dsh-plugin-tool-guard avatar

dsh-plugin-tool-guard

DeepSeek Harness 工具调用安全守卫(防火墙)插件:危险命令拦截、路径白名单、敏感文件黑名单、人工审批与审计

PluginSecurityTerminal / ShellFile
Verification
L5 · Run tested
Passed
Risk
Medium
Health
Active
Trust
Silver

What it doesAI

Security guard plugin for DeepSeek Harness that blocks dangerous tool calls, protects file paths, and adds human approval and audit.

  • Blocks dangerous commands via blacklist (rm -rf, mkfs, dd)
  • Path whitelist and sensitive file blacklist enforcement
  • Human approval for risky operations with full audit trail

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add dsh-plugin-tool-guard@1.0.0

security scan passed · npm package v1.0.0

Install method: npm · sandbox install verified (L5)

Verification & Compatibility

Grouped by plugin version: each card lists the dsh versions actually tested against that artifact version and their install verdicts (L5 wins). Untested combinations are omitted — absence means untested, never assumed compatible. L1–L3 are a plugin-level static archive (independent of the dsh version — the same verdict on every dsh row): they sit in each row's level grid next to L4/L5, marked "static", while their evidence is stored once per plugin inside that row's "checks & evidence" instead of being duplicated per version.

External credentials (plugin-level): none detected

Install compatibility matrix (rows = plugin versions〔latest 5〕, columns = dsh versions〔latest 5〕)
At-a-glance → evidence in the cards below
plugin \ dshdsh 0.1.3-alpha.2
current
1.0.0

✓ = L5 runtime verified · ◐ = L4 testing (install passed · L5 runtime pending) · ○ not a dsh plugin (nothing mounts) · ✗ failed · · untested (never assumed compatible)

Install compatibility (by plugin version, dsh versions within)
Legend:✓ L5 runtime verified◐ L4 testing · install passed○ no plugin features✗ failed
1.0.0npm✓ 1 runtime-verified2026-09-09

dsh-plugin-tool-guard

dsh 0.1.3-alpha.2current2026-09-09L5 · runtime verified
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.3-alpha.2
  • • Plugin artifact: npm · dsh-plugin-tool-guard@1.0.0
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Passed
Install + runtime smoke verified in the dsh sandbox — installs and runs
L5 · runtime verified · valid for dsh 0.1.3-alpha.2

ID: dsh-plugin-tool-guard@1.0.0@dsh0.1.3-alpha.2 · profile: l4-sandbox

Issued: 2026-09-09 · expires: 2026-09-16

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-09
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-09
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-09
spec dsh-plugin-tool-guard · channel npm package · outcome ran · exit 0
check took: 3.2s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-09
spec dsh-plugin-tool-guard · channel npm package · outcome ran · exit 0
check took: 3.2s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-09
spec dsh-plugin-tool-guard · channel npm package · outcome ran · exit 0
check took: 3.2s
L5 · Run tested✓ Passed

active in loader tree (150 entries)

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-09
spec dsh-plugin-tool-guard · install mode reused L4 scratch
check took: 44ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-09
ready line dsh web: http://127.0.0.1:59470/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-09
path / · HTTP 200 · took 44ms
Plugin active in inventory✓ Passed
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-09
verdict active · entries 150
match: include:dsh-plugin-tool-guard · dsh-plugin-tool-guard · phase active
phases: active 122 · null 28

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

Only the latest 3 published versions are shown; source-snapshot (commit hash) groups, unstated groups and older versions are omitted — the full archive stays in the data layer (snapshot/unstated groups appear only when a plugin has no published version).

Author badges

Embed the official badges in your README to showcase security & install-test status:

dsh.so risk
`[![dsh.so risk](https://www.dsh.so/badge/dsh-plugin-tool-guard.svg)](https://www.dsh.so/artifact/dsh-plugin-tool-guard/)`
dsh.so install
`[![dsh.so install](https://www.dsh.so/badge/install/dsh-plugin-tool-guard.svg)](https://www.dsh.so/artifact/dsh-plugin-tool-guard/)`

Security Report

Automated static scan, not manual review.

DSH.SO VETMEDIUMdbc8e1
Automated review · daily
MEDIUM

Vet verdict is suspicious: findings need human review (exfiltration endpoints, file deletion, etc.).

0 critical·1 high·0 medium
plugin version1.0.0dsh manifest
scanned version1.0.0npm2026-09-10
current version1.0.0same version
vet verdictsuspicious · npm

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

RiskRuleLocationDescription
high
R10
package.json
install 钩子:package.json scripts.prepare(安装期任意代码执行面)
medium
R11
run-tests.mjs:651
删除文件操作:rmSync(?)
Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-09-08 · activity: Active

• Repo created: 2026-09-08

• Stars: ★ 0 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/zhaoxuejie/dsh-plugin-tool-guard

Was this page helpful?