - '~/.aws'
          - '~/Library/Keychains'
        snapshotCooldownSeconds: 30
        denyNetwork: true
        denySystem: true
        failClosed: true
        requireGitBaseline: true
        turnReports: true