dsh-agent-guard
提供只读状态检查与私有存储写入保护的防护栏插件 适合需要防止数据丢失、审计操作状态并拦截非安全写入的系统防护任务。
安裝
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:a5557/dsh-agent-guard說明文件
閱讀完整 README ↗Usage
As tools (installed)
guard_inspect(scope?, workspace?, maxSessions?, includeHeaders?, redact?)
guard_journal(action?, limit?, snapshot?)
guard_inspect produces the evidence report (read-only, writes nothing anywhere).
guard_journal reports the guard's own state: whether it is enabled, whether the journal is
writable and its hash chain intact, the rollback points, and the most recent protected
operations. action: "trace" shows one operation in detail; the rollback action returns
human rollback instructions — there is no automatic rollback.
Interception (automatic, once installed)
Protected writes are decided at tools/pre-execute, where deny short-circuits before
the tool body runs. That is the difference between blocking and warning after the fact.
Defaults:
- a write to DSH core data while DSH is not known to be stopped → refused (fail-closed: "cannot determine" counts as running);
- a permitted protected write → backup first, then ask; if the backup fails or exceeds the budget (8 MiB per file by default) → refused, never allowed unbacked;
- two consecutive writes on one path whose checksum changed → circuit breaker, handed to a human through the approval channel;
- a generated
.bat/.cmd/.ps1/.shthat references a protected path → flagged asemit-scriptand never silently allowed.
In the UI
The plugin ships a client half, so it has a native seat in the interface:
- a sidebar icon (the
sidebar.panellistseat, currently unoccupied by official plugins) that opens a main panel showing guard status, rollback points, and recent protected operations; - a settings page ("环境护栏") under Settings, showing the same status plus exactly how to disable the guard.
Both views are strictly read-only: no repair, no migration, and no rollback button.
The client half is a hand-written window.__ModuleLoader__.load bundle, so this package needs
no build step and adds no devDependencies. An equivalent same-origin HTTP panel is
also served at /agent-guard as a fallback for hosts without a client bundle path.
The official client bundles are built with tsdown; this package hand-writes the same contract (
React.createElementinstead of JSX), and unit tests execute the bundle in a controlled sandbox, asserting all three seat registrations and the absence of any write path.