Back to directory

dsh-plugin-guard

Curated pickMaintenance: Active

lxzy-7/dsh-plugin-guard

DSH 防护/校验插件,对运行期行为做守卫与限制。

View on GitHub
$ dsh plugin add dsh-plugin-guard

42

stars

3

forks

JavaScript

Language

MIT

License

2026-08-16

Created

2026-08-18

Last push

A DeepSeek Harness plugin that makes plugin installs safe: pre-install snapshots, guarded `dsh web` boot with automatic rollback, and incident reports that auto-trigger agent analysis. MIT licensed, released as v0.3.2.

DSH integration

Native runtime

Author-claimed

Safety audit

Unaudited

Last verified

2026-09-04

License

MIT

01What can it help you accomplish?

  • Install any DeepSeek Harness plugin without risking a broken, unbootable app

    An automatic snapshot of 5 config files is taken before the install, so a bad plugin can never leave the app unable to boot with no recovery point

    DeepSeek Harness (dsh) users who install third-party plugins and want a safe install path

  • Recover automatically when a newly added plugin breaks dsh web boot

    On boot failure the guard rolls back to the last good snapshot, retries once, writes an incident report, and sets a pending marker so the next session's agent analyzes the failure

    Operators and maintainers running `dsh web` who need hands-off recovery and root-cause analysis

02How to install into DeepSeek Harness

Not specified by the author

03DSH integration and capability boundaries

DSH integrationNative runtime

Installs as a dsh plugin and hooks dsh's `tools.guard` to snapshot 5 config files before any install, then guards `dsh web` boot with automatic rollback and incident reports.

  • Pre-install snapshot (tools.guard hook)

    any plugin install, via any method→a snapshot of 5 config files (`package.json`, `pnpm-lock.yaml`, `pnpm-workspace.yaml`, `cordis.yml`, `cordis.patch.yml`) taken before the install

    copies 5 config files to a snapshot; does not run any plugin or evaluate behavior
  • Guarded boot with automatic rollback

    `dsh web` boot with the just-added plugin loaded→health-checks HTTP `/`; on failure kills the process tree, rolls back to the last good snapshot, and retries once

    starts and may kill the whole `dsh web` process tree during the guarded boot check
  • Incident report and agent analysis trigger

    a failed boot detected by the guard→writes an incident report and sets a pending marker; the next session's prompt tells the agent to analyze it, and `incident_resolved` clears the marker after a fix

    sets a pending marker that changes the next session's prompt until `incident_resolved` is called

04Who is it for? When not to use it?

Good for

  • DeepSeek Harness (dsh) users who install third-party plugins and want a safe install path
  • Operators and maintainers running `dsh web` who need hands-off recovery and root-cause analysis

Not for

  • The guard does not statically inspect plugin code and does not test a plugin in isolation; detection happens at boot level by running the harness with the plugin loaded, so it cannot catch bugs that do not break boot.
  • On a boot failure the guard kills the process tree, rolls back to the last good snapshot and retries once, then writes an incident report and sets a pending marker — this changes the next session's prompt.

05Compatibility, maintenance and safety notes

  • The guard does not statically inspect plugin code and does not test a plugin in isolation; detection happens at boot level by running the harness with the plugin loaded, so it cannot catch bugs that do not break boot.
  • Snapshots are pure file copies of 5 config files; no plugin is run and no behavior is evaluated during a snapshot, so secrets or runtime state outside those files are not captured.
  • On a boot failure the guard kills the process tree, rolls back to the last good snapshot and retries once, then writes an incident report and sets a pending marker — this changes the next session's prompt.
2026-08-162026-08-18v0.3.2

MIT · release v0.3.2 (2026-08-18) · curated plugin

06Frequently asked questions

How does dsh-plugin-guard protect my DeepSeek Harness install?

It hooks dsh's `tools.guard` to take an automatic snapshot of 5 config files before any plugin install, and runs a guarded `dsh web` boot that rolls back and retries once if a new plugin breaks startup.

Does it inspect or run my plugin to find problems?

No. The README states the guard does not statically inspect plugin code and does not test a plugin in isolation. Detection runs at boot level by starting `dsh web` with your plugin loaded and health-checking HTTP `/`.

What happens when a plugin breaks boot?

The guard automatically kills the process tree, rolls back to the last good snapshot, and retries once. It then writes an incident report and sets a pending marker so the next session's prompt tells the agent to analyze the failure.

How do I clear the incident marker after fixing?

After you fix the problem, call `incident_resolved` to clear the pending marker. Until then, the next session's prompt keeps asking the agent to analyze the incident.

What files are included in a snapshot?

A snapshot is a pure file copy of 5 config files: `package.json`, `pnpm-lock.yaml`, `pnpm-workspace.yaml`, `cordis.yml`, and `cordis.patch.yml`. No plugin is run and no behavior is evaluated.

08Data and sources

  • Author-claimedgithub.comc95036f33a2a…

    Install safety net for [DeepSeek Harness](https://github.com/deepseek-ai/dsh): pre-install snapshots, one-click / automa…

  • Author-claimedgithub.comc95036f33a2a…

    tools.guard hook: automatic snapshot BEFORE the install (in-process)

This page is generated from the project’s public documentation, repository metadata and a structured parse of DSH Plugins; last verified on 2026-09-04. Found an error? Submit a correction.

🏆

Best DeepSeek Harness Plugins

Twelve plugins worth installing first — picked from the whole catalog, across every category.

DSH Plugins is an independent community directory of DeepSeek Harness plugins. Not affiliated with or endorsed by DeepSeek. Third-party plugins are not security-audited — review the source before installing.

New DeepSeek Harness plugins, weekly. No spam.