PerryLink/dsh-permission-rules
Claude Code-style declarative permission rules for DeepSeek Harness: ordered allow/deny/ask rules with tool-na
dsh-permission-rules places an ordered YAML policy in front of every tool call. Rules can allow, deny, or ask based on tool globs, agent identity, nested arguments, workspace-relative paths, environment, or platform. Denials surface a model-visible reason, ask decisions use Harness's official approval seam, and every match or passthrough can be appended as an ignorable audit event. Hierarchical project files, hot reload, dry-run enforcement, schema validation, and bounded glob or regex handling make policies reviewable without changing the operating-system sandbox.
Install
dsh plugin --profile web add "github:PerryLink/dsh-permission-rules#main"A published npm alternative is dsh plugin --profile web add dsh-permission-rules. Restart the profile and verify the permission-rules configuration row with --dump-config.
Compatibility
DeepSeek Harness 0.1.1-rc.2, Node ^22.19.0 or >=24.0.0, all host platforms, and any model. Pre-marker 0.1.0-rc.6 hosts do not preserve the ignorable audit marker unless explicitly opted in.
Details
- Repo: PerryLink/dsh-permission-rules
- Category: Coding & Development
- Stars: 24
- Version: for DSH 0.1.1-rc.2
- Last push: 2026-09-21
- First seen: 2026-08-13
Recent updates
The current README documents rc.2 compatibility, hierarchical rule discovery, nested path matching, dry-run rollout, live reload with last-good retention, audit events, bounded pattern validation, and integration with dsh-auto-review for ask decisions.
FAQ
- How do I install dsh-permission-rules?
- Run dsh plugin --profile web add github:PerryLink/dsh-permission-rules#main, restart the profile, and verify the row with --dump-config.
- Does an allow rule bypass later security listeners?
- No. The README says allow and no-match delegate with next(), so downstream listeners still run.
- Does this replace the OS sandbox?
- No. It is a deterministic tool policy layer; operating-system sandbox policy remains a separate Harness seam.
Alternatives
timeance/dsh-approve-for-me · PerryLink/dsh-auto-review · omdsh-dev/dsh-security-audit