Drifter-yh/dsh-tool-policy
Declarative deny-by-default tool policy plugin for DeepSeek Harness
Applies allow / ask / deny rules to tool calls before they execute: a declarative, deny-by-default policy layer for built-in, third-party, and MCP tools that reuses Harness's existing approval and sandbox mechanisms. Typical uses: allow tool namespaces (read_*), require human approval for MCP tools (mcp__*), deny known destructive command patterns before the matched tool body starts, run a deny-by-default allowlist for unattended jobs, keep sensitive argument values out of policy feedback. A matching deny prevents that call from executing; it does not revoke the underlying capability — policy routing and capability sandboxing are complementary layers. Bundle defaults to deny with an empty rule list.
Install
dsh plugin --profile my-profile add github:Drifter-yh/dsh-tool-policy#028e2ce4167a88ad32b0c6eec89ee22072189e71GitHub pinned-commit install per README: dsh plugin --profile my-profile add github:Drifter-yh/dsh-tool-policy#028e2ce4167a88ad32b0c6eec89ee22072189e71 (pin the commit before allowing install-time code execution; the prepare script runs only the standalone tsdown build to create dist/; pnpm 10+ may require an allowBuilds entry). Profile-bundle install also documented: dsh plugin --profile my-profile add dsh-tool-policy — npm package not yet published as of 2026-08-26 (README cites registry, publishConfig public, 404 at verification time), so the github install is the reliable path.
Compatibility
DeepSeek Harness API range >=0.1.0-rc.5 <0.2.0; Cordis >=4.0.1 <5. Uses documented Context, tools service, and tools/pre-execute event only.
Details
- Repo: Drifter-yh/dsh-tool-policy
- Category: Other
- Stars: 3
- Version: GitHub source v0.2.0, pinned commit per README (npm not yet published)
- Last push: 2026-09-20
- First seen: 2026-08-13
Recent updates
v0.2.0: allow/ask/deny rules; deny-by-default; per-call policy layer; MCP namespace support (mcp__*); sensitive-argument redaction in feedback.
FAQ
- Is this a sandbox?
- No — it is a per-call policy layer. Harness sandboxing enforces capabilities; this plugin decides whether a specific known tool call is allowed, denied, or escalated to human approval.
- How do MCP tools match?
- DSH exposes MCP tools as mcp<serverName><rawName>, so an mcp__* rule covers the complete MCP namespace.
- What is the default?
- Deny with an empty rule list — configure the inserted tool-policy row in the profile layer before running tools.
Alternatives
omdsh-dev/dsh-security-audit · jkrandom-sudo/dsh-plugin-audit · PerryLink/dsh-doublecheck