MkaliezZ/dsh-agentfuse-plugin

Deterministic, fail-closed tool-call authorization for AI agents, with evidence. A pre-dispatch policy boundary for side-effect-capable agent tools, ported from the DHMS AgentFuse Python project. A blocked call is a completed policy decision with non-execution evidence — never a failed tool execution; evidence carries reason codes, policy ids, and a canonical arguments hash, never raw arguments or credentials. Framework-agnostic core (@dhms-agentfuse/core) plus the DSH guard plugin that registers a tested tools/pre-execute gate, durable decision events, and askTools deferral to the DSH human-approval chain. defaultAction blocks by default (fail-closed); denyTools always wins; non-empty allowTools means only those names may run.

Agent Capabilities ★ 3 updated 2026-08-29 ✅ runtime-tested
View on GitHub ↗

Install

cordis.patch.yml insert: - id: agentfuse, name: '@dhms-agentfuse/dsh-agentfuse'

Install per README (English, ALPHA status): add an insert row to cordis.yml or cordis.patch.yml: - id: agentfuse, name: '@dhms-agentfuse/dsh-agentfuse' with config (defaultAction: block, denyTools: [], askTools: [], allowTools: [], logDecisions: false). npm package @dhms-agentfuse/dsh-agentfuse 0.2.1 exists (registry-verified 2026-08-26); adapter README documents install paths (bundle + PR).

Compatibility

DeepSeek Harness — real integrated tools/pre-execute gate; DSH config schema; durable agentfuse/decision session event; host-owned approval deferral (askTools).

Details

Recent updates

v0.2.1: pre-execute gate; defaultAction block (fail-closed); deny/ask/allow tool lists; durable decision events with reason codes; canonical argument hashing.

FAQ

Is it safe to install?
It is ALPHA and fails closed — defaultAction: block means unlisted tools are blocked rather than allowed; evidence never contains raw arguments or credentials.
What happens when a call is blocked?
It is recorded as a completed policy decision with non-execution evidence (reason code, policy id, canonical args hash), not as a failed tool execution.
Can I defer decisions to a human?
Yes — askTools defers to the DSH human-approval chain instead of blocking.

Alternatives

jkrandom-sudo/dsh-plugin-audit · omdsh-dev/dsh-security-audit · lxzy-7/dsh-plugin-guard

More plugins in Agent Capabilities

Browse more in Agent Capabilities

Guides for Agent Capabilities plugins