dsh-tool-policy

Declarative deny-by-default tool policy plugin for DeepSeek Harness

PluginSecurity
Verification
L2 · Structured
Security
Pending
Health
Active
Trust
Bronze

What it doesAI

Declarative deny-by-default tool policy plugin that evaluates rules to deny, route for approval, or allow model-requested tools.

  • Fail-closed governance for model-requested tools
  • Rules evaluated at tools/pre-execute extension point
  • Can route tool calls to human approval seam

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add dsh-tool-policy

Install method: npm · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated scan, not manual review.

• Dependency vulnerabilities: — (pending)

• Suspicious permissions: — (pending)

• Hardcoded secrets: — (pending)

• Supply chain risks: — (pending)

⚠ Security audit scheduled — results will appear here after the next scan.

Activity

Last commit 2026-08-14 · activity: active

6 mo

Source

GitHub: github.com/Drifter-yh/dsh-tool-policy