The core principle of DeepSeek Harness (DSH) is “everything is a plugin.” When building agents, deletion operations are often irreversible. Directly using system commands rm or rmdir permanently removes files, which is not only risky but also interrupts the agent’s execution flow. dsh-shield is a plugin designed for DSH hands-off mode. It moves files to the Trash before deleting directories and applies special handling to link operations, ensuring security while maintaining zero approval prompts and zero popups, so the agent experience remains unchanged.

Plugin Introduction

This is a safety net plugin for DSH hands-off mode. It intercepts and rewrites deletion commands so that directory deletion moves content to the Trash and link deletion does not follow links. The plugin is maintained by x2802490130-prog, licensed under MIT, and categorized as admin-security.

Core Features

  • Directory deletion to Trash: Supports bash rm -r/-rf, cmd rmdir/rd/del /s, and filesystem tool directory deletion. Before execution, the target file/directory is renamed into the Trash (an instantaneous same-volume operation), and the command runs normally.
  • Glob salvage: Supports scenarios such as rm -rf dir/* and dir/*.log, individually salvaging matched subitems.
  • Links are never followed: For symbolic links, rm -rf link/ deletes the link itself rather than following the link and deleting the real content; if the parent directory is a link, it resolves through the link and salvages the actual target content.
  • Trash management: Provides a “Trash” section on the Settings page, supporting view, restore, delete, and clear operations.
  • System Trash compatibility: Can configure trashMode: system to use the system Trash, with automatic fallback on failure.
  • Zero intrusion: It only salvages without blocking; commands are actually executed, and the agent is unaware.
  • Local security: The management API is available only on the local loopback interface.

Configuration

The plugin is configured through the profile patch layer. The following are optional configuration items:

- id: dsh-shield
  config:
    trashRoot: D:\\path\\to\\trash      # 默认 $DSH_HOME/trash
    retentionDays: 14                  # 保留天数
    maxTrashBytes: 5368709120          # 最大占用 5GB
    trashMode: dir                      # dir | system

Typical Usage

  • Normal deletion: Directly use rm -rf dir; files are moved into the plugin-managed Trash.
  • Glob salvage: Execute rm -rf dir/*.log; all matched log files are salvaged one by one.
  • Link handling: Execute rm -rf link/; the link directory itself is deleted directly.
  • System Trash: Set trashMode: system in the configuration; deletion operations will attempt to move content to the system Trash.

Applicable Scenarios and Notes

  • Applicable scenarios: Suitable for scenarios where deletion operations must be performed in automated scripts or agents, but a fault-tolerance mechanism is desired. The plugin covers single-target and common glob scenarios, with the Trash as a fallback for extreme shell patterns.
  • Automatic cleanup: Trash content will be automatically cleaned up if it is older than 14 days or exceeds 5GB in usage.
  • Runtime permissions: The plugin runs with the current DSH process permissions. It is recommended to review the source code and license before installation.
  • Ecosystem note: The DSH philosophy is “everything is a plugin.” The community directory is an independent site and has no official affiliation with DeepSeek / High-Flyer.

Closing

dsh-shield reduces the risk of accidental deletion through the Trash mechanism while keeping the agent experience unchanged. For more information, see its GitHub repository or community directory.