dsh-agentfuse-plugin
by mkaliezz
面向 AI agent 的确定性、失败关闭的工具调用授权——带证据;ALPHA 阶段,寻找首个真实部署
Deterministic, fail-closed tool-call authorization for AI agents — with evidence. Status: ALPHA · seeking the first real (non-self) deployment
安装
dsh plugin --profile web add github:mkaliezz/dsh-agentfuse-pluginGitHub 源码安装:首次需按提示配置 allowBuilds 构建授权后重试
安装与环境配置指引、插件开发教程见 DSH 中文社区文档 ↗
安装即在你的机器上以你的权限运行第三方代码——它可读写文件、使用凭据、访问网络,DSH 的工具审批不会为插件代码加沙箱。「检测到 manifest」仅代表发现 dsh.bundle / dsh.plugin 清单,不构成兼容性或安全审查;安装前请审阅源码,不熟悉的插件先在不含密钥的环境试用。
README
目录
Deterministic, fail-closed tool-call authorization for AI agents — with evidence. Status: ALPHA · seeking the first real (non-self) deployment
AgentFuse is a pre-dispatch policy boundary for side-effect-capable AI agent
tools, ported from the DHMS AgentFuse Python project
(MkaliezZ/dhms-engine).
AGENTFUSE_IS_A_DANGER_CLASSIFIER=false
AGENTFUSE_IS_A_POLICY_AND_AUTHORIZATION_BOUNDARY=true
AGENTFUSE_DECISIONS=allow|block
AGENTFUSE_DEFERRALS=ask
AGENTFUSE_FAILS_CLOSED=true
A blocked call is a completed policy decision with non-execution evidence — never a failed tool execution. Evidence carries reason codes, policy ids, and a canonical arguments hash, never raw arguments or credentials.
Packages
| Package | What it is | Depends on |
|---|---|---|
packages/core · @dhms-agentfuse/core |
Framework-agnostic engine: decision/evidence vocabulary, deterministic policy resolution, canonical hashing | nothing |
packages/dsh-agentfuse · @dhms-agentfuse/dsh-agentfuse |
DeepSeek Harness guard plugin: tested tools/pre-execute gate, DSH config schema, durable agentfuse/decision session event, and host-owned approval deferral (askTools) |
@dhms-agentfuse/core, DSH |
The core defines the bounded policy vocabulary; the DSH package is one experimental adapter. Potential future integrations are tracked in the roadmap, but are not implemented here.
Quickstart (DeepSeek Harness)
# cordis.yml (or a cordis.patch.yml insert)
- id: agentfuse
name: '@dhms-agentfuse/dsh-agentfuse'
config:
defaultAction: block # fail-closed fall-through
denyTools: [] # deterministic block, always wins
askTools: [] # defer to the DSH human-approval chain
allowTools: [] # non-empty = only these names may run
logDecisions: false # durable evidence; needs in-repo catalog
See the adapter README for the policy order, the approval integration, and the install paths (bundle + PR).
Cross-adapter conformance
The DSH adapter consumes the provider-neutral DHMS AgentFuse v3.6.2 fixture
snapshot with source commit and SHA-256 provenance. Against DeepSeek Harness
commit 99f6f02fecdb7dff40c3fbc9470f5907c29f74ca, the real integrated
tools/pre-execute path records 11 PASS and 3 explicitly justified N/A cases;
it does not claim coverage of unwrapped or future DSH paths.
See the adapter conformance notes and the checked-in fixture provenance.
Repository layout
packages/
core/ @dhms-agentfuse/core — zero runtime dependencies
dsh-agentfuse/ @dhms-agentfuse/dsh-agentfuse — the DSH adapter (bundle)
ROADMAP.md phases, version line, stop-lines
Relationship to DHMS
AgentFuse is the runtime-execution-control line of DHMS (Digital Hyperthymesia
Memory Systems). The engine is a faithful TypeScript port of
dhms_agentfuse's decision engine and agentfuse-evidence-schema-v0.1;
decision and execution remain separate lifecycle facts.
License
Apache-2.0. See LICENSE.
原始 README: https://github.com/MkaliezZ/dsh-agentfuse-plugin/blob/main/README.md ↗
同类插件
查看全部 →
deepseek-harness
从仓库或系统描述生成经过校验的自包含交互式架构图、流程图、时序图、数据流图和生命周期图。

dsh-plugin
通过 DSH MCP 客户端挂载 Ouroboros 的纯配置包,在 DSH 中提供 36 个涵盖需求访谈、Seed、执行、评估与演化流程的工具。

dsh-tongflow
基于 TongFlow 的“片场”插件,用于图片、配音、音乐与视频制作:agent 为每个资产生成 TongFlow 工作流文件(.tongflow.json)并通过 TongFlow 插件执行,内嵌工作流画布,按镜头/角色/take 组织项目,附漫剧模板;以 @tongflow 开头的会话进入 Studio 界面。

helloagents
AI 编码 CLI 的工作流层:技能、项目知识、交付检查、更安全的配置写入与可恢复执行

dsh-ai-novel-writer
安装专用 AI 小说创作预设与工作台:提供带修订号的本地项目资产、紧凑侧边工作台,以及需要原生审批的逐文件变更。

rea
用 agent 逆向任何东西:从应用行为到原生二进制