DeepSeek Harness (DSH) provides a framework for developing agents, but in production use, the risk of an agent performing destructive operations (such as force pushes or deleting critical files) is difficult to quantify and trace. Traditional security solutions often require manual intervention or permission changes, which disrupt the workflow. dsh-risk-guard is a plugin for DSH, designed to provide zero-intrusion audit capability and circuit-breaker protection for irreversible operations.
It is maintained by shuxue6662-a11y under the MIT license. Its core value lies in decoupling security monitoring from business operations: it first silently records all tool calls, then uses a deterministic scoring model to identify high-risk behavior, and finally blocks irreversible operations before execution.
Core Capabilities¶
Silent Audit¶
The plugin does not pop up permission prompts or modify the sandbox environment. It records each tool call (tool name, masked parameters, execution result, risk label, and explainable score) in a local JSONL file. This provides a complete data foundation for post-hoc review.
Deterministic Risk Scoring¶
The scoring process does not call an LLM and incurs no extra cost. It covers scenarios such as destructive deletion, credential reads, outbound network access, writes outside the workspace, dependency installation, and heavyweight builds. Repeated high-risk calls or consecutive high-risk operations accumulate additional scores.
Safety Circuit Breaker¶
For irreversible catastrophic operations, the plugin directly blocks execution. Protected operations include:
* Deleting protected paths (such as the root directory or credential files);
* Disk erase/format commands;
* Force pushes to protected branches (defaults to main/master);
* Network commands that reference credential files.
Operational Report¶
By using the /risk-guard command, you can view the current session’s operation history, score distribution, label statistics, and specific circuit-breaker records. This addresses the traceability issue of “what exactly did the agent do.”
Installation and Activation¶
This plugin requires DeepSeek Harness to be installed first.
1. Using the Plugin Manager (Recommended)¶
Run the following command in the terminal:
dsh plugin --profile web add dsh-risk-guard
After installation is complete, restart the Web UI, and you can use the /risk-guard command in any session.
2. Installing via npm¶
If you use npm, run the following command:
npm install dsh-risk-guard
Then register the plugin in the configuration file cordis.patch.yml:
- insert:
- id: risk-guard
name: 'dsh-risk-guard'
Typical Usage¶
The plugin provides the following commands to view audit records:
/risk-guard # View the operation report for the current session
/risk-guard --turn # View only the previous turn's operations
/risk-guard --all # View a summary and detailed report for all sessions
/risk-guard --since=2026-08-01
# View records after the specified date (can be combined with other parameters)
/risk-guard -- # Output machine-readable JSON format
Applicable Scenarios and Notes¶
- Applicable Environment: DSH 0.1.0-rc.6, Web mode or Headless mode.
- Data Storage: All audit data is stored in the
<DSH_HOME>/risk-guard/directory. Sensitive information (such as GitHub Tokens or keys) is masked before storage. - Privacy and Network: The plugin sends no telemetry data and does not initiate network requests.
- Runtime Permissions: The plugin runs with the permissions of the current DSH process. If finer-grained permission control is required, configure it at the system level.
Summary¶
dsh-risk-guard is a system-level protection solution. By using deterministic rules instead of ambiguous LLM judgment, it ensures the objectivity of auditing. For agent development and debugging workflows that require high security, this is a tool worth adopting.
- Plugin catalog: dsh-risk-guard
- GitHub repository: shuxue6662-a11y/dsh-risk-guard