DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Safe Delete — DeepSeek Harness 插件(DSH Plugin)
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录
← Plugins
S

dsh-safe-delete

Safe Delete

在工具防护层拦截任何 DSH 代理会话(GUI、自动化运行、无头桥接)发出的 `rm` 命令,并将目标移至 macOS Trash,而不是删除。可在 Web GUI 的 Settings → General 中切换。

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add github:NattoCB/dsh-safe-delete#149190d58104e8b09497967babaa69de2252d309
README兼容性版本

兼容性与来源证明

Safe Delete 以 dsh-safe-delete 发布,当前版本为 0.2.0。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
web
发布来源
github
Registry 更新时间
2026/9/3

版本

0.2.0stable
2026/9/3
0.1.0stable
2026/9/1

相关插件

正在加载相关插件…

最新版
0.2.0
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
未提供
文件数
未提供
Surface
web
许可证
MIT
发布源
github
GitHub
★ 0
周下载
0
最近提交
2026/9/3
查看源码 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题

相关插件

继续浏览 security-access 分类下经过校验的插件。

Doctor@linxin666/dsh-doctorDSH 配置档案的事务性救援模式,配备受监督的启动器、隔离的恢复容器、确定性修复、健康监控以及本地 Web 恢复控制台Pocketdsh-pocket把 DeepSeek Harness 装进你的口袋:一个包、一个设置页,手机扫码即同步访问电脑上的 DSH(局域网 + 公网,实时同屏)。DSCODE@toddzheng024/dscode-bundle完整的 DeepSeek 编码代理,支持持久化 shell、Ultra 协作和自动权限审查。Auto Reviewdsh-auto-review针对 DeepSeek Harness 审批请求的第二模型 AI 自动审查:只读审查子代理在审批应答链上决定允许或拒绝,并采用故障关闭回退机制和完整的会话日志审计。

README

dsh-safe-delete

Every rm an agent runs becomes a recoverable move to the macOS Trash.





One global guard on the tools registry — ctx.tools.guard() —— no tool, prompt, or core changes

A DeepSeek Harness host-side plugin that makes agent-issued rm commands recoverable: targets are moved to the macOS Trash instead of deleted, across GUI sessions, automation runs, headless bridges, and subagents. One switch in Settings → General turns it off — disabled, commands run with native DSH behavior.

Capabilities

  • Recoverable deletion — an rm in command position is denied and rewritten to /usr/bin/trash -v; the model receives a report of exactly what was moved, so nothing silently disappears.
  • Every session, one guard — registers once on the DSH tools registry; GUI chats, scheduled automations, headless bridges, and subagents are all covered with zero per-session wiring.
  • Shell-aware interception — quote-preserving lexer catches sudo rm, /bin/rm, env/nice-prefixed rm, VAR=x rm, and xargs rm inside compound commands (&&, ||, ;, |).
  • Fail-safe by design — constructs that could hide an rm ($(...), backticks, subshells, heredocs, eval, nested sh -c) are denied with guidance instead of rewritten; a failed trash is reported, never retried as real deletion.
  • Runtime switch — toggle in the web GUI (Settings → General → Safe Delete) or via POST /safe-delete/config; the state persists across restarts in $DSH_HOME/storages/safe-delete.json.

How it works

The plugin installs one guard on the DSH tools registry. Every bash tool call is scanned before execution:

flowchart LR
    A["bash tool call"] --> B{"rm in command<br/>position?"}
    B -- "no" --> C["native execution"]
    B -- "yes" --> D{"switch on?"}
    D -- "off" --> C
    D -- "on" --> E{"safely<br/>rewritable?"}
    E -- "no: subshell, eval,<br/>heredoc, backticks" --> F["deny with guidance,<br/>nothing runs"]
    E -- "yes" --> G["run trash -v, deny the<br/>original, report targets"]

Intercepted calls are denied and re-executed as trash by the guard itself, so quoting and globs survive:

[dsh-safe-delete] intercepted `rm` — the targets were MOVED TO TRASH (recoverable),
not deleted. Original command denied. Targets: build/ dist
trash: build/ → .Trash/build/

Plain non-rm commands pass through untouched; commands that merely mention rm (echo rm, grep "rm " log) are ignored. rm flags (-f, -r, …) are stripped rather than honored: trash moves whole directories natively.

Scope and limits

CoveredNot covered
Commandsrm, sudo rm, absolute-path rm, xargs rm — simple and compoundfind -delete, unlink, git clean, language runtimes' own file APIs
Guaranteeintercepted at the guard layer, before executionthe guard is an accident-prevention net for the most common destructive verb, not a sandbox

sudo rm is intercepted before sudo ever runs, but trashing files that require root can still fail — trash errors are reported verbatim.

Install

dsh plugin --profile web add github:NattoCB/dsh-safe-delete

Restart the DSH web process — host-side bundles and their patches load at process start. On boot the plugin logs rm guard active once.

Configuration

SurfaceHow
Web GUISettings → General → Safe Delete — the switch takes effect on the next bash call, no reload
HTTPGET /safe-delete/config → { "enabled": bool }; POST /safe-delete/config with { "enabled": bool }
File$DSH_HOME/storages/safe-delete.json — { "enabled": bool }

Default: enabled. A missing or corrupt state file also resolves to enabled — installing the plugin expresses the intent to have the guard, and a corrupt file never silently downgrades protection.

Development

npm test        # node --test: lexer, rewrite matrix, guard contract, switch store/API

The lexer/rewriter is exported as exports._internals so tests exercise the real code paths (analyzeCommand, tokenize, splitSegments, makeGuard, ConfigStore, handleConfigRequest).

License

MIT — part of the awesome-dsh-plugin ecosystem.