Adds dangerous-operation policy checks, output redaction, and a security-review workflow.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:lonelymoon87/dsh-guardian
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
Runtime dangerous-operation policy, canonical output redaction, and security-review workflow for DeepSeek Harness.
The v0.1.3 release is tested with DSH 0.1.0-rc.8 and 0.1.1-rc.1 while retaining the rc.6-compatible peer range. Prebuilt packages are distributed through GitHub Releases. The unscoped npm name is owned by another publisher, so this project is not published there.
MVP
- A
tools/pre-executewaterfall classifies dangerous shell, SQL, and structured file-write arguments asdeny,ask, or unchanged. standard,strict, andpermissiveprofiles provide different approval levels while retaining non-negotiable deny rules.- Custom regular-expression rules add deployment-specific
denyoraskdecisions. - A
tools/post-executewaterfall redacts common credentials from canonical JSON results, failures, rendered text, and block feedback. - Consecutive text blocks are scanned as one stream so splitting a credential across blocks does not bypass redaction.
/security-reviewloads a bundled, read-only security-review skill.
The MVP is not a process sandbox, authorization system, data-loss-prevention service, or substitute for the provider policies mounted below it.
Policy behavior
The built-in rules deny recursive forced deletion of root or home paths, network-response pipes into shells, raw writes to /dev, and writes to /etc. Force pushes, destructive SQL, and other recursive forced deletions ask for approval. Strict mode additionally asks for sudo; permissive mode retains only deny rules.
Guardian always delegates through next(). When another policy listener returns a decision, the most restrictive result wins: deny outranks ask, which outranks allow.
Redaction behavior
Built-in patterns cover AWS access-key IDs, GitHub tokens, sk- API keys, PEM private-key blocks, and common credential assignments. Redaction is applied to the canonical JSON value when one exists, preserving arrays, objects, numbers, booleans, and null values. This prevents Code Mode and downstream renderers from retaining an unredacted value behind safe-looking display text.
Logs contain only the tool name, match count, and redaction labels. The plugin does not append custom session events because the current external plugin API does not expose an ignorable event envelope; emitting a required unknown event would make old sessions unreadable after uninstall.
Permissions and data
- Guardian inspects tool names, arguments, canonical results, and rendered output inside the current DSH process. It can deny a call or request approval but never executes the requested operation itself.
- Redaction replaces matched secret text before downstream model-visible consumers receive the canonical result. Logs retain only the tool name, match count, and non-secret labels.
- The plugin does not read credential stores, make network requests, write workspace files, transmit telemetry, or persist custom session events.
Install
The package supports DSH >=0.1.0-rc.6 <0.2.0 plugin APIs and Node.js ^22.19 || >=24.
dsh plugin --profile web add https://github.com/lonelymoon87/dsh-guardian/releases/download/v0.1.3/dsh-guardian-0.1.3.tgz
The release tarball is prebuilt and needs no build allowance. A pinned source install is also supported:
dsh plugin --profile web add github:lonelymoon87/dsh-guardian#v0.1.3
The source install runs this package's prepare build. pnpm 10 and later reject it until the profile allowlists the exact package key printed by the failed command; apply that instruction and rerun the same dsh plugin add command. Replace web with headless to install into the one-shot agent profile.
To upgrade, rerun dsh plugin add with the newer release URL. To uninstall:
dsh plugin --profile web remove dsh-guardian
Configuration
- id: guardian
name: dsh-guardian
config:
profile: standard
rules:
- name: production-host
pattern: production\\.internal
action: ask
reason: production target requires review
redaction:
enabled: true
patterns:
- label: internal-token
pattern: INT_[A-Z0-9]{12}
Regular-expression flags may contain only i, m, s, and u. Invalid expressions and labels fail during plugin loading.
Verification
The tests cover positive and negative cases for every built-in rule, structured paths, profile behavior, downstream policy composition, nested canonical values, custom credentials, block feedback, split text blocks, disabled redaction, command dispatch, and invalid configuration.
- The v0.1.3 tarball installs directly from its HTTPS release URL into clean DSH 0.1.0-rc.8 and 0.1.1-rc.1 profiles.
- The packed bundle and pinned GitHub source install both appear in
dsh --dump-config. - CI covers Node 22.19 and Node 24; a compatibility matrix repeats the real install against DSH 0.1.0-rc.8 plus the
latestandnextnpm tags. - Bugs and compatibility reports are tracked in GitHub Issues.
License
Links
More in this category
toby-bridges/api-relay-audit★ 860
Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.
SeaOf0/dsh-redteam-model★ 638
Authorized-security DSH collection: nine work modes (redteam coordinator, pentest, code audit, binary analysis, attack-defense, AV evasion, incident response, cloud security, CTF solving) and fifteen runtime plugins, managed from a settings page with one-click deploy, install, update and uninstall.
howmp/dsh-pentest★ 558
Authorized pentest mode for DeepSeek Harness — exploration chain, assets and findings with a Web view.
PerryLink/dsh-auto-review★ 206
Second-model auto-review on the approval answerer chain: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default.
NanmiCoder/dsh-auto-mode★ 163
Adds an Auto permission preset between Workspace Write and Full access: routine work stays in the official workspace-write sandbox while the current session model reviews escalation and destructive calls, granting one exact wider access once, asking when the intent is ambiguous, and denying critical paths.
PerryLink/dsh-permission-rules★ 114
Claude Code-style declarative permission rules: ordered allow/deny/ask YAML rules matching tool names, arguments, workspace paths, and agent identity on the tools/pre-execute waterfall, with full session-log audit, dry-run mode, and hot reload.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.