DeepSeek Harness Plugin

sjh9714/dsh-movein#plugin

Stars ★ 14 Downloads (30d) 466 Category Security & Permissions Added 2026-08-15 npm dsh-movein-permissions

Fine grained per tool permission rules for DSH at the tools/pre-execute gate, deny and ask lists in Claude Code rule syntax (`Bash(rm -rf:*), Read(_secrets_), mcp__server__tool`), works standalone without migrating.

Install

# from npm (prebuilt)

dsh plugin --profile web add dsh-movein-permissions

# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)

dsh plugin --profile web add github:sjh9714/dsh-movein#path:/plugin

Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).

README

Fine grained, per tool permission rules for DeepSeek Harness (DSH).

DSH ships three coarse permission presets (read-only, workspace-write, danger-full-access) and its README names the missing piece itself, there is no per tool allowlist. This plugin adds one at the tools/pre-execute gate, using Claude Code's battle tested rule syntax. You do not need to be migrating from Claude Code to use it.

为 DSH 补上按工具粒度的权限规则。DSH 自带的三档权限预设没有细粒度控制,这个插件在 tools/pre-execute 强制执行 deny/ask 规则,规则语法与 Claude Code 相同。不迁移也能单独用。

Install

dsh plugin --profile web add dsh-movein-permissions

Then add a row to ~/.dsh/cordis.patch.yml (or your profile's patch):

- insert:
    - id: cc-permissions
      name: 'dsh-movein-permissions'
      config:
        deny:
          - 'Bash(rm -rf:*)'
          - 'Read(*secrets*)'
          - 'mcp__github__delete_repo'
        ask:
          - 'Write'
          - 'Bash(git push:*)'

Restart dsh web. Denied calls return a typed refusal to the model, ask rules force a confirmation.

Compatibility

The plugin requires Node.js 22.13 or newer and supports DSH >=0.1.0-rc.8 <0.2.0 on the Web profile.

DSH release Disposable-profile install Web start Uninstall
0.1.0-rc.8 tested tested tested
0.1.1-rc.1 tested tested tested
0.1.1-rc.2 tested tested tested
0.1.2-alpha.3 tested tested tested
0.1.2-alpha.4 tested tested tested
0.1.2-alpha.5 tested tested tested

CI packs this plugin, installs it into a fresh temporary DSH_HOME, confirms the composed profile contains the plugin-owned entry, starts the Web UI on loopback and receives an HTTP response, removes the package, and confirms the entry is gone. It never touches a user profile or sends a model request. The unit suite separately verifies the permission gate itself on Windows, macOS, and Linux.

Rule syntax

Claude Code permission rule shape, Tool or Tool(specifier).

Rule Meaning
Bash(npm run test:*) any shell command starting with npm run test (matched on terminal_* tools)
Read(*secrets*) any read whose path contains secrets
Write every write
mcp__server__tool one exact MCP tool, names are identical in DSH and Claude Code

Mapped tools. Bash (terminal_open/terminal_send and friends), Read, Write, Edit, and every mcp__* tool. * patterns match as a superset, over-denying is the safe direction for a gate.

Deny wins over ask. Rules that reference tools with no DSH equivalent never match anything, harmless but pointless, the dsh-movein migration report lists them for you.

Coming from Claude Code?

npx dsh-movein --apply generates this row from your existing settings.json automatically, along with the rest of your setup.

License

MIT

Content from the project README on GitHub ↗

Links

More in this category

View the whole category →

Community comments

Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.