Back to directory

dsh-permission-rules

Curated pickMaintenance: Active

perrylink/dsh-permission-rules

Claude Code-style declarative permission rules for DeepSeek Harness: ordered allow/deny/ask rules with tool-name, argument (glob/regex), and workspace-path matching on the tools/pre-execute waterfall, session-log audit, and HMR reload.

View on GitHubHomepage
$ dsh plugin --profile web add "github:PerryLink/dsh-permission-rules#main"

117

stars

3

forks

TypeScript

Language

Apache-2.0

License

2026-08-13

Created

2026-09-25

Last push

Apache-2.0 dsh plugin that gates every DeepSeek Harness tool call with ordered allow/deny/ask rules, audits decisions to the session log, and enforces a process-level network policy — all in plain YAML, with hot reload.

DSH integration

Native runtime

Author-claimed

Safety audit

Unaudited

Last verified

2026-08-30

License

Apache-2.0

01What can it help you accomplish?

  • Gate every DeepSeek Harness tool call with an ordered allow / deny / ask permission policy written in plain YAML

    A deterministic, instant, auditable rule layer on the `tools/pre-execute` waterfall, with every hit and passthrough audit-logged as a `permissionRules/decision` session event

    DeepSeek Harness (dsh) operators who want Claude Code-style declarative safety guardrails without re-implementing the approval flow

  • Control shell subprocess network egress with a process-level network policy

    A built-in local HTTP/CONNECT proxy plus ordered network rules (deny-all / whitelist / allow-all / auto) that decide every outbound connection

    Teams that need Codex-style egress control and network-policy auditing inside DeepSeek Harness

02How to install into DeepSeek Harness

Prerequisites

  • DeepSeek Harness `0.1.1-rc.2` (or compatible) installed as the agent runtime
  • Node `^22.19.0 || >=24.0.0`

Installation steps

  1. 01

    Install the bundle: `dsh plugin --profile web add "github:PerryLink/dsh-permission-rules#main"`

    $ dsh plugin --profile web add "github:PerryLink/dsh-permission-rules#main"

  2. 02

    Or from npm (published releases): `dsh plugin --profile web add dsh-permission-rules`

    $ dsh plugin --profile web add dsh-permission-rules

  3. 03

    Restart and verify the row: `dsh --profile web --dump-config | grep -A4 'id: permission-rules'`

    $ dsh --profile web --dump-config | grep -A4 'id: permission-rules'

Verify the integration

  • After restart, `dsh --profile web --dump-config | grep -A4 'id: permission-rules'` prints the permission-rules row
  • Run `/rules` to list the active rules, their source files, and any last-reload error

Rollback

  • Uninstall with `dsh plugin --profile web remove dsh-permission-rules`
  • Set `enforce: false` for a dry-run rollback: deny/ask hits are audit-logged with a `dryRun` marker and every call passes through

03DSH integration and capability boundaries

DSH integrationNative runtime

Native dsh plugin — installs via `dsh plugin --profile web add`, then hooks the `tools/pre-execute` waterfall as a first-match allow/deny/ask listener.

  • Ordered allow / deny / ask rules on tools/pre-execute

    tool calls on the `tools/pre-execute` waterfall→first-match allow/deny/ask decision; `deny` makes the rule `reason` the model-visible error; `ask` rides the official approval seam

    Every hit and passthrough is audit-logged as a `permissionRules/decision` session event (log-only — nothing extra is injected into the model context)
  • Rich rule matching

    tool-name globs, agent-identity selectors, argument key/value globs or regexes, workspace-relative path globs, `when` host conditions, shell command decomposition→token-precise match across multiple dimensions

  • Process-level network policy + local proxy

    shell subprocess outbound connections→ordered network rules / deny-all / whitelist / allow-all / auto modes; denied connections audit to `permissionRules/network`

    Proxy environment variables are injected for subprocesses (`network.injectEnv`)A built-in local HTTP/CONNECT proxy binds `127.0.0.1`
  • Hot reload & fail-loud loading

    rule file edits→Chokidar watch with debounce reload; a broken edit keeps the previous rules, never crashes

    Invalid YAML, unknown actions/fields, bad globs/regexes, backtracking-prone patterns, or more than `maxRules` rules fail the load loudly

04Who is it for? When not to use it?

