DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Cc Safety Net — DeepSeek Harness 插件(DSH Plugin)
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录
← Plugins

cc-safety-net

Cc Safety Net

编码代理 CLI 钩子——阻止破坏性命令和访问机密文件

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add cc-safety-net@2.6.0
README兼容性版本

兼容性与来源证明

Cc Safety Net 以 cc-safety-net 发布,当前版本为 2.6.0。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
any
发布来源
npm
Registry 更新时间
2026/10/7

版本

2.6.0stable
2026/10/5
2.5.2stable
2026/10/3
2.5.1stable
2026/10/2
查看其余 1 个版本收起版本
2.5.0stable
2026/10/1
最新版
2.6.0
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
1.9 MB
文件数
23
Surface
any
许可证
MIT
发布源
npm
GitHub
★ 1.6k
周下载
13,087
安全扫描
✓ v2.6.0 扫描通过
最近提交
2026/10/6
查看源码 ↗项目主页 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题

README

CC Safety Net

English · 简体中文 · 日本語

https://github.com/user-attachments/assets/928dbe97-31e3-41d1-b35a-7941a701b056

CC Safety Net (Coding CLI Safety Net) blocks destructive commands and access to secrets such as SSH keys and .env files before the tool call runs. It parses what the command does. Wrapping the command or reordering flags does not hide it. A broken config file never blocks anything. It is not a sandbox: it does not contain processes, set filesystem permissions, or watch network egress.

[!NOTE] Full documentation → covers installation, configuration, reference material, guides, and the security model. This README is the short version.

How it works

An AI coding agent tries to run a command or open a file. CC Safety Net checks what it would actually do before it runs. Safe calls such as git status run normally; dangerous ones such as git reset --hard never run, and the agent is told why.

Supported coding CLIs

CC Safety Net supports these coding agent CLIs on Windows, macOS, and Linux.

Amp Code
Amp Code
Antigravity CLI
Antigravity CLI
Claude Code
Claude Code
Codex
Codex
Cursor
Cursor
DeepSeek Harness
DeepSeek Harness
Devin CLI
Devin CLI
Factory Droid
Factory Droid
Gemini CLI
Gemini CLI
GitHub Copilot CLI
GitHub Copilot CLI
Grok Build
Grok Build
Hermes Agent
Hermes Agent
Kimi Code
Kimi Code
OpenClaw
OpenClaw
OpenCode
OpenCode
Pi
Pi

Features

  • Blocks destructive commands such as git reset --hard, git push --force, and rm -rf on dangerous targets, even inside bash -c or python -c. See Blocked Commands.
  • Blocks secret access to SSH keys, .env files, ~/.aws, and coding-CLI credentials, from the shell and from the agent's file tools. See Secret Protection.
  • Tunes the policy in a GUI. Run npx cc-safety-net gui to pick the Standard, Strict, or Paranoid preset and turn rules on or off. See Modes.
  • Adds blocks through rulebooks: official packs for Terraform, AWS, gcloud, and Azure, or your own JSON. See Official Rulebooks.
  • Shares policy through git. Commit .cc-safety-net/ so clones and cloud sessions get the same rules. See Team Setup.
  • Embeds in your own tools. Call checkCommand from Node.js without installing the hook. See Library API.

Quick start

You need Node.js 18 or higher. Install into the coding CLIs on this machine, then check that protection is working:

npx -y cc-safety-net@latest install
npx -y cc-safety-net@latest doctor

Update with npx -y cc-safety-net@latest update and uninstall with npx -y cc-safety-net uninstall. Keep the @latest qualifier: a bare cc-safety-net spec can run an older copy from the npx cache. Per-CLI requirements are in Installation.

Development

See CONTRIBUTING.md to report a bug or request a feature.

License

MIT