Apache-2.0 の dsh プラグイン。DeepSeek Harness のすべてのツール呼び出しを順序付き allow/deny/ask ルールで判定し、決定をセッションログに記録、プロセスレベルのネットワークポリシーを強制。すべて YAML で記述、ホットリロード対応。
DSH 統合
ネイティブ実行
作者による申告
安全性監査
未監査
最終検証日
2026-08-30
ライセンス
Apache-2.0
01どんなタスクに使えるのか?
Gate every DeepSeek Harness tool call with an ordered allow / deny / ask permission policy written in plain YAML
A deterministic, instant, auditable rule layer on the `tools/pre-execute` waterfall, with every hit and passthrough audit-logged as a `permissionRules/decision` session event
DeepSeek Harness (dsh) operators who want Claude Code-style declarative safety guardrails without re-implementing the approval flow
Control shell subprocess network egress with a process-level network policy
A built-in local HTTP/CONNECT proxy plus ordered network rules (deny-all / whitelist / allow-all / auto) that decide every outbound connection
Teams that need Codex-style egress control and network-policy auditing inside DeepSeek Harness
02DeepSeek Harness への導入方法
前提条件
- DeepSeek Harness `0.1.1-rc.2` (or compatible) installed as the agent runtime
- Node `^22.19.0 || >=24.0.0`
インストール手順
- 01
Install the bundle: `dsh plugin --profile web add "github:PerryLink/dsh-permission-rules#main"`
$ dsh plugin --profile web add "github:PerryLink/dsh-permission-rules#main"
- 02
Or from npm (published releases): `dsh plugin --profile web add dsh-permission-rules`
$ dsh plugin --profile web add dsh-permission-rules
- 03
Restart and verify the row: `dsh --profile web --dump-config | grep -A4 'id: permission-rules'`
$ dsh --profile web --dump-config | grep -A4 'id: permission-rules'
導入成功の確認
- After restart, `dsh --profile web --dump-config | grep -A4 'id: permission-rules'` prints the permission-rules row
- Run `/rules` to list the active rules, their source files, and any last-reload error
ロールバック
- Uninstall with `dsh plugin --profile web remove dsh-permission-rules`
- Set `enforce: false` for a dry-run rollback: deny/ask hits are audit-logged with a `dryRun` marker and every call passes through
03DSH 統合と能力の範囲
Native dsh plugin — installs via `dsh plugin --profile web add`, then hooks the `tools/pre-execute` waterfall as a first-match allow/deny/ask listener.
Ordered allow / deny / ask rules on tools/pre-execute
tool calls on the `tools/pre-execute` waterfall→first-match allow/deny/ask decision; `deny` makes the rule `reason` the model-visible error; `ask` rides the official approval seam
Every hit and passthrough is audit-logged as a `permissionRules/decision` session event (log-only — nothing extra is injected into the model context)Rich rule matching
tool-name globs, agent-identity selectors, argument key/value globs or regexes, workspace-relative path globs, `when` host conditions, shell command decomposition→token-precise match across multiple dimensions
Process-level network policy + local proxy
shell subprocess outbound connections→ordered network rules / deny-all / whitelist / allow-all / auto modes; denied connections audit to `permissionRules/network`
Proxy environment variables are injected for subprocesses (`network.injectEnv`)A built-in local HTTP/CONNECT proxy binds `127.0.0.1`Hot reload & fail-loud loading
rule file edits→Chokidar watch with debounce reload; a broken edit keeps the previous rules, never crashes
Invalid YAML, unknown actions/fields, bad globs/regexes, backtracking-prone patterns, or more than `maxRules` rules fail the load loudly
04誰に向いているのか?使うべきでない場面は?
向いている用途
- DeepSeek Harness (dsh) operators who want Claude Code-style declarative safety guardrails without re-implementing the approval flow
- Teams that need Codex-style egress control and network-policy auditing inside DeepSeek Harness
不向きな用途
- On pre-marker harness hosts (the `0.1.0-rc.1`–`rc.7` and `0.1.1-rc.1`–`rc.7` lines) the `ignorable` marker is silently dropped and the runtime disables session-log audit with a one-time warning; set `allowUnmarkedAudit: true` to opt back in.
05互換性・メンテナンス・セキュリティ上の注意
- On pre-marker harness hosts (the `0.1.0-rc.1`–`rc.7` and `0.1.1-rc.1`–`rc.7` lines) the `ignorable` marker is silently dropped and the runtime disables session-log audit with a one-time warning; set `allowUnmarkedAudit: true` to opt back in.
