bigclawd/dsh-security-guard
Static and runtime security guard for dsh: rule-based scans for malicious code, prompt injection and token waste, runtime interception of dangerous tool calls, /scan command, plugin_scan tool, web panel, and allowlist.
A security guard for DSH that statically scans and runtime-intercepts the code and tool calls an agent touches. The static pass parses TS/JS with the TypeScript compiler API and a content pass adds regex/phrase/url/file rules plus token-waste heuristics (oversized files, base64-dominant blobs, repetition, comment padding), classifying every finding block / warn / clean. Runtime gates watch pre-step, tool and fs events: destructive exec/spawn is denied, shell pipelines writing to ~/.ssh or the token cache ask first, writes outside workspaceRoots are blocked, and assistant token usage is tracked. Surfaces include a /scan command, a plugin_scan tool, a live web panel and a user-managed allowlist.
Install
dsh plugin --profile default add dsh-security-guardREADME install (into the default profile; substitute your own profile name). npm package dsh-security-guard 0.1.0-rc.7 (registry-verified 2026-09-10; registry repository field -> github.com/bigclawd/dsh-security-guard). The host application can also be mounted directly (ctx.plugin(Guard, {...})) with options for rulesDir, scan limits, runtime gates, allowlist file, the web panel path and the install hook.
Compatibility
DSH host plugin; the web panel is served by the harness web server at the configured path (default /scan). Static analysis is purely AST-based (ts.createSourceFile) — scanned source is never imported, evaluated or executed. Runtime decisions use the host's native PreToolDecision / PostToolDecision / PreStepDecision contracts. Rules are plain JSON, overridable per id.
Details
- Repo: bigclawd/dsh-security-guard
- Category: Development & Runtime
- Stars: 1
- Version: npm dsh-security-guard 0.1.0-rc.7 (registry-verified 2026-09-10)
- Last push: 2026-08-16
- First seen: 2026-08-16
Recent updates
README documents the install hook: because the host emits no "package installed" event, the guard watches the profile manifest ($DSH_HOME/profiles/<name>/package.json) and statically scans every newly added dependency under node_modules, recording the report as an install event, a guard/install-scan event and a guard-install-scans.jsonl entry (disable with installHook: { enabled: false }).
FAQ
- How do I install dsh-security-guard?
- Run: dsh plugin --profile default add dsh-security-guard (use your own profile name), then use /scan <path> or the plugin_scan tool.
- Does the scanner run the code it checks?
- No. The scanner is purely static — only ts.createSourceFile / ts.createScanner are used, and scanned source is never imported, evaluated or executed; there are no opaque AI-signature or hashing mechanisms, only auditable id-overridable JSON rules.
- What does it do at runtime?
- It intercepts before actions happen: it rejects steps matching prompt-injection or token-drain patterns, denies destructive exec/spawn, asks on shell pipelines writing to ~/.ssh or the token cache, blocks writes outside workspaceRoots, observes reads of sensitive paths, and warns on suspicious token consumption.