Security and governance for dsh: rule-based tool denial, full tool-call audit trail, and governance reports.
Install
# from npm (prebuilt)
dsh plugin --profile web add dsh-plugins-guard
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:kouyichi/dsh-plugins#path:/dsh-guard
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
This plugin publishes its README in Chinese only.
生态空白:整个 security & governance 分类都是 0-3★ 萌芽。本插件把两个头部 agent 的安全模式移植到 dsh:
- Codex「sandbox × approval」 → 声明式拒绝规则层(
tools.guard()官方 seam,单调拒绝、无规则即无操作) - Claude Code PreToolUse hook 审计(security-guidance)→ 全量工具调用审计 + 治理报告
工具
| 工具 | 功能 |
|---|---|
guard_rules |
规则管理:add {tool, pattern, reason} / remove / list / toggle。tool 支持通配(bash*) |
guard_report |
治理报告:工具分布、错误率、被拒统计、危险命令命中 |
guard_status |
插件状态 |
guard_export |
审计导出 markdown |
guard_clear |
清空审计 |
存储:~/.dsh/guard/rules.json + ~/.dsh/guard/audit.jsonl
示例
guard_rules action=add tool=bash pattern="rm -rf /" reason="禁止删除根目录"
guard_rules action=add tool=web_search reason="本项目禁用联网搜索"
guard_report period_days=7
Links
More in this category
Tencent/WeKnora#dsh-weknora★ 21028
Four read-only tools over a WeKnora knowledge base: list knowledge bases, hybrid passage search, reassemble one document's chunks in order, and WeKnora's own cited RAG or ReAct-agent answer with a resumable session id.
superdesigndev/treg★ 709
Tool catalog for agents: search ~2,600 external endpoints (SEO and SERP, backlinks, social, people and company enrichment, ad libraries, scraping) by the task you want done, read each one's parameters and per-call price, then call it with the credential injected server-side. Ships the skill plus an MCP row that stays disabled until TREG_TOKEN is set.
anysearch-team/anysearch-dsh★ 377
AnySearch-powered real-time web and vertical search provider for DeepSeek Harness.
EthanYoQ/Invoice-Downloader#dsh-invoice-downloader★ 285
Local IMAP invoice download, OCR, archive, and Excel reimbursement summaries for DeepSeek Harness.
omdsh-dev/dsh-data-agent★ 183
Let the AI connect to databases and write SQL for you.
zhaoolee/notes#dsh-plugin★ 155
Export DSH conversations as Smartisan Notes-style PNGs, or create and update Markdown notes in a configured account-scoped workspace.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.