dsh-guard
DiscoveredDSH sandbox hardening toolset: persistent auditing and file rollback (dsh-audit-rollback), model-selectable automatic approval (dsh-auto-review-router).
dsh-guard
面向 DeepSeek Harness(核心 @deepseek-ai/dsh 0.2.1-alpha.1)的沙箱侧加固工具集。
补上官方当前没有的两块能力:可回滚的持久审计,以及可指定模型的自动审批。
背景
核查结论(2026-10-04,只读核查 0.2.1-alpha.1):
| 能力 | 官方现状 |
|---|---|
| 权限三档 | read-only / workspace-write / danger-full-access,各自捆绑沙箱与审批策略 |
| 审批策略 | 只有 ask / never;无 allow-always、无记住授权、无撤销 |
| 审计 | dsh-workspace-changes 给每轮 diff,但只存活在 Host 进程内存,重启即失;非 git 工作区不覆盖 shell 改动 |
| 回滚 | 完全没有任何 revert / undo / restore 入口 |
| 自动审批 | dsh-experimental-auto-review 逐调用审查,但 reviewer 路由硬编码为当前会话的 provider/model,无 Config(源码只导出 apply/inject/name,patch 层改不了) |
包
| 包 | 内容 | 版本 |
|---|---|---|
packages/dsh-audit-rollback | 编辑前内容捕获(SHA-1 内容寻址)+ 逐轮 JSONL 审计账本 + 离线 CLI 精确回滚;带可编辑设置页 | 0.2.1 |
packages/dsh-auto-review-router | 把 Auto 审查的 reviewer 路由解耦为可配置 provider/model/effort;带可编辑设置页 | 0.2.1 |
业务存储逻辑只使用 node:*;配置声明使用宿主提供的官方 schema peer,设置写入走宿主 settings / configEditor,不捆绑另一套 DSH 核心,不另建配置文件。
安装
桌面(desktop)profile
桌面 profile 由 Electron 管理,CLI 会拒绝操作。请通过 GUI 插件管理器安装或更新两个发布 tarball;不要手工编辑 profile 的依赖清单,也不要在 profile 目录执行 pnpm install。安装后检查插件加载结果、设置入口及保存后的实际值;仅在管理器要求时重载或重启。
历史手工 junction 安装不再作为推荐流程。工作区源码与已安装副本可能不同;修改源码不代表当前 GUI 已加载新版本。
非桌面 profile
dsh plugin --profile <name> add <包绝对路径或 tarball URL>
⚠️ 不建议用 pnpm 的 git 依赖直接安装 monorepo 子包。
github:<owner>/<repo>#path:/packages/<pkg>语法可以解析到子包,但会连带解析并安装整个 workspace 的成员与其 peer——实测一次装了 530 个包,其中包括整套@deepseek-ai/dsh*,会往 profile 里塞进另一套核心版本。
发布产物
每次 main 推送都会自动构建并发布一个 release,附带两个 tarball:dsh-audit-rollback.tgz 与 dsh-auto-review-router.tgz。
资产名不带版本号,因此 https://github.com/KouzakiUmi/dsh-guard/releases/latest/download/<资产名>.tgz 永久有效,不会随发版 404。
设置
两个包各带可编辑配置与实时状态页,系统级设置统一位于 设置 → 内置插件,只保留一个入口,不再在设置侧栏另开页面:
- 审计与回滚:编辑捕获工具、捕获字节上限、参数预览上限、调用记账与排除路径;保留账本、对象库和最近捕获诊断。状态目录不是即时字段;未实现的影子 Git 快照不作为有效开关提供。
- Auto 审查路由:编辑启用状态、reviewer provider/model/effort、会话回退、上下文/历史/超时预算及日志策略;显示实际注册结果、路由和冲突。
保存通过官方 settings 服务,按 Config schema 校验,以 revision 拒绝过期写入,持久化至当前 profile 的 Cordis patch。不直接修改依赖清单,也不使用额外的插件设置文件。更高层 overlay 覆盖或 Settings 不可用时显示明确错误,不伪报保存成功。
即时字段使用 .volatile() 配置引用;审计轮次和单次模型审查各持有配置快照,避免编辑途中混用新旧配置。启用插件不等于自动替用户选中 Auto,也不改变用户的审批策略。
旧版“Config 一律不可变、只能手写 YAML”的说明已撤回。普通字段仍需配置编辑器重载;即时字段可以直接在设置页编辑。源码改动不代表已安装副本已经生效。
文档
docs/design-audit-rollback.md— 阶段 A 契约(数据布局、账本字段、CLI 退出码、跨平台要求)docs/design-auto-review-router.md— 阶段 B 契约(Config、策略文本、决策协议、上下文分区)docs/design-plugin-ui-and-listing.md— 设置 UI 与商店收录docs/release-plan.md、docs/release.md— CI 与发包流程
