Preface¶
DeepSeek Harness (DSH) emphasizes pluginization and automation. However, in practice, if an agent has direct access to the file system, it can easily lose configurations, delete project files by mistake, or damage the runtime environment due to incorrect operations or script errors. The dsh-safety plugin serves as a compatibility safety Harness for DSH and enforces a three-tier file policy at the tool execution boundary. Its core value is to intercept destructive calls and require manual approval, ensuring that every critical operation remains auditable and reversible.
What It Is¶
This is a file-system safety Harness for DeepSeek Harness (DSH). It provides runtime guarding, a recycle-bin-based safe_delete feature (with undo support), composition snapshots and rollback, and pre-restart validation. The plugin is provided as a standard DSH profile bundle and also includes a standalone CLI with zero runtime dependencies.
Core Features¶
Runtime Guard¶
The plugin intercepts destructive calls before they run. Core rules include:
* Recursive deletion interception: By default, recursive deletion commands such as rm -r/-rf and Remove-Item -Recurse are denied, forcing them to go through the safe_delete channel.
* Protected path interception: write/edit operations on critical paths such as package.json, cordis.patch.yml, lockfiles, node_modules, and deployment directories are blocked.
* Code scanning: It does not only intercept file-system APIs, but also scans run_code code bodies to prevent hidden destructive operations such as fs.rmSync from being executed through code.
* Variable reference interception: Path deletions involving variable expansion, such as Remove-Item "$env:USERPROFILE...", are intercepted.
User-gated Approval System¶
The model cannot approve destructive operations by itself; manual confirmation is required.
* safety_ask: The model calls this tool with structured parameters (path, kind, what, why, consequence, alternative), creating an approval request that includes consequences calculated by the system and returns an ID.
* Manual intervention: The model must prompt the user to run dsh-safety allow <id>.
* Mechanism limits: Approvals are one-time and limited by time, synchronized across processes using an atomic lock. The model itself cannot set force:true to bypass validation.
Safe Deletion and Undo¶
safe_delete: The only approved deletion channel. Supportspreview:trueto preview deletion contents, and refuses to delete the root directory or the plugin’s own state directory.- Undo: Deleted files are moved to a recycle bin and can be restored via
safety_undo. - Audit: Every deletion is recorded in the log.
Composition Snapshot and Rollback¶
safety_snapshot: Saves the entire plugin composition (manifests, patches, lockfiles,package.json, etc.) and computes a SHA-256 hash.safety_restore: Rolls the environment back to the last known good state. Before rollback, it backs up the current files to ensure that a failed rollback does not leave the environment in a half-broken state.- Security filtering: Files containing credentials are excluded by default.
Pre-restart Validation¶
safety_check: Runs before DSH restarts and checks UTF-8 encoding, detects garbled characters (errors that prevent opening), JSON parsing errors, and duplicate plugin IDs.
Audit Logs¶
Via safety_journal or safety_status, you can query all records of intercepted, approved, deleted, snapshot, and rollback operations.
Installation and Enablement¶
The plugin is provided as a standard DSH profile bundle and is also published as the npm package @suagr_xl/dsh-safety. After installation, it is automatically loaded as a plugin when DSH starts and takes over file-system operations.
Typical Usage¶
User Approval Flow¶
- The model detects that a file needs to be deleted, calls
safety_ask, and returns an ID. - The model prompts the user: “Please approve the deletion: dsh-safety allow
“. - The user runs
dsh-safety allow <id>in the terminal. - The plugin records the approval and allows the operation to proceed.
Undo Deletion¶
# 恢复最近一次安全删除的文件
dsh-safety undo
Snapshot and Rollback¶
# 创建当前配置快照
dsh-safety snapshot
# 恢复到上一次快照
dsh-safety restore
Check Environment¶
# 检查配置完整性及潜在错误
dsh-safety check
Applicability and Cautions¶
- Environment requirement: Node.js version >= 22 is required.
- Dependencies: Zero runtime dependencies; only depends on the Node.js environment.
- Permission risk: The plugin runs with the privileges of the current DSH process. Ensure that the DSH process permissions are reasonable.
- Security principle: The plugin excludes files containing credentials by default, but it is recommended to inspect the source code and license before deployment.
- Standalone CLI: Even if DSH cannot start, the
dsh-safetyCLI remains available and can be used for emergency recovery or auditing.
Summary¶
dsh-safety provides a robust security foundation for DSH plugin development and usage by intercepting operations at runtime, enforcing manual approval, and providing snapshot and rollback capabilities. It turns lessons from production incidents into mandatory mechanisms, rather than relying on documentation alone.