← DeepSeek Harness Plugins
DeepSeek Harness PluginManifest Valid

dsh-permission-rules

Declarative allow/deny/ask tool permission rules and process-level network policy for DeepSeek Harness.

UI & ProductivityTerminal & TUIDeveloper ToolsSecurity & PolicySkills & WorkflowsRemote Execution
115GitHub Stars3ForksUpdated2026-09-25

Install

$ dsh plugin --profile web add "github:PerryLink/dsh-permission-rules#main"

Plugin Overview & Capabilities

AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.

source-grounded
dsh-permission-rules brings Claude Code-style declarative permission rules and process-level network policies to DeepSeek Harness. It enforces ordered allow/deny/ask rules directly on the tools/pre-execute waterfall with support for tool names, arguments, workspace paths, and command decomposition, while proxying subprocess traffic via a local HTTP/CONNECT proxy.

Key Capabilities

  • Evaluates ordered allow, deny, and ask permission rules before executing tools
  • Supports multi-dimensional matching across tool names, agent selectors, arguments, paths, environment variables, and network targets
  • Provides process-level outbound network governance via a local HTTP/CONNECT proxy with deny-all, whitelist, and allow-all modes
  • Offers hot rule reloading with Chokidar file watching and dry-run evaluation
  • Integrates full session-log audit events and a settings UI with rule editing and recent interception counters
  • Includes the /rules slash command for runtime inspection, reloading, audit history, and hypothetical testing

Useful For

  • Preventing accidental or malicious execution of destructive commands (e.g., git push to protected branches, sudo, rm -rf)
  • Restricting agent tool actions on sensitive directories and files
  • Enforcing network boundaries on shell subprocesses and web tools using sandbox-aligned presets
  • Auditing and testing security policies across multi-agent or subagent workflows

Who It Fits

  • Developers and teams enforcing security boundaries in DeepSeek Harness workspaces
  • System administrators defining high-risk command baselines and network restrictions
  • Users pairing deterministic security rules with automated second-model review

Documented Limitations

  • Path candidate extraction relies on documented argument keys rather than OS kernel-level path interception
  • Glob matching uses a conservative subset without brace expansion
  • Regex backtracking protections are structural and best substituted with glob mode for untrusted input
  • Older or alpha harness builds require specific handling or migration scripts for ignorable session-log audit markers

DSH Compatibility

Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.

Not tested yetNo runtime compatibility tests have been published yet.

Security Signals

Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.

Dependency Counts

package.json declares 6 runtime, 32 development, 13 peer, and 0 optional dependencies.

info
Dsh Bundle Declared

package.json declares DSH bundle metadata.

info
License Declared

GitHub reports the repository license as Apache-2.0.

info
Package Manifest Available

A root package.json was captured and can be inspected by the registry.

info
Prepare Script Detected

package.json declares a prepare lifecycle script that may run during relevant package installation workflows.

info
Source Available

Public GitHub source metadata is available for this registry snapshot.

info

Source & Registry Notes

Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.

Source repository
PerryLink/dsh-permission-rules
Registry source
GitHub · dsh-plugin topic
Registry classification
Plugin
Source checked
8918ee8 · 2026-09-28

This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.

Repository Activity

GitHub stars
115GitHub stars
Forks
3
Open issues
8
Last commit
2026-09-25
Last release
2026-09-25
For maintainers

Maintaining this plugin?

This listing is generated from public repository data. If you maintain this project, you can review the information and share this listing with your users if you find it useful.

Add to README
Listed on DSHPlugin.app