dsh-dros-vajraclaw
Local tool-call failsafe for DSH: blocks a fixed list of high-risk shell patterns and credential-file reads before execution, with a per-session hash-linked JSONL audit log, and an optional external Gateway for centralized policy.
DSH 本機工具調用防護外掛:攔截高風險 Shell 指令模式與敏感憑證讀取,具備持久化哈希鏈 JSONL 審計記錄,可選配外部 Gateway 集中治理。
How to install
dsh plugin add dsh-plugin-vajraclaw About
⚡ DROS™ VajraClaw for DSH & Multi-Agent Workstations Local Tool-Call Failsafe & Runtime Governance Sidecar for Autonomous AI Agents English | 繁體中文說明 | 🌐 Official Website **Local tool-call failsafe for DSH**: blocks high-risk shell patterns (e.g. destructive recursive deletions, fork bombs, disk overwriting) and credential-file reads before execution, with a persistent hash-linked JSONL audit log, and an optional external Gateway for centralized multi-agent policy. 🎯 **Dual Architecture Overview:** 1. **Embedded Mode (Default)**: Zero-dependency local TypeScript pattern-matching failsafe and …
Recommendation signals
Meta
- License
- Apache-2.0
- Language
- TypeScript
- GitHub stars
- 0
- mo. downloads
- –
- Last push
- 2026-09-05
- Created
- 2026-08-20
Basic safety check
- Findings
- None
- Sources
- curated:awesome-dsh-plugin.com, curated:awesome-dsh-plugin/awesome-dsh-plugin
- Topics
- agent-governance, agent-security, awesome-dsh-plugin, deepseek-harness, dros, dsh-market, dsh-plugin, governance, guardrail, runtime-security, security, vajraclaw, w3c-did, zero-trust
Related plugins
dsh-secure-audit
PensiveFei/dsh-secure-audit
Read-only security and compliance plugin for DeepSeek Harness: prompt-injection detection, Chinese-PII redaction, and a local configuration audit with redacted, reproducible reports.
dsh-auto-approve
Jiao-XXX/dsh-auto-approve
Adds an `auto` permission preset between workspace-write and danger-full-access: a classifier grants routine sandbox escalations once, while dangerous or uncertain requests still go to a human.
dsh-plugin-vet
wulun811/dsh-plugin-vet
Plugin trust pipeline for DeepSeek Harness: deterministic static scan with verdicts, opt-in runtime guard with honeypot lures, agent audit-protocol skill, and a browser shield status light. Alarm-only, never an enforcer.
dsh-agent-approval
MoonlitDropOfBlood/dsh-agent-approval
An independent approval subagent judges every sandbox escalation, with a configurable model and an audit log.