Rules, commands & skills manager for dsh: /rules slash command, settings panel with visual rule editing (add/edit/disable/delete, free-zone support), user-defined custom commands with {input} arguments, skill management, and automatic backup & one-click restore of AGENTS.md.
Install
# from npm (prebuilt)
dsh plugin --profile web add dsh-rules-manager
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:jilian-dsh/dsh-rules-manager#path:/dsh-rules-manager
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
A DeepSeek Harness (DSH) plugin for managing your user-global rules and commands: the
/rulesslash command plus a settings panel "规则、命令与技能" with visual rule editing, a slash-command list, user-defined custom commands, skill management, and backup restore.⚡ Rules live in
$DSH_HOME/AGENTS.md; every change takes effect immediately (DSH hot-reloads the file) and is automatically backed up before each write — you can restore to any backup snapshot at any time.
Features
| Capability | Where | Notes |
|---|---|---|
| List / view / add / edit / delete / disable / restore rules | /rules command or Settings → 规则、命令与技能 |
Rules are the user-global instructions (AGENTS.md), grouped by section, full-text visual editing |
| Command list | Settings → 规则、命令与技能 → 命令 | Read-only list of all available slash commands (name/description/usage) |
| Custom commands | Settings → 规则、命令与技能 → 自定义命令 | Define your own shortcuts: type /name in the chat box to send a preset prompt to the AI; supports arguments (see below); disable/enable supported; long presets are collapsed by default — click "详情" to expand |
| Skill management | Settings → 规则、命令与技能 → 技能 | View installed skills (name/description/full text), disable (moved out of the skills dir, content preserved), enable (moved back), delete (moved to ~/.dsh/.backups/trash-<timestamp>/, recoverable); disable/delete fully takes effect after restarting DSH |
| Backup & restore | Settings → 规则、命令与技能 → 备份与恢复 | Browse all auto backups (time / rule count / size), restore to any snapshot with one click |
Examples
/rules list all rules
/rules show 2 show full text of rule 2
/rules add 我的规则|这是正文 add a rule (| separates title and body)
/rules edit 2 新正文 edit rule 2's body
/rules delete 3 delete rule 3 (numbers are never reused)
/rules health rule health check: counts, sections, free zone, missing level, empty/long body, duplicate titles
Custom commands: define hello = "Please greet me warmly" in the panel, then type /hello in the chat box.
⚖️ Execution levels (must-read for new users)
Every rule title ends with an execution level, e.g. ### [规则 9] PS 编码与命令执行(执行等级:A+D). It decides how strictly the rule is machine-enforced:
| Level | Meaning | Machine behavior |
|---|---|---|
| A | Hard block | Rule-violating tool calls are directly denied (the model cannot bypass) |
| B | Audit & correct | Violating text is logged + a correction reminder is injected |
| C | Sequence check | Judged by event order; violations are denied (e.g. authorize before acting) |
| D | Self-certify | Requires a self-certification statement, no hard block |
| M | Meta | Rules about the rules themselves |
- Levels can combine (e.g.
A+D= hard block + self-certify). - When adding a rule without a level in the title,
(执行等级:D)is appended automatically with a hint — level D is only a self-certify reminder and never hard-blocks. For a hard block, write(执行等级:A)in the title (combinable). - The rule engine (dsh-rule-engine) only hard-blocks tool calls for rules whose level contains A/C/M; B/D levels get text auditing and self-certify hints.
Custom commands with arguments
Anything typed after the command name is treated as an argument and merged into the preset prompt before delivery. Three rules:
- The preset contains
{input}→ the argument replaces every{input}occurrence (usable multiple times); running it without an argument shows a usage hint instead of sending a truncated prompt; - No
{input}and an argument is given → the argument is appended to the preset (newline-separated); - No
{input}and no argument → only the preset is sent (identical to previous behavior; existing commands are unaffected).