- Path candidates are heuristic: only the documented argument keys feed path matching, and workspace-relative matching is ASCII-case-insensitive only when `caseInsensitivePaths` is on. Globs are a conservative subset with no brace expansion.
- `paths` candidates come only from a documented set of argument keys (depth-capped) and only workspace-relative paths match. OS-level sandbox policy belongs to the sandbox seam, not this plugin.
Apache-2.0 · actively maintained (latest release v0.6.1, 2026-08-27)
06よくある質問
DeepSeek Harness に dsh-permission-rules をインストールするには?
公開リリースは `dsh plugin --profile web add dsh-permission-rules`、最新の main は `dsh plugin --profile web add "github:PerryLink/dsh-permission-rules#main"` を実行します。その後再起動し、`dsh --profile web --dump-config | grep -A4 'id: permission-rules'` で確認します。
前提条件と互換性は?
DeepSeek Harness `0.1.1-rc.2` と Node `^22.19.0 || >=24.0.0` が必要です。すべてのプラットフォーム(ホスト+Web 設定クライアント)で動作し、任意のモデルに対応します(deny/ask の理由はツール結果経由で伝わるため)。
DeepSeek Harness とどう接続・統合されるのですか?
ネイティブな dsh プラグインです。`tools/pre-execute` リスナーを登録するため、すべてのツール呼び出しが最初に順序付き allow/deny/ask ルールを通ります。`ask` の判定は公式の承認シームを利用します(`dsh-auto-review` をマウントすれば第2モデルが回答、あるいは人間が回答)——承認フローを再実装することはありません。
Claude Code の権限やサンドボックスとどう違いますか?
Claude Code 風ですが、DeepSeek Harness 内部のポリシー層として動作し、カーネルではありません。`paths` の候補はドキュメント化された引数キーのみから来て、ワークスペース相対パスだけにマッチします。OS 級のサンドボックスポリシーはサンドボックスシームの責務です。さらにプロセスレベルのネットワークポリシーと組み込みローカルプロキシを備え、`ask` は harness 自身の承認フローを再利用します。
トラブルシューティング:監査ログが消える、ルールが読み込まれない?
pre-marker の harness ホスト(`0.1.0-rc.1`–`rc.7` と `0.1.1-rc.1`–`rc.7` 系列)では `ignorable` マーカーが静かに破棄され、セッションログ監査が一度だけ警告付きで無効になります。`allowUnmarkedAudit: true` を設定すれば再有効化できます。壊れた YAML、未知のフィールド、不正な glob/regex、あるいは `maxRules` 超過は、ホットリロードで以前のルールを維持するか、ロード時に明示的に失敗します。`/rules` を実行すれば直近のリロードエラーが確認できます。
07関連する DSH ワークフロー
cc-safety-net
by kenryu42
AIコーディングエージェント向けの実行前セキュリティガード。Gitやファイル操作の破壊的コマンド、機密ファイルへのアクセスをツール実行前に検知してブロックします。
tencentmeeting-cli
by tencentcloud
テンセント会議(Tencent Meeting)の CLI ツール。オープンプラットフォームの OAuth2 認証を利用し、会議管理、録画管理、参加者レポートなどに対応
dsh-auto-review
by perrylink
DeepSeek Harness 承認リクエスト向け第 2 モデル AI 自動レビュー:読み取り専用レビューサブエージェントが構造化 allow/deny 判定を返す。デフォルトフェイルクローズ、セッションログで完全監査可能
jevcore
by perrylink
DeepSeek Harness、Model Context Protocol、Nodeで利用できるTypeSafe Jevコア。文章ではなく型付きの判断を扱い、デフォルトではオフラインで動作します。
08データと出典
Claude Code-style declarative permission rules for DeepSeek Harness.
`dsh-permission-rules` puts an ordered **`allow` / `deny` / `ask`** rule list in front of every tool call on the `tools/…
このページは、プロジェクトの公開ドキュメント、リポジトリのメタデータ、および DSH Plugins の構造化解析に基づいて生成されています。最終検証日:2026-08-30。誤りを見つけた場合は、修正を送信してください。
dsh プラグイン おすすめ
最初に入れたい 12 のプラグイン。全カタログ・全カテゴリから厳選しました。
