DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Guardian — DeepSeek Harness 插件(DSH Plugin)
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录
← Plugins
G

dsh-guardian

Guardian

DeepSeek Harness 的危险操作策略、规范输出脱敏和安全审查。

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add github:lonelymoon87/dsh-guardian#6091479072ea236249a858467d481708868678e8
README兼容性版本

兼容性与来源证明

Guardian 以 dsh-guardian 发布,当前版本为 0.1.3。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
any
发布来源
github
Registry 更新时间
2026/8/21

版本

0.1.3stable
2026/8/21

相关插件

正在加载相关插件…

最新版
0.1.3
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
未提供
文件数
未提供
Surface
any
许可证
MIT
发布源
github
GitHub
★ 1
周下载
0
最近提交
2026/8/21
查看源码 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题

相关插件

继续浏览 security-access 分类下经过校验的插件。

Doctor@linxin666/dsh-doctorDSH 配置档案的事务性救援模式,配备受监督的启动器、隔离的恢复容器、确定性修复、健康监控以及本地 Web 恢复控制台Mobiledsh-mobileDeepSeek Harness 移动端适配与安全访问插件,支持局域网、远程连接、Android App 和手机浏览器。DSCODE@toddzheng024/dscode-bundle完整的 DeepSeek 编码代理,支持持久化 shell、Ultra 协作和自动权限审查。Auto Reviewdsh-auto-review针对 DeepSeek Harness 审批请求的第二模型 AI 自动审查:只读审查子代理在审批应答链上决定允许或拒绝,并采用故障关闭回退机制和完整的会话日志审计。

README

dsh-guardian

Runtime dangerous-operation policy, canonical output redaction, and security-review workflow for DeepSeek Harness.

The v0.1.3 release is tested with DSH 0.1.0-rc.8 and 0.1.1-rc.1 while retaining the rc.6-compatible peer range. Prebuilt packages are distributed through GitHub Releases. The unscoped npm name is owned by another publisher, so this project is not published there.

简体中文

MVP

  • A tools/pre-execute waterfall classifies dangerous shell, SQL, and structured file-write arguments as deny, ask, or unchanged.
  • standard, strict, and permissive profiles provide different approval levels while retaining non-negotiable deny rules.
  • Custom regular-expression rules add deployment-specific deny or ask decisions.
  • A tools/post-execute waterfall redacts common credentials from canonical JSON results, failures, rendered text, and block feedback.
  • Consecutive text blocks are scanned as one stream so splitting a credential across blocks does not bypass redaction.
  • /security-review loads a bundled, read-only security-review skill.

The MVP is not a process sandbox, authorization system, data-loss-prevention service, or substitute for the provider policies mounted below it.

Policy behavior

The built-in rules deny recursive forced deletion of root or home paths, network-response pipes into shells, raw writes to /dev, and writes to /etc. Force pushes, destructive SQL, and other recursive forced deletions ask for approval. Strict mode additionally asks for sudo; permissive mode retains only deny rules.

Guardian always delegates through next(). When another policy listener returns a decision, the most restrictive result wins: deny outranks ask, which outranks allow.

Redaction behavior

Built-in patterns cover AWS access-key IDs, GitHub tokens, sk- API keys, PEM private-key blocks, and common credential assignments. Redaction is applied to the canonical JSON value when one exists, preserving arrays, objects, numbers, booleans, and null values. This prevents Code Mode and downstream renderers from retaining an unredacted value behind safe-looking display text.

Logs contain only the tool name, match count, and redaction labels. The plugin does not append custom session events because the current external plugin API does not expose an ignorable event envelope; emitting a required unknown event would make old sessions unreadable after uninstall.

Permissions and data

  • Guardian inspects tool names, arguments, canonical results, and rendered output inside the current DSH process. It can deny a call or request approval but never executes the requested operation itself.
  • Redaction replaces matched secret text before downstream model-visible consumers receive the canonical result. Logs retain only the tool name, match count, and non-secret labels.
  • The plugin does not read credential stores, make network requests, write workspace files, transmit telemetry, or persist custom session events.

Install

The package supports DSH >=0.1.0-rc.6 <0.2.0 plugin APIs and Node.js ^22.19 || >=24.

dsh plugin --profile web add https://github.com/lonelymoon87/dsh-guardian/releases/download/v0.1.3/dsh-guardian-0.1.3.tgz

The release tarball is prebuilt and needs no build allowance. A pinned source install is also supported:

dsh plugin --profile web add github:lonelymoon87/dsh-guardian#v0.1.3

The source install runs this package's prepare build. pnpm 10 and later reject it until the profile allowlists the exact package key printed by the failed command; apply that instruction and rerun the same dsh plugin add command. Replace web with headless to install into the one-shot agent profile.

To upgrade, rerun dsh plugin add with the newer release URL. To uninstall:

dsh plugin --profile web remove dsh-guardian

Configuration

- id: guardian
  name: dsh-guardian
  config:
    profile: standard
    rules:
      - name: production-host
        pattern: production\\.internal
        action: ask
        reason: production target requires review
    redaction:
      enabled: true
      patterns:
        - label: internal-token
          pattern: INT_[A-Z0-9]{12}

Regular-expression flags may contain only i, m, s, and u. Invalid expressions and labels fail during plugin loading.

Verification

The tests cover positive and negative cases for every built-in rule, structured paths, profile behavior, downstream policy composition, nested canonical values, custom credentials, block feedback, split text blocks, disabled redaction, command dispatch, and invalid configuration.

  • The v0.1.3 tarball installs directly from its HTTPS release URL into clean DSH 0.1.0-rc.8 and 0.1.1-rc.1 profiles.
  • The packed bundle and pinned GitHub source install both appear in dsh --dump-config.
  • CI covers Node 22.19 and Node 24; a compatibility matrix repeats the real install against DSH 0.1.0-rc.8 plus the latest and next npm tags.
  • Bugs and compatibility reports are tracked in GitHub Issues.

License

MIT