开发
npm install --ignore-scripts # 仅仓库开发依赖,不在 DSH profile 目录执行
node tools/verify.mjs # 机械验收:语法、全部测试、API peer、清单一致性
node scripts/check-manifest.mjs # 逐包清单校验(含 exports["./client"] 门禁)
node scripts/pack-all.mjs # 打包到 dist/ 并核对实际 tarball 字节及 JS 语法
npm run release:local # verify + check-manifest + pack-all
CI(.github/workflows/ci.yml)在 main 推送时跑同一套序列;v* tag 触发版本化发布(make_latest: false,不会抢 latest)。
已知限制
- 审计只覆盖文件工具点名的路径(
write/edit/str_replace_editor);shell(pwsh/bash)对文件的改动不入账,gitSnapshot是未实现的占位开关。 dsh-auto-review-router与官方dsh-experimental-auto-review互斥(两者都注册保留名auto,后注册者会失败),也不要与dsh-codex-connect的enableAutoReview同时启用。- 两者的 Host 侧都未在真实 DSH 进程里跑过完整链路(见各包 README 的「未核实项」);
dsh-auto-review-router的 13 项内部 API 用法是探测式实现。
许可证
MIT
Comments
Loading…
Similar plugins
by 782042369
DSH compatibility guard: repairs compaction limits, fail-safe sandbox escalation, and missing tool descriptions for third-party models; capability lookups are cached and the deprecated prompt-injection path is off by default.
★ 0
MIT
JavaScript
Sep 8, 2026
dsh plugin --profile web add dsh-model-compat-guardby ZK-Andy
Continual self-evolution plugin for DeepSeek Harness: versioned, auditable, rollback-safe harness state refined from session trajectories, with a benchmark-driven validation loop.
★ 20
↓ 1.8k/wk
MIT
TypeScript
Oct 5, 2026
dsh plugin --profile agent add dsh-continual-evolveby zxmqq1234
DeepSeek Harness(dsh)自动重试插件:报错自动重试、中断自动继续、挂起自动唤醒、 每一步右上角弹窗告诉你,不用再手动发"继续",数据看板还原每一次重试的真相。与 dsh系统重试互补而非替代——在内置重试耗尽或不覆盖的错误码上追加保障。
★ 4
MIT
TypeScript
Sep 30, 2026
dsh plugin --profile web add dsh-auto-retryby lispking
A self-evolving plugin for DeepSeek Harness (dsh). It observes how the agent runs, proposes improvements to its own assets via the LLM, validates each proposal inside a sandboxed trial agent, and appl
★ 3
↓ 202/wk
MIT
TypeScript
Aug 25, 2026
dsh plugin --profile web add dsh-auto-evolveby ZSeven-W
DeepSeek Harness (DSH) plugin: a read-only ledger for the plugins you already have installed — a capability inventory with file:line evidence, declared-vs-detected reconciliation, cross-profile versio
★ 24
↓ 53/wk
MIT
JavaScript
Sep 24, 2026
dsh plugin --profile web add @zseven-w/dsh-harborby d86e
dsh-doctor: self-healing watchdog for the DeepSeek Harness web profile. Recovers from plugin-induced boot failures within 60s, runs an unbounded CLI doctor, captures every tool error, and watches all
★ 4
MIT
TypeScript
Sep 8, 2026
dsh plugin --profile web add @d86e/dsh-doctor