dsh-permission-rules
Claude Code 风格的声明式权限规则:按序 allow/deny/ask 的 YAML 规则,在 tools/pre-execute 瀑布上匹配工具名、参数、工作区路径与 agent 身份,带完整会话日志审计、干跑模式与热重载。
Claude Code-style declarative permission rules: ordered allow/deny/ask YAML rules matching tool names, arguments, workspace paths, and agent identity on the tools/pre-execute waterfall, with full session-log audit, dry-run mode, and hot reload.
怎么安装
dsh plugin add dsh-permission-rules 简介
🛡️ dsh-permission-rules **Claude Code-style declarative permission rules for DeepSeek Harness.** *Rules decide what is known. A reviewer model decides what is not.* English · 简体中文 · Español · Português · हिन्दी --- Compatibility | Surface | Status | |---|---| | Harness | DeepSeek Harness 0.1.0-rc.5–0.1.0-rc.6 | | Node | ^22.19.0 || >=24.0.0 | | Platforms | All (host + web settings client) | | Model | Any (deny/ask reasons surface through tool results) | What you get dsh-permission-rules puts an ordered **allow / deny / ask** rule list in front of every tool call on the tools/pre-execute water…
推荐参考
信息
- 协议
- Apache-2.0
- 语言
- TypeScript
- GitHub 星标
- 114
- 月下载
- 6.3K
- 最近更新
- 2026-09-24
- 创建于
- 2026-08-13
基础安全检查
- 检查结果
- 无
- 收录来源
- curated:awesome-dsh-plugin.com, curated:awesome-dsh-plugin/awesome-dsh-plugin, curated:0xsline/awesome-deepseek-harness
- 主题标签
- ai-safety, allow-deny-ask, approval, cordis, deepseek, deepseek-harness, dsh, dsh-plugin, network, network-policy, permission, policy, proxy, safety
同类推荐
dsh-auto-mode
NanmiCoder/dsh-auto-mode
在 Workspace Write 与 Full access 之间增加 Auto 权限档:日常操作留在官方 workspace-write 沙箱内,由当前会话模型复核升权与破坏性调用,精确的越界访问按次放行一次,意图不明时询问,命中关键路径则拒绝。
dsh-passwords
slywalker2006/dsh-passwords
让 DeepSeek Harness 变成服务器级多租户平台:远程访问 + 自动 HTTPS、子用户权限与配额、沙盒强制、加密认证与审计日志。
sofagent
KongFangXun/sofagent/tree/main/engine/dsh-plugins/cordis-plugin-sofagent-audit
面向 AI 编程 agent 的提交时审计 harness——24 条 git diff 规则(密钥泄漏、越界改动、提示注入)、HMAC 签名审计链、快照回滚、84 工具 MCP server;dsh plugin add 即装。
dsh-vault
Ox0400/dsh-vault
Harness 的本地加密凭据保险库:Web 设置页与 vault_* 工具,可存取与复制密码、API 密钥、TOTP 与银行卡信息,支持健康审计、到期轮换、导入导出以及只读/询问访问模式。