
dsh-permission-rules
Claude Code-style declarative permission rules for DeepSeek Harness: ordered allow/deny/ask rules with tool-name, argument (glob/regex), and workspace-path matching on the tools/pre-execute waterfall, session-log audit, and HMR reload.
PluginSecurityDeveloperAI ModelsStorageTerminal / ShellFile
Verification
L2 · Structured
Security
Pending
Health
Active
Trust
Bronze
What it doesAI
Declarative allow/deny/ask permission rules for DeepSeek Harness tools with path/argument matching, audit logging, and hot reload.
- Ordered allow/deny/ask rules per tool
- Glob/regex matching on tool arguments
- Workspace-path matching, session audit logs, HMR
AI-generated from the repo README — for reference only.
Installation
dsh plugin --profile web add dsh-permission-rulesInstall method: npm · not yet tested in container (L3+)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
Requirements
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
Security Report
Automated scan, not manual review.
• Dependency vulnerabilities: — (pending)
• Suspicious permissions: — (pending)
• Hardcoded secrets: — (pending)
• Supply chain risks: — (pending)
⚠ Security audit scheduled — results will appear here after the next scan.
Activity
Last commit 2026-08-14 · activity: active
6 mo