JohnXu22786/safety-net
Destructive-command interception gate for dsh: parses shell semantics, judges risk against 41 built-in rules, and holds irreversible rm -rf, git reset --hard, and git push --force style commands at a confirmation gate.
Barricade — a destructive-command interception gate. It parses command semantics before rm -rf, git reset --hard, git push --force and similar commands actually land and requires human confirmation. A POSIX lexer understands quotes, escapes, heredocs, command substitution and pipeline chains, and 41 built-in rules cover git, rm, dd/mkfs/shred/chmod/chown, find -delete, curl|sh, interpreter one-liners and fork bombs — including irreversible actions a sandbox can't stop.
Install
dsh plugin --profile demo add github:JohnXu22786/safety-netREADME-documented install into the demo profile from GitHub (replace demo with your profile). The bundle is named dsh-barricade, so a local form is dsh plugin --profile web add ../dsh-barricade (or ... add dsh-barricade when published). Cordis inserts the barricade row via cordis.patch.yml.
Compatibility
Zero runtime dependencies (pure Node.js ESM); works with any harness that hands the shell to an agent. It does not sandbox or limit capabilities — it only gates irreversible operations.
Details
- Repo: JohnXu22786/safety-net
- Category: Tools & Capabilities
- Stars: 1
- Version: GitHub main (README-documented)
- Last push: 2026-08-16
- First seen: 2026-08-16
Recent updates
Runs as a plugin listening to the tools/pre-execute waterfall, throwing BarricadeBlocked when a block verdict is produced; mode can be deny (default) or ask (human confirmation via ctx.approval).
FAQ
- How do I install safety-net (Barricade)?
- Run: dsh plugin --profile demo add github:JohnXu22786/safety-net (use your own profile name), or the local bundle form; Cordis inserts the barricade row via cordis.patch.yml.
- How does it decide what to block?
- It parses command semantics with its own POSIX lexer (quotes, escapes, heredocs, $(...), sub-shells, pipelines) rather than string matching, then applies 41 built-in per-command rules.
- Does it limit what the agent can do?
- No. It does not sandbox and does not limit capabilities — it only holds irreversible operations at a confirmation gate, in deny or ask mode.
Alternatives
zhaoolee/notes · Vladimir-Human/ru-marketplace-mcp#dsh · DDDMUC/dsh-free-search