Introduction

Agents are increasingly executing Shell commands autonomously. When the command is rm -rf, a wrong variable or misjudged context switch is enough to lose a repository—or worse. agent-guard makes destructive operations reversible by default through quarantine, auditing, and human escalation, and records persistent intent before supported mutations.

What This Is

agent-guard is a DeepSeek Harness plugin that provides reliability guarantees while AI agents execute operations. It is not responsible for security sandboxing; instead, it defends against operational mistakes.

Core value: Makes destructive operations reversible by default.
Maintainer: mokuyoaxis
License: MIT

Core Features

The plugin includes the following capabilities:

  • Quarantined deletion: Redirects deletion operations to the .agent-trash/ directory with a manifest file.
  • Git snapshots: Automatically creates a snapshot before operations that overwrite Git data.
  • Human escalation: Triggers human confirmation (ASK) for composite operations that the agent cannot safely handle automatically.
  • Audit logging: Records decisions and outcomes using append-only JSONL logs.
  • Cross-Harness operation: Can run on any Harness that can execute Python.

Installation and Enablement

Ensure the environment meets the dependency requirements before installing: Python 3.9+, a POSIX shell, and git.

Add the plugin using the official installation command:

dsh plugin --profile <p> add github:mokuyoaxis/agent-guard

After installation, the plugin takes over the agent’s relevant operations.

Typical Usage

The plugin provides scripts for handling deletion, restoration, and inspection operations. The following are typical commands:

  1. Safe deletion: Performs deletion on a directory, while the actual operation quarantines it to the trash.
    python3 skills/delete-guard/scripts/safe_delete.py build/ --reason "stale"
  1. Check status: Views the current quarantine status.
    python3 skills/delete-guard/scripts/status.py
  1. Restore files: Lists restorable IDs and restores them.
    python3 skills/delete-guard/scripts/restore.py list
    python3 skills/delete-guard/scripts/restore.py <txid>
  1. Garbage collection: Cleans up files in .agent-trash/.
    python3 skills/delete-guard/scripts/gc.py
  1. Command interception: Checks a command before execution.
    python3 skills/delete-guard/scripts/check.py --enforce -- "$COMMAND"

Applicable Scenarios and Notes

  • Use cases: Scenarios where the agent needs to clean up build artifacts, workspaces, and similar tasks, especially operations with a high risk of accidental deletion.
  • Notes:
    • This is reliability infrastructure, not a security sandbox. It defends against mistakes, not malicious agents.
    • Zero third-party dependencies.
    • Session-based capability; restoration is limited to manual intervention.

Conclusion

agent-guard provides a set of mechanisms that allow agents to convert irreversible destruction into reversible quarantine when performing destructive operations. For scenarios where agents need to interact with the file system autonomously, it is a practical layer of protection.

Catalog page: https://www.skillhub.cn/plugins/mokuyoaxis/agent-guard
GitHub repository: https://github.com/mokuyoaxis/agent-guard