agentic-control-plane/dsh-acp-plugin

Agentic Control Plane for DeepSeek Harness — policy-check every tool call before it runs

Agentic Control Plane for DeepSeek Harness intercepts every tool call and checks it against your configured policies before it runs. Allowed calls are logged; blocked calls are denied with a reason shown to the model; held calls surface an approval prompt. Every decision — what ran, what was blocked, why — lands in the cloud console (cloud.agenticcontrolplane.com) alongside DSH's own Trajectory log, giving two independent witnesses to one execution history. One workspace covers all harnesses (dsh, Claude Code, Codex, Cursor).

Agent Capabilities ★ 5 updated 2026-08-17 ✅ runtime-tested
View on GitHub ↗

Install

dsh plugin --profile <your-profile> add @agenticcontrolplane/dsh

npm package @agenticcontrolplane/dsh 0.1.3 (registry-verified 2026-08-24). Zero npm dependencies. After install, a free account at cloud.agenticcontrolplane.com provides the policy console — every tool decision is logged there in addition to DSH's own Trajectory log. Alternatively install from GitHub: dsh plugin add github:agentic-control-plane/dsh-acp-plugin (no build required). NOTE: unrelated to Zed's Agent Client Protocol (dsh-acp) — this plugin intercepts tool calls for policy decisions; the Zed ACP wires editors to agents.

Compatibility

Any DeepSeek Harness profile (web or headless). Zero runtime dependencies. Requires an Agentic Control Plane account for the policy console (free tier available). Works across dsh, Claude Code, Codex, Cursor, and other harnesses in one workspace.

Details

Recent updates

0.1.3: pre-call policy intercept (allow/hold/deny) on every tool call; reason shown to model on deny; approval prompts on hold; cloud console logging (tool, input preview, decision, reason, latency, cost); zero npm dependencies; GitHub install supported; note on ACP acronym disambiguation.

FAQ

What is the difference between hold and deny?
Deny immediately blocks the tool call and shows the reason to the model (which can respond or try a different approach). Hold surfaces an interactive approval prompt — a human decides whether to allow or block before the tool runs.
Is this the same as Zed's Agent Client Protocol (ACP)?
No — same acronym, different project. Zed's ACP (@deepseek-ai/dsh-acp) is an editor↔agent protocol for wiring VS Code / Zed into DSH. This plugin (Agentic Control Plane) intercepts tool calls for policy enforcement. The README links to agenticcontrolplane.com/acp-vs-acp for the full comparison.
Does it work with harnesses other than DSH?
Yes — one Agentic Control Plane workspace covers dsh, Claude Code, Codex, Cursor, and other harnesses. Policies configured in the cloud console apply across all of them.

Alternatives

omdsh-dev-dsh-plugin-terminal · PerryLink/dsh-lsp-actions · 030611/qiushi-dsh-evidence-audit

More plugins in Agent Capabilities

Browse more in Agent Capabilities

Guides for Agent Capabilities plugins