为 DSH 补上按工具粒度的权限规则:在 tools/pre-execute 强制执行 deny/ask 清单,规则语法与 Claude Code 相同,不迁移也能单独用。
安装
# npm 包(预构建)
dsh plugin --profile web add dsh-movein-permissions
# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)
dsh plugin --profile web add github:sjh9714/dsh-movein#path:/plugin
装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本——pnpm 默认拦截,所以安装可能停在 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED 或 ERR_PNPM_IGNORED_BUILDS;dsh 会打印出需要添加的确切键名,把它加进该 profile 的 pnpm-workspace.yaml 的 allowBuilds 下,重跑一次即可装上。放行构建本身就是一次信任判断:请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。
README
该插件的 README 只有英文版本。
Fine grained, per tool permission rules for DeepSeek Harness (DSH).
DSH ships three coarse permission presets (read-only, workspace-write, danger-full-access) and its README names the missing piece itself, there is no per tool allowlist. This plugin adds one at the tools/pre-execute gate, using Claude Code's battle tested rule syntax. You do not need to be migrating from Claude Code to use it.
为 DSH 补上按工具粒度的权限规则。DSH 自带的三档权限预设没有细粒度控制,这个插件在 tools/pre-execute 强制执行 deny/ask 规则,规则语法与 Claude Code 相同。不迁移也能单独用。
Install
dsh plugin --profile web add dsh-movein-permissions
Then add a row to ~/.dsh/cordis.patch.yml (or your profile's patch):
- insert:
- id: cc-permissions
name: 'dsh-movein-permissions'
config:
deny:
- 'Bash(rm -rf:*)'
- 'Read(*secrets*)'
- 'mcp__github__delete_repo'
ask:
- 'Write'
- 'Bash(git push:*)'
Restart dsh web. Denied calls return a typed refusal to the model, ask rules force a confirmation.
Compatibility
The plugin requires Node.js 22.13 or newer and supports DSH >=0.1.0-rc.8 <0.2.0 on the Web profile.
| DSH release | Disposable-profile install | Web start | Uninstall |
|---|---|---|---|
0.1.0-rc.8 |
tested | tested | tested |
0.1.1-rc.1 |
tested | tested | tested |
0.1.1-rc.2 |
tested | tested | tested |
0.1.2-alpha.3 |
tested | tested | tested |
0.1.2-alpha.4 |
tested | tested | tested |
0.1.2-alpha.5 |
tested | tested | tested |
CI packs this plugin, installs it into a fresh temporary DSH_HOME, confirms the composed profile contains the plugin-owned entry, starts the Web UI on loopback and receives an HTTP response, removes the package, and confirms the entry is gone. It never touches a user profile or sends a model request. The unit suite separately verifies the permission gate itself on Windows, macOS, and Linux.
Rule syntax
Claude Code permission rule shape, Tool or Tool(specifier).
| Rule | Meaning |
|---|---|
Bash(npm run test:*) |
any shell command starting with npm run test (matched on terminal_* tools) |
Read(*secrets*) |
any read whose path contains secrets |
Write |
every write |
mcp__server__tool |
one exact MCP tool, names are identical in DSH and Claude Code |
Mapped tools. Bash (terminal_open/terminal_send and friends), Read, Write, Edit, and every mcp__* tool. * patterns match as a superset, over-denying is the safe direction for a gate.
Deny wins over ask. Rules that reference tools with no DSH equivalent never match anything, harmless but pointless, the dsh-movein migration report lists them for you.
Coming from Claude Code?
npx dsh-movein --apply generates this row from your existing settings.json automatically, along with the rest of your setup.
License
MIT
链接
同类插件
toby-bridges/api-relay-audit★ 861
从 DeepSeek Harness 对 AI API 中转站和 LLM 代理运行本地安全审计,生成 Markdown 报告,覆盖提示词注入、模型替换信号、工具调用改写、错误泄漏、流完整性和按 profile 启用的 Web3 风险。
SeaOf0/dsh-redteam-model★ 646
面向授权安全研究的 DSH 合集:九个工作模式(redteam 总控、渗透测试、代码审计、二进制分析、攻防评估、免杀对抗、应急溯源、云安全攻防、CTF 解题)与十五个运行时插件,设置页管理台支持一键部署、安装、更新与卸载。
howmp/dsh-pentest★ 559
面向 DeepSeek Harness 的授权渗透模式:以探索链路记录目标、线索、资产与漏洞,并在 Web 中可视化展示。
PerryLink/dsh-auto-review★ 212
审批链上的第二模型自动审查:只读审查子代理返回带理由的 allow/deny 结构化裁决,默认 fail-closed。
NanmiCoder/dsh-auto-mode★ 164
在 Workspace Write 与 Full access 之间增加 Auto 权限档:日常操作留在官方 workspace-write 沙箱内,由当前会话模型复核升权与破坏性调用,精确的越界访问按次放行一次,意图不明时询问,命中关键路径则拒绝。
PerryLink/dsh-permission-rules★ 115
Claude Code 风格的声明式权限规则:按序 allow/deny/ask 的 YAML 规则,在 tools/pre-execute 瀑布上匹配工具名、参数、工作区路径与 agent 身份,带完整会话日志审计、干跑模式与热重载。
社区评论
评论公开保存在 GitHub Discussions。加载评论会连接 GitHub 和 Giscus;发表内容需要 GitHub 账号。