DeepSeek Harness (DSH) 的插件化架构允许 Agent 获取最高权限(如 danger-full-access)。当模型执行 Remove-Item、rm、del 等删除命令时,通常意味着永久性破坏,缺乏安全回退机制。dsh-trash 插件通过拦截删除操作,将其转换为可恢复的移动操作,为 Agent 提供误删保护。

这是一个由 LeonSone 维护的 DSH 插件,核心价值在于将所有删除行为纳入一个可恢复的垃圾存储区。它支持 pwsh、bash 和 run_code 工具,默认回收站位置为 $DSH_HOME/trash,零运行时依赖。

Core Features

  • Intercept deletion commands: During the tools/pre-execute stage of pwsh, bash, and run_code tools, intercepts commands such as Remove-Item, rm, del, rd, unlink, fs.unlink, os.remove, and shutil.rmtree, refuses execution, and directs the model to use the trash tools.
  • Provide trash tools: Provides four tools: trash, trash-list, trash-restore, and trash-purge.
  • Default path: The trash location defaults to $DSH_HOME/trash. Each entry contains data/ (preserving the original file name) and meta.json (recording the original path, timestamp, and size).
  • Cross-volume support: Supports cross-volume moves and automatically falls back to copy if renaming is not possible.
  • Zero dependencies: Uses only built-in Node.js modules and has no additional runtime dependencies.

Installation and Activation

Add the plugin using the official installation command:

dsh plugin --profile web add github:LeonSone/dsh-trash

After installation, restart dsh web or the headless runner to load the plugin.

Typical Usage

After the plugin is loaded, the model’s behavior changes automatically:

  • Move to trash: Calls trash(paths=[...]) to move files/directories into the trash.
  • List trash: Uses trash-list(path?) to list entries (path filtering supported).
  • Restore files: Uses trash-restore(entry_id=...) or trash-restore(path='...') to restore entries.
  • Permanent deletion: The only true deletion path is trash-purge(confirm: true).

Applicable Scenarios and Notes

  • Security policy: The plugin uses a fail-safe design and prefers false positives (intercepting strings that contain deletion commands) over false negatives, preventing real deletions from occurring. Short aliases (such as rm and del) are matched only at command positions, so scenarios such as cat /tmp/rm are not intercepted.
  • Overwrite protection: If a restore target already exists, the existing target is first backed up to the trash to ensure no data loss.
  • Runtime permissions: The plugin runs with the permissions of the current dsh process. The source code and license should be checked before installation.

Summary

dsh-trash provides a safety fallback for Agent deletion by intercepting standard deletion commands and exposing trash-purge as the only exit. For more details and source code, see: GitHub.