Preset: Please summarize in one sentence: {input}
Type: /summarize this week's progress
Sent: Please summarize in one sentence: this week's progress
Preset: Please generate a weekly report
Type: /weekly-report monthly revenue 50k
Sent: Please generate a weekly report
monthly revenue 50k ← argument appended
Preset: Please greet me warmly
Type: /hello ← no argument
Sent: Please greet me warmly
🕊️ Free Zone
AGENTS.md supports a free zone: the section framed by the <!-- free-zone:start --> / <!-- free-zone:end --> comment markers. The model can read it and it still works as instructions, but the rule engine (dsh-rule-engine) does not parse or enforce it (no hard block, no auditing, not in /guard rules) — ideal for soft constraints, third-party codes of conduct (e.g. a legal work code), etc.
- Entries inside use
### [规则 F<n>](F = Free prefix, e.g.F1,F2); using the main numbering### [规则 N]inside the zone is forbidden; - Management: free-zone entries appear under a separate "自由区域" group in
/rules listand the settings panel — editable / disableable / deletable like normal rules; - Adding normal rules:
/rules addalways inserts beforefree-zone:start, so new rules never fall into the free zone; - Adding free-zone rules: must be written manually between the
free-zone:start/endmarkers using the### [规则 F2]format; - Promotion: rename the F number to a main number and move it out of the zone — the rule engine takes over enforcement automatically;
- Command support:
/rules show F1,/rules edit F1 新正文,/rules delete F1(letter indices supported since 1.4.3).
📝 Adding a free-zone rule (3 steps)
/rules add cannot place a rule into the free zone (by design — it prevents normal rules from landing in an area the engine does not enforce). Do this instead:
If dsh-rule-engine is installed: first type
/guard unlockin the chat box (AGENTS.md is write-protected; unlock allows edits for 10 minutes by default; only the user holds the key);Open
$DSH_HOME/AGENTS.mdwith a text editor (typicallyD:\\example\\workspace\.dsh\AGENTS.md), scroll to the end, find the<!-- free-zone:start -->and<!-- free-zone:end -->markers, and paste between them in this format (numbering continues from F2; F1 is already taken by the example; never reuse an existing number):### [规则 F2] Your code-of-conduct title Your content here (multiple lines are fine).Save the file — takes effect immediately, no restart needed. You can also ask your AI assistant to write it for you (run
/guard unlockfirst).
Note: do not write outside the free-zone markers — the rule engine would parse it as a normal rule (without an execution level it will not hard-block, but it will appear in
/guard rules).
Safety
- Auto backup: before every AGENTS.md write, a full copy is saved to
$DSH_HOME/.backups/AGENTS.md-<timestamp>.bak(last 5 kept; timestamps include milliseconds so rapid consecutive writes never overwrite each other); - One-click restore (double safety): restoring a backup first backs up the current AGENTS.md automatically — you can always revert again, data is never lost;
- No renumbering: deleting a rule keeps the remaining numbers stable;
- Name-conflict guard: custom commands colliding with system commands (e.g.
/rules,/compact) are rejected; - Name rules: lowercase letters, digits, hyphen, underscore only (
/^[a-z][a-z0-9_-]*$/); - Argument merging:
{input}placeholders in the preset are replaced by the typed argument (multiple allowed); without{input}, the argument is appended (newline-separated); a command with{input}run without an argument shows a usage hint (no truncated prompt is sent), while a command without{input}run without an argument sends only the preset (backward compatible).
Install
Option 1: npm (recommended — dependencies resolved automatically)
Both packages are published on npm as dsh-rules-manager and dsh-rules-manager-client:
# Run inside your plugin directory (e.g. $DSH_HOME/profiles/web)
npm install dsh-rules-manager dsh-rules-manager-client
Then wire them in cordis.patch.yml (step 2 below; reference the npm package names) and restart DSH.
DSH dependencies (@deepseek-ai/*) resolve automatically via peerDependencies.
Option 2: copy from source
Both packages must be installed:
Copy
dsh-rules-manager/into$DSH_HOME/profiles/web/, anddsh-rules-manager-client/into$DSH_HOME/profiles/node_modules/;Wire them in
$DSH_HOME/profiles/web/cordis.patch.yml:- insert: - id: rules-manager name: './rules-manager/index.js' - id: rules-manager-service name: './rules-manager/service.js' - id: rules-manager-client name: 'dsh-rules-manager-client'Restart DSH. The settings panel shows "规则、命令与技能"; the
/rulescommand works in the chat box.
