Drifter-yh/dsh-tool-policy

Declarative deny-by-default tool policy plugin for DeepSeek Harness

Applies allow / ask / deny rules to tool calls before they execute: a declarative, deny-by-default policy layer for built-in, third-party, and MCP tools that reuses Harness's existing approval and sandbox mechanisms. Typical uses: allow tool namespaces (read_*), require human approval for MCP tools (mcp__*), deny known destructive command patterns before the matched tool body starts, run a deny-by-default allowlist for unattended jobs, keep sensitive argument values out of policy feedback. A matching deny prevents that call from executing; it does not revoke the underlying capability — policy routing and capability sandboxing are complementary layers. Bundle defaults to deny with an empty rule list.

Other ★ 3 updated 2026-09-20 ✅ runtime-tested
View on GitHub ↗

Install

dsh plugin --profile my-profile add github:Drifter-yh/dsh-tool-policy#028e2ce4167a88ad32b0c6eec89ee22072189e71

GitHub pinned-commit install per README: dsh plugin --profile my-profile add github:Drifter-yh/dsh-tool-policy#028e2ce4167a88ad32b0c6eec89ee22072189e71 (pin the commit before allowing install-time code execution; the prepare script runs only the standalone tsdown build to create dist/; pnpm 10+ may require an allowBuilds entry). Profile-bundle install also documented: dsh plugin --profile my-profile add dsh-tool-policy — npm package not yet published as of 2026-08-26 (README cites registry, publishConfig public, 404 at verification time), so the github install is the reliable path.

Compatibility

DeepSeek Harness API range >=0.1.0-rc.5 <0.2.0; Cordis >=4.0.1 <5. Uses documented Context, tools service, and tools/pre-execute event only.

Details

Recent updates

v0.2.0: allow/ask/deny rules; deny-by-default; per-call policy layer; MCP namespace support (mcp__*); sensitive-argument redaction in feedback.

FAQ

Is this a sandbox?
No — it is a per-call policy layer. Harness sandboxing enforces capabilities; this plugin decides whether a specific known tool call is allowed, denied, or escalated to human approval.
How do MCP tools match?
DSH exposes MCP tools as mcp<serverName><rawName>, so an mcp__* rule covers the complete MCP namespace.
What is the default?
Deny with an empty rule list — configure the inserted tool-policy row in the profile layer before running tools.

Alternatives

omdsh-dev/dsh-security-audit · jkrandom-sudo/dsh-plugin-audit · PerryLink/dsh-doublecheck

More plugins in Other

Browse more in Other

Guides for Other plugins