DeepSeek Harness (DSH) provides a framework for developing agents, but in production use, the risk of an agent performing destructive operations (such as force pushes or deleting critical files) is difficult to quantify and trace. Traditional security solutions often require manual intervention or permission changes, which disrupt the workflow. dsh-risk-guard is a plugin for DSH, designed to provide zero-intrusion audit capability and circuit-breaker protection for irreversible operations.

It is maintained by shuxue6662-a11y under the MIT license. Its core value lies in decoupling security monitoring from business operations: it first silently records all tool calls, then uses a deterministic scoring model to identify high-risk behavior, and finally blocks irreversible operations before execution.

Core Capabilities

Silent Audit

The plugin does not pop up permission prompts or modify the sandbox environment. It records each tool call (tool name, masked parameters, execution result, risk label, and explainable score) in a local JSONL file. This provides a complete data foundation for post-hoc review.

Deterministic Risk Scoring

The scoring process does not call an LLM and incurs no extra cost. It covers scenarios such as destructive deletion, credential reads, outbound network access, writes outside the workspace, dependency installation, and heavyweight builds. Repeated high-risk calls or consecutive high-risk operations accumulate additional scores.

Safety Circuit Breaker

For irreversible catastrophic operations, the plugin directly blocks execution. Protected operations include:
* Deleting protected paths (such as the root directory or credential files);
* Disk erase/format commands;
* Force pushes to protected branches (defaults to main/master);
* Network commands that reference credential files.

Operational Report

By using the /risk-guard command, you can view the current session’s operation history, score distribution, label statistics, and specific circuit-breaker records. This addresses the traceability issue of “what exactly did the agent do.”

Installation and Activation

This plugin requires DeepSeek Harness to be installed first.

Run the following command in the terminal:

dsh plugin --profile web add dsh-risk-guard

After installation is complete, restart the Web UI, and you can use the /risk-guard command in any session.

2. Installing via npm

If you use npm, run the following command:

npm install dsh-risk-guard

Then register the plugin in the configuration file cordis.patch.yml:

- insert:
    - id: risk-guard
      name: 'dsh-risk-guard'

Typical Usage

The plugin provides the following commands to view audit records:

/risk-guard              # View the operation report for the current session
/risk-guard --turn       # View only the previous turn's operations
/risk-guard --all        # View a summary and detailed report for all sessions
/risk-guard --since=2026-08-01
                        # View records after the specified date (can be combined with other parameters)
/risk-guard --           # Output machine-readable JSON format

Applicable Scenarios and Notes

  • Applicable Environment: DSH 0.1.0-rc.6, Web mode or Headless mode.
  • Data Storage: All audit data is stored in the <DSH_HOME>/risk-guard/ directory. Sensitive information (such as GitHub Tokens or keys) is masked before storage.
  • Privacy and Network: The plugin sends no telemetry data and does not initiate network requests.
  • Runtime Permissions: The plugin runs with the permissions of the current DSH process. If finer-grained permission control is required, configure it at the system level.

Summary

dsh-risk-guard is a system-level protection solution. By using deterministic rules instead of ambiguous LLM judgment, it ensures the objectivity of auditing. For agent development and debugging workflows that require high security, this is a tool worth adopting.