In the usage scenarios of DeepSeek Harness (DSH), finely controlling tool invocations and file access scope is key to safeguarding environment security. DSH provides basic sandboxing and approval mechanisms, but for scenarios such as specific path matching and command-prefix interception, a more fine-grained policy is often needed. The dsh-permissions plugin provides a Claude Code-style permission rule engine and manages rules through a visual editor, meeting this need for fine-grained security control.
Plugin Positioning¶
dsh-permissions is a rule engine plugin that provides permission control capabilities for DeepSeek Harness. It supports four-level rule priority, global and workspace scope stacking, and draft-style visual editing. All rules are persistently stored and injected into the system prompt at runtime, enabling the model to be aware of the current permission constraints.
Core Features¶
Four-Level Rule Priority¶
Rules are divided into four priority levels, from highest to lowest: hard > deny > ask > allow.
* hard rules: They have the highest priority. Even if the session is in a “full access” approval posture (policy never), hard rules still take effect and cannot be waived.
* deny rules: Directly block the operation.
* ask rules: Decide whether to allow the operation based on the session’s approval policy.
* allow rules: Skip this plugin’s confirmation prompt and allow the operation directly.
Scope and Matching¶
- Scope stacking: Supports layering
globalrules andworkspacerules. When they conflict,denyrules always win. - Wildcard matching: For file-related tools (read/write/edit/glob/grep/read_image), supports path wildcard matching. For example,
write(*.pem)matches paths ending in.pem, andwrite(.ssh)matches any.sshfragment at any position in the path (case-insensitive, with slashes handled consistently). - Non-file tools: Non-file tools perform prefix matching against the raw value of the first argument; the
greptool additionally matches itspathparameter.
Persistence and Transparency¶
- Rules are stored in the Harness’s
settings.yamland are retained after restart. - Active rules are injected into the system prompt (marked as
[active-permission-rules]), enabling the model to see the full rule text and adjust its behavior accordingly.
Visual Editor¶
The plugin provides a browser-side settings page with draft-style editing. Changes do not take effect until “Save and Apply” is clicked; users can click “Discard Changes” at any time to restore the last saved state. It includes 16 secure default values (hard rules), protecting directories such as .ssh, .aws, .gnupg, AppData, .pem, .key, .env, and .htpasswd, and the deny: pwsh(rm -rf *) command.
Installation and Enablement¶
Use the official installer to install it.
dsh plugin add dsh-permissions
After installation, restart the application. A “Permissions” option appears on the settings page; click it to open the visual editor.
Typical Usage¶
Examples of intercepting command or file operation tools are as follows:
Intercept command tools
pwsh: 拦截该工具的全部调用
pwsh(npm run): 首参以 npm run 开头
Intercept file writes
write(*.pem): 文件路径以 .pem 结尾
write(*secret*): 文件路径包含 secret
write(.ssh): 路径任意位置出现 .ssh 片段
write(C:\users\*): 绝对路径前缀
Use Cases and Notes¶
Use cases:
* Developers who need to restrict the AI to operating on specific directories or file types.
* Scenarios that require intercepting dangerous commands (such as rm -rf *) or commands with specific prefixes.
* Situations where security policies must be enforced at the workspace level.
Notes:
* Security boundary: The plugin only narrows the existing sandbox or approval posture and never bypasses the DSH sandbox or the tools.guard guard.
* Error feedback: When a rule intercepts an operation, it is presented to the model as a tool error (for example, Error: Permission rule denied... or Hard rule denied (higher than full access, cannot be waived)...).
* Settings endpoint: The settings page route is a plugin-defined endpoint and is not exposed in the DSH api-proxy settings whitelist.
* Draft mechanism: All changes first enter a draft state and must be manually saved and applied before they have any real effect on AI behavior.
Summary¶
dsh-permissions provides DeepSeek Harness with a visual permission management solution that spans global and workspace scopes. Through strict priority design and wildcard matching, it enables developers to build fine-grained security policies at very low cost while maintaining compatibility with the DSH sandbox mechanism.