a5557/dsh-agent-guard ↗★ 0

dsh-agent-guard

提供只读状态检查与私有存储写入保护的防护栏插件 适合需要防止数据丢失、审计操作状态并拦截非安全写入的系统防护任务。

套件
dsh-agent-guard
相容性
待驗證
版本
0.1.0
授權
MIT
最近更新
2026年10月3日

安裝

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:a5557/dsh-agent-guard

Usage

As tools (installed)

guard_inspect(scope?, workspace?, maxSessions?, includeHeaders?, redact?)
guard_journal(action?, limit?, snapshot?)

guard_inspect produces the evidence report (read-only, writes nothing anywhere). guard_journal reports the guard's own state: whether it is enabled, whether the journal is writable and its hash chain intact, the rollback points, and the most recent protected operations. action: "trace" shows one operation in detail; the rollback action returns human rollback instructions — there is no automatic rollback.

Interception (automatic, once installed)

Protected writes are decided at tools/pre-execute, where deny short-circuits before the tool body runs. That is the difference between blocking and warning after the fact. Defaults:

  • a write to DSH core data while DSH is not known to be stopped → refused (fail-closed: "cannot determine" counts as running);
  • a permitted protected write → backup first, then ask; if the backup fails or exceeds the budget (8 MiB per file by default) → refused, never allowed unbacked;
  • two consecutive writes on one path whose checksum changed → circuit breaker, handed to a human through the approval channel;
  • a generated .bat/.cmd/.ps1/.sh that references a protected path → flagged as emit-script and never silently allowed.

In the UI

The plugin ships a client half, so it has a native seat in the interface:

  • a sidebar icon (the sidebar.panellist seat, currently unoccupied by official plugins) that opens a main panel showing guard status, rollback points, and recent protected operations;
  • a settings page ("环境护栏") under Settings, showing the same status plus exactly how to disable the guard.

Both views are strictly read-only: no repair, no migration, and no rollback button. The client half is a hand-written window.__ModuleLoader__.load bundle, so this package needs no build step and adds no devDependencies. An equivalent same-origin HTTP panel is also served at /agent-guard as a fallback for hosts without a client bundle path.

The official client bundles are built with tsdown; this package hand-writes the same contract (React.createElement instead of JSX), and unit tests execute the bundle in a controlled sandbox, asserting all three seat registrations and the absence of any write path.