dsh-guard
by kouyichi
dsh 安全治理:规则化工具拦截、完整工具调用审计轨迹与治理报告。
Security and governance for dsh: rule-based tool denial, full tool-call audit trail, and governance reports.
安装
dsh plugin --profile web add github:kouyichi/dsh-plugins#path:/dsh-guardGitHub 源码安装:首次需按提示配置 allowBuilds 构建授权后重试
安装与环境配置指引、插件开发教程见 DSH 中文社区文档 ↗
安装即在你的机器上以你的权限运行第三方代码——它可读写文件、使用凭据、访问网络,DSH 的工具审批不会为插件代码加沙箱。「检测到 manifest」仅代表发现 dsh.bundle / dsh.plugin 清单,不构成兼容性或安全审查;安装前请审阅源码,不熟悉的插件先在不含密钥的环境试用。
README
生态空白:整个 security & governance 分类都是 0-3★ 萌芽。本插件把两个头部 agent 的安全模式移植到 dsh:
- Codex「sandbox × approval」 → 声明式拒绝规则层(
tools.guard()官方 seam,单调拒绝、无规则即无操作) - Claude Code PreToolUse hook 审计(security-guidance)→ 全量工具调用审计 + 治理报告
工具
| 工具 | 功能 |
|---|---|
guard_rules |
规则管理:add {tool, pattern, reason} / remove / list / toggle。tool 支持通配(bash*) |
guard_report |
治理报告:工具分布、错误率、被拒统计、危险命令命中 |
guard_status |
插件状态 |
guard_export |
审计导出 markdown |
guard_clear |
清空审计 |
存储:~/.dsh/guard/rules.json + ~/.dsh/guard/audit.jsonl
示例
guard_rules action=add tool=bash pattern="rm -rf /" reason="禁止删除根目录"
guard_rules action=add tool=web_search reason="本项目禁用联网搜索"
guard_report period_days=7
原始 README: https://github.com/kouyichi/dsh-plugins/blob/main/dsh-guard/README.md ↗
同类插件
查看全部 →
dsh-anchored-standard
两阶段 DeepSeek Harness 预设:先 Minimal 对齐的 bootstrap,再切完整 Standard 工具(Project2 98/99)

PicGo-Core
极致的图片上传引擎,CLI 与 API 双支持

awesome-deepseek-harness
DeepSeek Harness(DSH)及其优秀社区插件的精选指南。

awesome-deepseek-harness
DeepSeek Harness (DSH)生态系统:来自dsh-external/hub和公共dsh-plugin主题的精选插件、工具和基础设施。

AI-Novel-Writer
本地优先 AI 小说创作工作台,提供 Windows/macOS 桌面版与 DeepSeek Harness 插件开发预览,支持角色、大纲、章节蓝图、审稿修稿和本地模型。

mcp-for-stata
MCP-for-Stata:把 Stata 集成进你的 agent