Apache-2.0 dsh plugin that gates every DeepSeek Harness tool call with ordered allow/deny/ask rules, audits decisions to the session log, and enforces a process-level network policy — all in plain YAML, with hot reload.
DSH integration
Native runtime
Author-claimed
Safety audit
Unaudited
Last verified
2026-08-30
License
Apache-2.0
01What can it help you accomplish?
Gate every DeepSeek Harness tool call with an ordered allow / deny / ask permission policy written in plain YAML
A deterministic, instant, auditable rule layer on the `tools/pre-execute` waterfall, with every hit and passthrough audit-logged as a `permissionRules/decision` session event
DeepSeek Harness (dsh) operators who want Claude Code-style declarative safety guardrails without re-implementing the approval flow
Control shell subprocess network egress with a process-level network policy
A built-in local HTTP/CONNECT proxy plus ordered network rules (deny-all / whitelist / allow-all / auto) that decide every outbound connection
Teams that need Codex-style egress control and network-policy auditing inside DeepSeek Harness
02How to install into DeepSeek Harness
Prerequisites
- DeepSeek Harness `0.1.1-rc.2` (or compatible) installed as the agent runtime
- Node `^22.19.0 || >=24.0.0`
Installation steps
- 01
Install the bundle: `dsh plugin --profile web add "github:PerryLink/dsh-permission-rules#main"`
$ dsh plugin --profile web add "github:PerryLink/dsh-permission-rules#main"
- 02
Or from npm (published releases): `dsh plugin --profile web add dsh-permission-rules`
$ dsh plugin --profile web add dsh-permission-rules
- 03
Restart and verify the row: `dsh --profile web --dump-config | grep -A4 'id: permission-rules'`
$ dsh --profile web --dump-config | grep -A4 'id: permission-rules'
Verify the integration
- After restart, `dsh --profile web --dump-config | grep -A4 'id: permission-rules'` prints the permission-rules row
- Run `/rules` to list the active rules, their source files, and any last-reload error
Rollback
- Uninstall with `dsh plugin --profile web remove dsh-permission-rules`
- Set `enforce: false` for a dry-run rollback: deny/ask hits are audit-logged with a `dryRun` marker and every call passes through
03DSH integration and capability boundaries
Native dsh plugin — installs via `dsh plugin --profile web add`, then hooks the `tools/pre-execute` waterfall as a first-match allow/deny/ask listener.
Ordered allow / deny / ask rules on tools/pre-execute
tool calls on the `tools/pre-execute` waterfall→first-match allow/deny/ask decision; `deny` makes the rule `reason` the model-visible error; `ask` rides the official approval seam
Every hit and passthrough is audit-logged as a `permissionRules/decision` session event (log-only — nothing extra is injected into the model context)Rich rule matching
tool-name globs, agent-identity selectors, argument key/value globs or regexes, workspace-relative path globs, `when` host conditions, shell command decomposition→token-precise match across multiple dimensions
Process-level network policy + local proxy
shell subprocess outbound connections→ordered network rules / deny-all / whitelist / allow-all / auto modes; denied connections audit to `permissionRules/network`
Proxy environment variables are injected for subprocesses (`network.injectEnv`)A built-in local HTTP/CONNECT proxy binds `127.0.0.1`Hot reload & fail-loud loading
rule file edits→Chokidar watch with debounce reload; a broken edit keeps the previous rules, never crashes
Invalid YAML, unknown actions/fields, bad globs/regexes, backtracking-prone patterns, or more than `maxRules` rules fail the load loudly
04Who is it for? When not to use it?
Good for
- DeepSeek Harness (dsh) operators who want Claude Code-style declarative safety guardrails without re-implementing the approval flow
- Teams that need Codex-style egress control and network-policy auditing inside DeepSeek Harness
Not for
- On pre-marker harness hosts (the `0.1.0-rc.1`–`rc.7` and `0.1.1-rc.1`–`rc.7` lines) the `ignorable` marker is silently dropped and the runtime disables session-log audit with a one-time warning; set `allowUnmarkedAudit: true` to opt back in.
