bigclawd/dsh-security-guard

Static and runtime security guard for dsh: rule-based scans for malicious code, prompt injection and token waste, runtime interception of dangerous tool calls, /scan command, plugin_scan tool, web panel, and allowlist.

A security guard for DSH that statically scans and runtime-intercepts the code and tool calls an agent touches. The static pass parses TS/JS with the TypeScript compiler API and a content pass adds regex/phrase/url/file rules plus token-waste heuristics (oversized files, base64-dominant blobs, repetition, comment padding), classifying every finding block / warn / clean. Runtime gates watch pre-step, tool and fs events: destructive exec/spawn is denied, shell pipelines writing to ~/.ssh or the token cache ask first, writes outside workspaceRoots are blocked, and assistant token usage is tracked. Surfaces include a /scan command, a plugin_scan tool, a live web panel and a user-managed allowlist.

Development & Runtime ★ 1 updated 2026-08-16
View on GitHub ↗

Install

dsh plugin --profile default add dsh-security-guard

README install (into the default profile; substitute your own profile name). npm package dsh-security-guard 0.1.0-rc.7 (registry-verified 2026-09-10; registry repository field -> github.com/bigclawd/dsh-security-guard). The host application can also be mounted directly (ctx.plugin(Guard, {...})) with options for rulesDir, scan limits, runtime gates, allowlist file, the web panel path and the install hook.

Compatibility

DSH host plugin; the web panel is served by the harness web server at the configured path (default /scan). Static analysis is purely AST-based (ts.createSourceFile) — scanned source is never imported, evaluated or executed. Runtime decisions use the host's native PreToolDecision / PostToolDecision / PreStepDecision contracts. Rules are plain JSON, overridable per id.

Details

Recent updates

README documents the install hook: because the host emits no "package installed" event, the guard watches the profile manifest ($DSH_HOME/profiles/<name>/package.json) and statically scans every newly added dependency under node_modules, recording the report as an install event, a guard/install-scan event and a guard-install-scans.jsonl entry (disable with installHook: { enabled: false }).

FAQ

How do I install dsh-security-guard?
Run: dsh plugin --profile default add dsh-security-guard (use your own profile name), then use /scan <path> or the plugin_scan tool.
Does the scanner run the code it checks?
No. The scanner is purely static — only ts.createSourceFile / ts.createScanner are used, and scanned source is never imported, evaluated or executed; there are no opaque AI-signature or hashing mechanisms, only auditable id-overridable JSON rules.
What does it do at runtime?
It intercepts before actions happen: it rejects steps matching prompt-injection or token-drain patterns, denies destructive exec/spawn, asks on shell pipelines writing to ~/.ssh or the token cache, blocks writes outside workspaceRoots, observes reads of sensitive paths, and warns on suspicious token consumption.

More plugins in Development & Runtime

Browse more in Development & Runtime

Guides for Development & Runtime plugins