A hands-off safety net: directories the agent deletes go to a trash folder first and symlinks are never followed, with zero approvals.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:x2802490130-prog/dsh-shield
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
This plugin publishes its README in Chinese only.
DSH 脱手模式安全网:删除目录先进回收站、删除链接绝不跟随。零审批、零弹窗,agent 体验不变。
能力
- 目录删除先进回收站:bash 的
rm -r/-rf、cmd 的rmdir/rd/del /s、fs 工具的目录删除,执行前把目标 rename 进回收站(同卷瞬时),命令照常执行 - glob 抢救:
rm -rf dir/*、dir/*.log逐个抢救子项;父目录是链接时顺链接解析,抢救真实目标内容 - 链接绝不跟随:
rm -rf link/自动改写为删链接本身 - 回收站管理:设置页「回收站」分区 —— 查看 / 恢复 / 删除 / 清空;超 14 天或 5GB 自动清理
- 可选系统回收站:配置
trashMode: system走系统回收站(失败自动回落)
配置(profile 补丁层,均可省略)
- id: dsh-shield
config:
trashRoot: D:\\path\\to\\trash # 默认 $DSH_HOME/trash
retentionDays: 14
maxTrashBytes: 5368709120
trashMode: dir # dir | system
安全边界
- 只抢救不拦截:命令仍会执行,agent 无感
- 单目标 + 常见 glob 场景已覆盖;极端 shell 花样以回收站兜底
- 管理 API 仅本机回环可用
测试
node test.mjs # 27 项
License
MIT
Links
More in this category
yjh051108/dsh-routing-suite★ 7003
One repository, three parts: a runtime injector for DSH plugin packages (inject, hot-reload, unload, promote a dev staging tool to the front, route self-heal, plus a settings-page plugin manager that lists, unloads and drags folders in to internalize), a task-aware reasoning-mode router agent preset (router-standard / router-spec / router-react), and a graded two-level task protocol whose six tools (commit_star, lock_stage, revise_do, edit_plan, mark_task, redteam_verdict) pin task state to disk. The injector implementation ships in-tree, so the install carries its own behaviour rather than a dependency list.
strukto-ai/mirage#dsh★ 3666
Swaps the filesystem and bash providers for a mirage virtual workspace: file tools and shell commands run over mounted resources (RAM, S3, Redis, Slack, Gmail, Notion, Postgres) instead of the host disk, with per-mount read/write/exec modes, per-command sandbox routing (monty, pyodide, quickjs in process; docker, e2b, daytona remote), and installed CLIs (git, gh, slack, linear, ntn, gws, or one you register) as head words in the virtual terminal.
hust-open-atom-club/oh-dsh★ 325
Community distribution: TUI, desktop, and Web UI as one bundle with layered installation.
weijiafu14/pi2dsh★ 206
Pi Host ABI compatibility engine: after one install, unmodified Pi extensions from npm mount as native DSH plugins with `dsh plugin add <pi-package>`. Verified end to end on stock DSH with pi-mcp-adapter (full MCP manager: OAuth, resources, prompts, MCP Apps, elicitation, sampling), @tintinweb/pi-subagents, pi-code, pi-hermes-memory and pi-background-tasks; `pi2dsh inspect` reports a package's compatibility before installing.
lire1131/dsh-undo-savepoint★ 166
Undo/redo & rollback system for DSH: every config change is auto-snapshotted; undo/redo/restore to any version from the WebUI or the offline CLI/GUI tools (works even when DSH fails to boot).
Fishquito7/dsh-skill-mcp-panel★ 155
Manages DSH skills and MCP servers from the web settings: skill cards with hot enable/disable, workspace scopes, groups, batch migration and drag-and-drop import, plus stdio/HTTP MCP CRUD with connection tests, secret redaction and the unified dsh-panel CLI.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.