Introduction

The core philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” When developing with coding agents, agent tool calls sometimes perform destructive operations, such as rm -rf /, git reset --hard, or git push --force. Once these commands are executed, they are often irreversible. Barricade is an interception gate for this scenario. It assesses risk before command execution through semantic-level parsing and requires human confirmation, thereby preventing accidental data loss.

What Is It

Barricade is a destructive-command interception gate for coding agents. It is maintained by JohnXu22786 and released under the MIT license. Its core function is to parse and assess commands such as rm -rf and git reset --hard before they actually take effect, and to require human confirmation. It does not sandbox or restrict agent capabilities; it focuses solely on intercepting destructive operations that even a sandbox cannot prevent (such as overwriting remote history and deleting untracked files).

Core Features

Barricade’s core capabilities focus on command parsing and risk assessment:

  • Semantic-level command parsing: It does not rely on simple string matching. It includes a built-in POSIX lexer that can recognize quotes, escape characters, command substitution $(...), subshells, and pipeline chains. This means complex forms such as sudo rm -rf /, bash -c "rm -rf /", or eval "rm -rf /" cannot bypass detection.
  • 41 built-in rules: They cover many dangerous operations, including 13 dangerous Git forms, scope-tiered rm assessment, combinations involving dd/mkfs/shred/chmod/chown, find -delete, and curl|sh.
  • Three decision modes: It provides relaxed, balanced (default), and vigilant modes. Depending on severity, it allows, asks for confirmation, or rejects commands. In vigilant mode, unparseable input is denied by default.
  • Interactive confirmation: In a TTY environment, the system displays the command and the matched rules. Supported actions include confirming within the current session, permanently allowing it (writing to policy), and showing details.
  • Cross-Harness integration: The decision core is decoupled from the Harness. Three integration forms are provided: a DSH plugin, a generic stdin-hook JSON contract, and a gate shell wrapper.
  • Audit logs: Interception and confirmation records are persisted in JSONL format, and sensitive content is automatically redacted.

Installation and Activation

Barricade requires a Node.js >= 18.13 runtime and has no other runtime dependencies.

1. Install the Plugin

Add the plugin to the target DSH profile:

dsh plugin --profile demo add github:JohnXu22786/safety-net

2. Load the Configuration

After installation, the bundle needs to be loaded. It can be loaded via a local directory or a package name:

# 方式一:通过本地目录加载
dsh plugin --profile web add ../dsh-barricade

# 方式二:通过已发布包名加载
dsh plugin --profile web add dsh-barricade

# 启动 Harness
dsh --profile web

After successful loading, cordis.patch.yml inserts the plugin definition into the configuration layer.

DSH Plugin Integration

When Barricade runs as a DSH plugin, it listens for the tools/pre-execute event. If the decision is to block, it throws a BarricadeBlocked exception, causing the tool call to fail and feeding the reason back to the model.

Configuration Options

The plugin supports the following optional configuration:

Key Default Description
mode "deny" deny: block on match; ask: request human confirmation via the ctx.approval service; denial or an unavailable service is treated as blocking
toolNames common shell name list Block only specified tool names; can also be overridden by the BARRICADE_TOOLS environment variable
commandPath "args.command" Dot-path to the command text in the tool call
level policy file Specify the decision level; supports relaxed / balanced / vigilant

Configuration Example

Add it to cordis.patch.yml or the --patch overlay:

- insert:
    - id: barricade
      name: dsh-barricade
      config:
        mode: ask
        toolNames: [bash, run_code, run_command]

Typical Usage

Command-Line Tool

Barricade provides a standalone CLI tool that can directly analyze command risk:

# 判定命令,放行返回 0,拦截返回 1
barricade check -c "rm -rf /"

# 分析命令并输出详细 JSON 信息(不执行)
barricade analyze -- -c "git push --force origin main"

stdin-hook Integration

For Harnesses that support PreToolUse-style hooks, you can use gate mode:

echo '{"command":"git push --force origin main"}' | node bin/barricade.js hook

The output format conforms to the agreed JSON contract and includes action, severity, and reason.

Notes

  • Execution model: The plugin runs with the permissions of the DSH process, rather than inside an isolated sandbox. Check the source code and license before installation.
  • Fail-safe: In non-TTY environments, the default behavior is deny (fail-safe), meaning the command is blocked directly when interactive confirmation is unavailable.
  • Interface evolution: DSH is currently in developer preview, and interfaces may change. The plugin uses defensive programming internally to recognize tool-call shapes and multiple forms of ctx.approval to maintain compatibility.

Summary

Barricade provides coding agents with a line of defense against destructive commands. Through semantic-level parsing and flexible decision modes, it can effectively prevent high-risk operations such as rm -rf or git push --force from being executed accidentally, without restricting agent capabilities.