The client package must live under
profiles/node_modules/(DSH discovers client plugins by npm package name). Host dependencies resolve through the junction forest inprofiles/node_modules.
Architecture
dsh-rules-manager/ host plugin (pure Node, no build)
├── index.js /rules slash command
├── service.js Remote service (TypertRemoteService) backing the settings panel
├── rules-core.js shared core: AGENTS.md parse / backup / CRUD
dsh-rules-manager-client/ client plugin (browser bundle)
├── index.js host-side placeholder entry
└── client.js settings panel (hand-written __ModuleLoader__ bundle)
- Host home resolution uses
resolveDshHome()from@deepseek-ai/dsh-home-paths; - client→host RPC uses Typert Remote:
ctx.remote.$mount({package, descriptors})+ctx.get("remote.rulesManager"); - Custom commands deliver the preset prompt via
invocation.agent.followup(message)(the official inbox channel).
Development
node test-service.js # 101 assertions: Remote markers + rule CRUD + user commands (with args) + backup restore (isolated)
node test-local.js # 33 assertions: /rules command end-to-end (including health check, isolated)
Both tests use a temporary DSH_HOME + AGENTS.md copy; they never touch your real files.
Fixed source
- 1.6.0 (current) is pinned to main commit
1a8ff53(git checkout 1a8ff53reproduces the source shipped as npmdsh-rules-manager@1.6.0and GitHub Release v1.6.0). - 1.5.4 is pinned to main commit
ee1f7669176744b71b2e3faeeb572e54cc6a5523(full 40-char;git checkout ee1f766reproduces the source shipped as npmdsh-rules-manager@1.5.4and GitHub Release v1.5.4).
License
MIT. Copyright (c) 2026 dsh-rules-manager contributors.
Community plugin, independent of the DeepSeek Harness official repository. Discover via the dsh-plugin topic.
Links
More in this category
yjh051108/dsh-routing-suite★ 6993
One repository, three parts: a runtime injector for DSH plugin packages (inject, hot-reload, unload, promote a dev staging tool to the front, route self-heal, plus a settings-page plugin manager that lists, unloads and drags folders in to internalize), a task-aware reasoning-mode router agent preset (router-standard / router-spec / router-react), and a graded two-level task protocol whose six tools (commit_star, lock_stage, revise_do, edit_plan, mark_task, redteam_verdict) pin task state to disk. The injector implementation ships in-tree, so the install carries its own behaviour rather than a dependency list.
strukto-ai/mirage#dsh★ 3672
Swaps the filesystem and bash providers for a mirage virtual workspace: file tools and shell commands run over mounted resources (RAM, S3, Redis, Slack, Gmail, Notion, Postgres) instead of the host disk, with per-mount read/write/exec modes, per-command sandbox routing (monty, pyodide, quickjs in process; docker, e2b, daytona remote), and installed CLIs (git, gh, slack, linear, ntn, gws, or one you register) as head words in the virtual terminal.
hust-open-atom-club/oh-dsh★ 326
Community distribution: TUI, desktop, and Web UI as one bundle with layered installation.
weijiafu14/pi2dsh★ 210
Pi Host ABI compatibility engine: after one install, unmodified Pi extensions from npm mount as native DSH plugins with `dsh plugin add <pi-package>`. Verified end to end on stock DSH with pi-mcp-adapter (full MCP manager: OAuth, resources, prompts, MCP Apps, elicitation, sampling), @tintinweb/pi-subagents, pi-code, pi-hermes-memory and pi-background-tasks; `pi2dsh inspect` reports a package's compatibility before installing.
lire1131/dsh-undo-savepoint★ 169
Undo/redo & rollback system for DSH: every config change is auto-snapshotted; undo/redo/restore to any version from the WebUI or the offline CLI/GUI tools (works even when DSH fails to boot).
Fishquito7/dsh-skill-mcp-panel★ 166
Manages DSH skills and MCP servers from the web settings: skill cards with hot enable/disable, workspace scopes, groups, batch migration and drag-and-drop import, plus stdio/HTTP MCP CRUD with connection tests, secret redaction and the unified dsh-panel CLI.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.