pandashere/dsh-self-control-guard
Self-control guard plugin for DeepSeek Harness host exit and restart workflows.
A self-control guard for the DeepSeek Harness host process: intercepts high-confidence host-kill attempts from the bash tool (canonical kill <host-pid>, kill $PPID, pkill dsh, killall dsh forms) with a monotonic hard denial that no pre-execute listener can force-allow, teaches the model the controlled exit tool (dsh_self_exit always; dsh_self_restart only when restartEnabled: true), and leaves an audit trail. The controlled tools are registered up front but hidden from the model-facing tool list.
Install
npm install && npm run check && npm pack && dsh plugin --profile web add <tarball>The plugin ships as a standalone bundle installable into any DSH profile. Build, validate, and pack it from the plugin directory: npm install, npm run check, npm pack, then install the generated tarball into a DSH profile (dsh plugin --profile web add ./self-control-guard-<version>.tgz) and restart dsh web. Installing the source directory as a link is not supported by the README. Requirements: Node.js 22 or newer and @deepseek-ai/dsh@0.1.0-rc.6.
Compatibility
DeepSeek Harness 0.1.0-rc.6; Node.js 22+. Host-process guard plugin — works with the bash tool's pre-execute listeners.
Details
- Repo: pandashere/dsh-self-control-guard
- Category: Other
- Stars: 5
- Version: GitHub source tarball (standalone bundle; no npm package)
- Last push: 2026-08-13
- First seen: 2026-08-13
Recent updates
Interception + teaching + audit trail; hidden controlled tools (not enumerable by the model but callable by name); monotonic hard denial.
FAQ
- What does the guard block?
- High-confidence attempts to terminate the host from the bash tool: canonical kill <host-pid>, kill $PPID, pkill dsh, and killall dsh forms. Denial is monotonic and hard — no pre-execute listener can force-allow it.
- What does it teach the model instead?
- The controlled exit tool dsh_self_exit (always) and dsh_self_restart (only when restartEnabled is true). A pinned guidance message is injected right after an interception.
- Can the model discover the controlled tools?
- No — they are registered up front but hidden (hidden: true keeps them out of schemas()), so an unassisted model cannot discover them by enumeration, yet they stay callable by name.
Alternatives
Jiao-XXX/dsh-auto-approve · Hanihahaha/dsh-auto-approve · timeance/dsh-approve-for-me