lonelymoon87/dsh-guardian
Adds dangerous-operation policy checks, output redaction, and a security-review workflow.
dsh-guardian is runtime dangerous-operation policy, canonical output redaction and a security-review workflow for DeepSeek Harness. A tools/pre-execute waterfall classifies dangerous shell, SQL and structured file-write arguments as deny/ask/unchanged; standard/strict/permissive profiles set approval levels while keeping non-negotiable deny rules; custom regex rules add deployment-specific decisions. Built-in rules deny recursive forced deletion of root/home paths, network-response pipes into shells, raw /dev writes and /etc writes; force pushes, destructive SQL and other recursive forced deletions ask. A tools/post-execute waterfall redacts common credentials (AWS keys, GitHub tokens, …) from canonical JSON results, failures, rendered text and block feedback, scanning consecutive text blocks as one stream so split credentials cannot bypass redaction. /security-review loads a bundled read-only security-review skill; when other policy listeners exist the most restrictive result wins (deny > ask > allow).
Install
dsh plugin --profile web add github:lonelymoon87/dsh-guardian#v0.1.3GitHub Releases per README (EN primary with 简体中文 edition): prebuilt packages ship through GitHub Releases; the unscoped npm name is owned by another publisher so this project is not published there — install from the v0.1.3 release asset or the pinned GitHub route github:lonelymoon87/dsh-guardian#v0.1.3. Tested with DSH 0.1.0-rc.8 and 0.1.1-rc.1 while retaining an rc.6-compatible peer range.
Compatibility
DSH 0.1.0-rc.6 through 0.1.1-rc.1; hooks tools/pre-execute and tools/post-execute; profiles standard/strict/permissive; not a process sandbox or authorization system.
Details
- Repo: lonelymoon87/dsh-guardian
- Category: Development & Runtime
- Stars: 0
- Version: git github:lonelymoon87/dsh-guardian#v0.1.3 (GitHub Releases only)
- Last push: 2026-08-21
- First seen: 2026-08-13
Recent updates
v0.1.3 current (GitHub Releases; tested against DSH 0.1.0-rc.8 / 0.1.1-rc.1 per README).
FAQ
- What does the pre-execute gate do?
- Classifies dangerous shell, SQL and structured file-write arguments as deny, ask or unchanged, with standard/strict/permissive profiles over a fixed deny rule set.
- What gets redacted on output?
- Common credentials — AWS access-key IDs, GitHub tokens and similar — are redacted from canonical JSON results, failures, rendered text and block feedback, scanning consecutive blocks as one stream.
- Is it a sandbox?
- No — the README is explicit that it is not a process sandbox, authorization system, DLP service or substitute for provider policies; it layers policy and redaction on the tool seams.
Alternatives
moon09300731/dsh-approval-gate · Starfie1d1272/dsh-builtin-toggles