lonelymoon87/dsh-guardian

Adds dangerous-operation policy checks, output redaction, and a security-review workflow.

dsh-guardian is runtime dangerous-operation policy, canonical output redaction and a security-review workflow for DeepSeek Harness. A tools/pre-execute waterfall classifies dangerous shell, SQL and structured file-write arguments as deny/ask/unchanged; standard/strict/permissive profiles set approval levels while keeping non-negotiable deny rules; custom regex rules add deployment-specific decisions. Built-in rules deny recursive forced deletion of root/home paths, network-response pipes into shells, raw /dev writes and /etc writes; force pushes, destructive SQL and other recursive forced deletions ask. A tools/post-execute waterfall redacts common credentials (AWS keys, GitHub tokens, …) from canonical JSON results, failures, rendered text and block feedback, scanning consecutive text blocks as one stream so split credentials cannot bypass redaction. /security-review loads a bundled read-only security-review skill; when other policy listeners exist the most restrictive result wins (deny > ask > allow).

Development & Runtime ★ 0 updated 2026-08-21
View on GitHub ↗

Install

dsh plugin --profile web add github:lonelymoon87/dsh-guardian#v0.1.3

GitHub Releases per README (EN primary with 简体中文 edition): prebuilt packages ship through GitHub Releases; the unscoped npm name is owned by another publisher so this project is not published there — install from the v0.1.3 release asset or the pinned GitHub route github:lonelymoon87/dsh-guardian#v0.1.3. Tested with DSH 0.1.0-rc.8 and 0.1.1-rc.1 while retaining an rc.6-compatible peer range.

Compatibility

DSH 0.1.0-rc.6 through 0.1.1-rc.1; hooks tools/pre-execute and tools/post-execute; profiles standard/strict/permissive; not a process sandbox or authorization system.

Details

Recent updates

v0.1.3 current (GitHub Releases; tested against DSH 0.1.0-rc.8 / 0.1.1-rc.1 per README).

FAQ

What does the pre-execute gate do?
Classifies dangerous shell, SQL and structured file-write arguments as deny, ask or unchanged, with standard/strict/permissive profiles over a fixed deny rule set.
What gets redacted on output?
Common credentials — AWS access-key IDs, GitHub tokens and similar — are redacted from canonical JSON results, failures, rendered text and block feedback, scanning consecutive blocks as one stream.
Is it a sandbox?
No — the README is explicit that it is not a process sandbox, authorization system, DLP service or substitute for provider policies; it layers policy and redaction on the tool seams.

Alternatives

moon09300731/dsh-approval-gate · Starfie1d1272/dsh-builtin-toggles

More plugins in Development & Runtime

Browse more in Development & Runtime

Guides for Development & Runtime plugins