Preface¶
When using DeepSeek Harness (DSH) to handle Windows tasks, agents may perform dangerous operations such as deleting files, reading credentials, or modifying system state. Without controls, these operations can lead to data loss or security risks. dsh-windows-workspace-guard aims to provide protection for Windows workspaces, immutable paths, Git risks, and approval and audit processes.
What Is This¶
This is a DeepSeek Harness plugin for controlling agent file operations in Windows environments. It is developed and maintained independently and is not an official DeepSeek component. By restricting dangerous operations, providing approval mechanisms, and generating audit logs, the plugin helps developers ensure that agents operate within controlled boundaries.
Core Features¶
The plugin intercepts and makes decisions on tool calls made by Windows agents. Its main capabilities include:
- Decision results: For each operation, it returns
PASS(allow),ASK(requires manual approval), orHARD BLOCK(hard block). - Risk blocking: It prevents deletion of original files, operations outside the workspace, destruction of Git recovery paths, reading credentials, and changing system state.
- Tool support: Supports tools such as
pwsh,read,read_image,write,edit,glob,grep, andstr_replace_editor. - Audit logging: Audit log files have a maximum size of 32 MiB. It provides an audit summary tool for counting total decisions and frequent rule IDs.
- Precheck capability: Supports inspecting instructions without executing commands (dry-run) to identify risks.
Installation and Enablement¶
Run the following command in the terminal to install the plugin:
dsh plugin --profile web add github:julescules/dsh-windows-workspace-guard#v1.1.1
After installation, restart DSH to load the plugin configuration.
Typical Usage¶
The plugin provides multiple helper tools for inspection, auditing, and diagnostics.
-
Precheck command: Check command risks before execution.
Ask the agent:
> Run windows_workspace_guard_doctor, then use windows_workspace_guard_check to inspect this command without executing it: Get-Content -LiteralPath $env:DSH_HOME.credentials.yaml -
View audit summary: Summarize decision statistics.
Ask the agent:
> Run windows_workspace_guard_audit_summary and show the most frequent rule IDs. -
Diagnose uncovered tools: Check which tools are not covered by the plugin.
Ask the agent:
> Run windows_workspace_guard_doctor and explain uncovered tools.
Use Cases and Notes¶
- Community plugin: This is an unofficial community plugin. Evaluate it on your own as needed.
- Conservative boundaries: It provides conservative tool boundary controls and is not a general-purpose DLP (Data Loss Prevention) system. It does not inspect arbitrary native process memory or unsupported tools.
- No network requests: The plugin does not send any network requests during runtime.
- Audit files: Audit files are not generated unless
auditPathis configured. - Path configuration recommendation: When configuring
workspaceRootsandsensitivePaths, keep paths as absolute paths and as narrowly scoped as possible.
Short Conclusion¶
With the configurations above, you can build a protection layer for Windows agents that includes workspace isolation, credential protection, and audit capabilities. For more details, refer to the official directory or the GitHub repository.