Fine grained per tool permission rules for DSH at the tools/pre-execute gate, deny and ask lists in Claude Code rule syntax (`Bash(rm -rf:*), Read(_secrets_), mcp__server__tool`), works standalone without migrating.
Install
# from npm (prebuilt)
dsh plugin --profile web add dsh-movein-permissions
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:sjh9714/dsh-movein#path:/plugin
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
Fine grained, per tool permission rules for DeepSeek Harness (DSH).
DSH ships three coarse permission presets (read-only, workspace-write, danger-full-access) and its README names the missing piece itself, there is no per tool allowlist. This plugin adds one at the tools/pre-execute gate, using Claude Code's battle tested rule syntax. You do not need to be migrating from Claude Code to use it.
为 DSH 补上按工具粒度的权限规则。DSH 自带的三档权限预设没有细粒度控制,这个插件在 tools/pre-execute 强制执行 deny/ask 规则,规则语法与 Claude Code 相同。不迁移也能单独用。
Install
dsh plugin --profile web add dsh-movein-permissions
Then add a row to ~/.dsh/cordis.patch.yml (or your profile's patch):
- insert:
- id: cc-permissions
name: 'dsh-movein-permissions'
config:
deny:
- 'Bash(rm -rf:*)'
- 'Read(*secrets*)'
- 'mcp__github__delete_repo'
ask:
- 'Write'
- 'Bash(git push:*)'
Restart dsh web. Denied calls return a typed refusal to the model, ask rules force a confirmation.
Compatibility
The plugin requires Node.js 22.13 or newer and supports DSH >=0.1.0-rc.8 <0.2.0 on the Web profile.
| DSH release | Disposable-profile install | Web start | Uninstall |
|---|---|---|---|
0.1.0-rc.8 |
tested | tested | tested |
0.1.1-rc.1 |
tested | tested | tested |
0.1.1-rc.2 |
tested | tested | tested |
0.1.2-alpha.3 |
tested | tested | tested |
0.1.2-alpha.4 |
tested | tested | tested |
0.1.2-alpha.5 |
tested | tested | tested |
CI packs this plugin, installs it into a fresh temporary DSH_HOME, confirms the composed profile contains the plugin-owned entry, starts the Web UI on loopback and receives an HTTP response, removes the package, and confirms the entry is gone. It never touches a user profile or sends a model request. The unit suite separately verifies the permission gate itself on Windows, macOS, and Linux.
Rule syntax
Claude Code permission rule shape, Tool or Tool(specifier).
| Rule | Meaning |
|---|---|
Bash(npm run test:*) |
any shell command starting with npm run test (matched on terminal_* tools) |
Read(*secrets*) |
any read whose path contains secrets |
Write |
every write |
mcp__server__tool |
one exact MCP tool, names are identical in DSH and Claude Code |
Mapped tools. Bash (terminal_open/terminal_send and friends), Read, Write, Edit, and every mcp__* tool. * patterns match as a superset, over-denying is the safe direction for a gate.
Deny wins over ask. Rules that reference tools with no DSH equivalent never match anything, harmless but pointless, the dsh-movein migration report lists them for you.
Coming from Claude Code?
npx dsh-movein --apply generates this row from your existing settings.json automatically, along with the rest of your setup.
License
MIT
Links
More in this category
toby-bridges/api-relay-audit★ 861
Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.
SeaOf0/dsh-redteam-model★ 646
Authorized-security DSH collection: nine work modes (redteam coordinator, pentest, code audit, binary analysis, attack-defense, AV evasion, incident response, cloud security, CTF solving) and fifteen runtime plugins, managed from a settings page with one-click deploy, install, update and uninstall.
howmp/dsh-pentest★ 559
Authorized pentest mode for DeepSeek Harness — exploration chain, assets and findings with a Web view.
PerryLink/dsh-auto-review★ 212
Second-model auto-review on the approval answerer chain: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default.
NanmiCoder/dsh-auto-mode★ 164
Adds an Auto permission preset between Workspace Write and Full access: routine work stays in the official workspace-write sandbox while the current session model reviews escalation and destructive calls, granting one exact wider access once, asking when the intent is ambiguous, and denying critical paths.
PerryLink/dsh-permission-rules★ 115
Claude Code-style declarative permission rules: ordered allow/deny/ask YAML rules matching tool names, arguments, workspace paths, and agent identity on the tools/pre-execute waterfall, with full session-log audit, dry-run mode, and hot reload.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.