dsh-safeguard
DSH plugin: block dangerous shell commands and secret leakage before execution (tools/pre-execute veto)
DSH插件:在执行前阻止危险shell命令和密钥泄露(tools/pre-execute否决权)。
How to install
dsh plugin add dsh-safeguard About
dsh-safeguard 面向 DeepSeek Harness(DSH)的危险命令 + 密钥泄漏拦截插件。挂载到 tools/pre-execute waterfall,在工具解析前短路拒绝,被拦截的副作用不会发生。 简介 **危险命令拦截**:对 bash 工具的命令做正则匹配,命中即 deny。 **密钥泄漏拦截**:对所有工具的 arguments 做 JSON.stringify 后扫描常见密钥模式,命中即 deny。 **可配置**:危险/密钥检测开关、额外正则、精确豁免名单。 **两个辅助工具**:guard_list(列出当前规则)与 guard_check(纯检查不拦截,供调试/自检)。 重要:本插件是**基于正则的启发式拦截**,不验签、不识别密钥真伪、不做沙箱隔离。它无法替代密钥扫描器、签名校验或操作系统级沙箱,只能拦截明显的高风险动作。 安装 sh dsh plugin --profile <profile> add dsh-safeguard 本地开发安装: sh dsh plugin --profile <profile> add file:./plugins/dsh-safeguard 默认规则表 危险命令(enableDanger) | 规则名 | 匹配内容 | |---|---| | rm -rf | rm -rf / rm -fr 且目标是 /…
Recommendation signals
Meta
- License
- MIT
- Language
- JavaScript
- GitHub stars
- 0
- mo. downloads
- 646
- Last push
- 2026-08-16
- Created
- 2026-08-15
Links
Basic safety check
- Findings
- None
- Sources
- curated:0xsline/awesome-deepseek-harness
- Topics
- deepseek-harness, dsh-plugin
Related plugins
mobile-mcp
mobile-next/mobile-mcp
Model Context Protocol Server for Mobile Automation and Scraping (iOS, Android, Emulators, Simulators and Real Devices)
davinci-resolve-mcp
samuelgursky/davinci-resolve-mcp
MCP server integration for DaVinci Resolve Studio
ssh-mcp
tufantunc/ssh-mcp
MCP server exposing SSH control for Linux servers via Model Context Protocol.