Good for

  • DeepSeek Harness (dsh) operators who want Claude Code-style declarative safety guardrails without re-implementing the approval flow
  • Teams that need Codex-style egress control and network-policy auditing inside DeepSeek Harness

Not for

  • On pre-marker harness hosts (the `0.1.0-rc.1`–`rc.7` and `0.1.1-rc.1`–`rc.7` lines) the `ignorable` marker is silently dropped and the runtime disables session-log audit with a one-time warning; set `allowUnmarkedAudit: true` to opt back in.

05Compatibility, maintenance and safety notes

  • On pre-marker harness hosts (the `0.1.0-rc.1`–`rc.7` and `0.1.1-rc.1`–`rc.7` lines) the `ignorable` marker is silently dropped and the runtime disables session-log audit with a one-time warning; set `allowUnmarkedAudit: true` to opt back in.
  • Path candidates are heuristic: only the documented argument keys feed path matching, and workspace-relative matching is ASCII-case-insensitive only when `caseInsensitivePaths` is on. Globs are a conservative subset with no brace expansion.
  • `paths` candidates come only from a documented set of argument keys (depth-capped) and only workspace-relative paths match. OS-level sandbox policy belongs to the sandbox seam, not this plugin.
2026-08-132026-08-29v0.6.1

Apache-2.0 · actively maintained (latest release v0.6.1, 2026-08-27)

06Frequently asked questions

How do I install dsh-permission-rules with DeepSeek Harness?

Run `dsh plugin --profile web add dsh-permission-rules` for the published release, or `dsh plugin --profile web add "github:PerryLink/dsh-permission-rules#main"` for the latest main. Then restart and verify with `dsh --profile web --dump-config | grep -A4 'id: permission-rules'`.

What are the prerequisites and compatibility?

DeepSeek Harness `0.1.1-rc.2` and Node `^22.19.0 || >=24.0.0`. It runs on all platforms (host + web settings client) and works with any model, since deny/ask reasons surface through tool results.

How does it connect to / integrate with DeepSeek Harness?

It is a native dsh plugin: it registers a `tools/pre-execute` listener so every tool call passes through its ordered allow/deny/ask rules first. `ask` decisions ride the official approval seam — mount `dsh-auto-review` for a second-model answerer, or a human answers — so nothing in the approval flow is re-implemented.

How is it different from Claude Code's permissions or a sandbox?

It is Claude Code-style but runs inside DeepSeek Harness as a policy layer, not a kernel. `paths` candidates come only from a documented set of argument keys and only workspace-relative paths match; OS-level sandbox policy stays with the sandbox seam. It also adds a process-level network policy with a built-in local proxy, and `ask` reuses the harness's own approval flow rather than inventing one.

Troubleshooting: audit log missing or rules not loading?

On pre-marker harness hosts (the `0.1.0-rc.1`–`rc.7` and `0.1.1-rc.1`–`rc.7` lines) the `ignorable` marker is dropped and session-log audit is disabled with a one-time warning; set `allowUnmarkedAudit: true` to opt back in. Broken YAML, unknown fields, bad globs/regexes, or more than `maxRules` keep the previous rules (hot reload) or fail the load loudly — run `/rules` to see any last-reload error.

08Data and sources

  • Author-claimedgithub.combb7735cddce9…

    Claude Code-style declarative permission rules for DeepSeek Harness.

  • Author-claimedgithub.combb7735cddce9…

    `dsh-permission-rules` puts an ordered **`allow` / `deny` / `ask`** rule list in front of every tool call on the `tools/…

This page is generated from the project’s public documentation, repository metadata and a structured parse of DSH Plugins; last verified on 2026-08-30. Found an error? Submit a correction.

🏆

Best DeepSeek Harness Plugins

Twelve plugins worth installing first — picked from the whole catalog, across every category.

DSH Plugins is an independent community directory of DeepSeek Harness plugins. Not affiliated with or endorsed by DeepSeek. Third-party plugins are not security-audited — review the source before installing.

New DeepSeek Harness plugins, weekly. No spam.