05Compatibility, maintenance and safety notes
- On pre-marker harness hosts (the `0.1.0-rc.1`–`rc.7` and `0.1.1-rc.1`–`rc.7` lines) the `ignorable` marker is silently dropped and the runtime disables session-log audit with a one-time warning; set `allowUnmarkedAudit: true` to opt back in.
- Path candidates are heuristic: only the documented argument keys feed path matching, and workspace-relative matching is ASCII-case-insensitive only when `caseInsensitivePaths` is on. Globs are a conservative subset with no brace expansion.
- `paths` candidates come only from a documented set of argument keys (depth-capped) and only workspace-relative paths match. OS-level sandbox policy belongs to the sandbox seam, not this plugin.
Apache-2.0 · actively maintained (latest release v0.6.1, 2026-08-27)
06Frequently asked questions
How do I install dsh-permission-rules with DeepSeek Harness?
Run `dsh plugin --profile web add dsh-permission-rules` for the published release, or `dsh plugin --profile web add "github:PerryLink/dsh-permission-rules#main"` for the latest main. Then restart and verify with `dsh --profile web --dump-config | grep -A4 'id: permission-rules'`.
What are the prerequisites and compatibility?
DeepSeek Harness `0.1.1-rc.2` and Node `^22.19.0 || >=24.0.0`. It runs on all platforms (host + web settings client) and works with any model, since deny/ask reasons surface through tool results.
How does it connect to / integrate with DeepSeek Harness?
It is a native dsh plugin: it registers a `tools/pre-execute` listener so every tool call passes through its ordered allow/deny/ask rules first. `ask` decisions ride the official approval seam — mount `dsh-auto-review` for a second-model answerer, or a human answers — so nothing in the approval flow is re-implemented.
How is it different from Claude Code's permissions or a sandbox?
It is Claude Code-style but runs inside DeepSeek Harness as a policy layer, not a kernel. `paths` candidates come only from a documented set of argument keys and only workspace-relative paths match; OS-level sandbox policy stays with the sandbox seam. It also adds a process-level network policy with a built-in local proxy, and `ask` reuses the harness's own approval flow rather than inventing one.
Troubleshooting: audit log missing or rules not loading?
On pre-marker harness hosts (the `0.1.0-rc.1`–`rc.7` and `0.1.1-rc.1`–`rc.7` lines) the `ignorable` marker is dropped and session-log audit is disabled with a one-time warning; set `allowUnmarkedAudit: true` to opt back in. Broken YAML, unknown fields, bad globs/regexes, or more than `maxRules` keep the previous rules (hot reload) or fail the load loudly — run `/rules` to see any last-reload error.
07Related DSH workflows
cc-safety-net
by kenryu42
A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs. Supports Amp Code, Antigravity CLI, Claude Code, Codex, Cursor, DeepSeek Harness, Gemini CLI, GitHub Copilot CLI, Grok Build, Hermes Agent, Kimi Code, OpenClaw, OpenCode, and Pi.
tencentmeeting-cli
by tencentcloud
Tencent Meeting command-line tool with OAuth2 authorization for meeting, recording and attendance-report management.
dsh-auto-review
by perrylink
Second-model AI auto-review for DeepSeek Harness approval requests: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default, fully auditable from the session log (approval/asked -> autoReview/verdict -> approval/decided).
jevcore
by perrylink
TypeSafe Jev for DeepSeek Harness, the Model Context Protocol, and plain Node: typed judgments instead of prose, offline by default.
08Data and sources
Claude Code-style declarative permission rules for DeepSeek Harness.
`dsh-permission-rules` puts an ordered **`allow` / `deny` / `ask`** rule list in front of every tool call on the `tools/…
This page is generated from the project’s public documentation, repository metadata and a structured parse of DSH Plugins; last verified on 2026-08-30. Found an error? Submit a correction.
Best DeepSeek Harness Plugins
Twelve plugins worth installing first — picked from the whole catalog, across every category.
