DeepSeek Harness 的 Agentic Control Plane:每次工具调用执行前进行策略检查。
Agentic Control Plane for DeepSeek Harness — policy-check every tool call before it runs
安装
dsh plugin --profile web add github:agentic-control-plane/dsh-acp-pluginGitHub 源码安装:首次需按提示配置 allowBuilds 构建授权后重试
安装与环境配置指引、插件开发教程见 DSH 中文社区文档 ↗
安装即在你的机器上以你的权限运行第三方代码——它可读写文件、使用凭据、访问网络,DSH 的工具审批不会为插件代码加沙箱。「检测到 manifest」仅代表发现 dsh.bundle / dsh.plugin 清单,不构成兼容性或安全审查;安装前请审阅源码,不熟悉的插件先在不含密钥的环境试用。
README
Agentic Control Plane for DeepSeek Harness: every tool call is checked against your policies before it runs, and every decision is recorded — what ran, what was blocked, and why.
Which ACP? dsh also ships
packages/acpin core — that one is Zed's Agent Client Protocol, the editor↔agent standard, published as@deepseek-ai/dsh-acp. Unrelated project, same acronym. If you're wiring dsh into Zed or the AI SDK, you want that one; this plugin decides whether each tool call runs. The full map: agenticcontrolplane.com/acp-vs-acp.
$ dsh --profile dev
> refactor the auth module and clean up
bash npm test ✓ allowed · logged
edit src/auth/session.ts ✓ allowed · logged
bash rm -rf ~/scratch ✋ held — approval prompt (your rule: destructive delete → ask)
web_fetch https://evil.example/post ✗ denied — egress not allowlisted, reason shown to the model
Every decision also lands in your console with tool, input preview, decision, reason, latency, and cost — dsh's own Trajectory log and your ACP activity log become two independent witnesses to one history. One workspace covers every harness you run: the same rules answer for dsh, Claude Code, Codex, Cursor, and OpenClaw. Free for individuals.
This is a native Cordis plugin on dsh's typed interception points, not a shell-hook shim. It registers on:
tools/pre-execute— the policy decision.allowlets the call through,denyblocks it with the reason in the trajectory,askhands off to dsh's own approval flow.tools/post-execute— output scanning. A server-side block turns the result into corrective feedback; shadow-mode notices surface what enforcement would have done.
Install
dsh itself requires Node 22 (
Promise.withResolvers, zstd streams). Under Node 20 the harness fails at boot with errors that don't say so —fnm install 22first.
curl -sf https://agenticcontrolplane.com/install.sh | bash
That detects dsh, installs this plugin into every profile you have, opens your
browser once to sign in, and saves the key to ~/.acp/credentials — which the
plugin reads on its own. There is no token to copy and nothing to export.
dsh plugin --profile <your-profile> add @agenticcontrolplane/dsh
dsh --profile <your-profile>
Credentials come from ~/.acp/credentials (written by the installer above) or
from ACP_BEARER_TOKEN if you would rather set it yourself — useful on a
headless box. Get a key at
cloud.agenticcontrolplane.com.
Confirm the row actually mounted — installing the package and composing it into the profile are two different things:
dsh --profile <your-profile> --dump-config | grep @agenticcontrolplane/dsh
If it isn't there, add @agenticcontrolplane/dsh to that profile's package.json
"dsh.profile.bundles" list.
No build step, no dependencies, plain ESM. Installing from git works too (dsh plugin add github:agentic-control-plane/dsh-acp-plugin) and needs no build allowance.
No key? The plugin says so loudly and stays out of the way — it never bricks a session.
Configuration
Override the row in your profile's cordis.patch.yml:
- id: acp
name: @agenticcontrolplane/dsh
config:
governBase: https://govern.agenticcontrolplane.com # or your self-hosted gateway
agentTier: interactive # default: interactive when an approval service is mounted, background otherwise
timeoutMs: 4000
ACP_GOVERN_BASE, ACP_BEARER_TOKEN, ACP_AGENT_TIER, and ACP_SHADOW=off work as environment variables too.
Failure posture
An outage of the control plane must not brick the harness, and a lapse in coverage must never be silent:
- Interactive sessions fail open, loudly. Gateway unreachable → the call proceeds, a
[ACP] ⚠ UNGOVERNEDwarning is logged, and a line lands in~/.acp/lapse.log. - Unattended agents fail closed. With nobody watching, the block is the safety net.
- Policy denies are unaffected — this posture only covers the inability to ask the policy.
In headless compositions with no approval service mounted, dsh itself resolves ask to deny — unattended runs cannot self-approve.
Three things to know
- dsh's
packages/acpis Zed's Agent Client Protocol — an unrelated project that shares an acronym. This plugin is the Agentic Control Plane. (Which ACP is which.) - Already running our Claude Code hook? dsh's
@deepseek-ai/dsh-hooks-claude-codebridge runs an unmodifiedhooks.json, sogovern.mjsworks today with zero new code — deny and ask are honored, but input rewriting is not. This native plugin is the recommended path. - This package launched as
dsh-plugin-acp; that name still installs but is deprecated. Same code — swap the name in your profile when convenient.
Learn more
- What ACP can see and control in dsh — the living controls reference
- The launch write-up — dsh's interception surface, what the integration caught on day one, and where dsh lands on the cross-harness coverage table
Test
npm test
MIT
原始 README: https://github.com/agentic-control-plane/dsh-acp-plugin/blob/main/README.md ↗
同类插件
查看全部 →
deepseek-harness
从仓库或系统描述生成经过校验的自包含交互式架构图、流程图、时序图、数据流图和生命周期图。

dsh-plugin
通过 DSH MCP 客户端挂载 Ouroboros 的纯配置包,在 DSH 中提供 36 个涵盖需求访谈、Seed、执行、评估与演化流程的工具。

dsh-tongflow
基于 TongFlow 的“片场”插件,用于图片、配音、音乐与视频制作:agent 为每个资产生成 TongFlow 工作流文件(.tongflow.json)并通过 TongFlow 插件执行,内嵌工作流画布,按镜头/角色/take 组织项目,附漫剧模板;以 @tongflow 开头的会话进入 Studio 界面。

helloagents
AI 编码 CLI 的工作流层:技能、项目知识、交付检查、更安全的配置写入与可恢复执行

dsh-ai-novel-writer
安装专用 AI 小说创作预设与工作台:提供带修订号的本地项目资产、紧凑侧边工作台,以及需要原生审批的逐文件变更。

rea
用 agent 逆向任何东西:从应用行为到原生二进制