Introduction¶
The core philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” When developing with coding agents, agent tool calls sometimes perform destructive operations, such as rm -rf /, git reset --hard, or git push --force. Once these commands are executed, they are often irreversible. Barricade is an interception gate for this scenario. It assesses risk before command execution through semantic-level parsing and requires human confirmation, thereby preventing accidental data loss.
What Is It¶
Barricade is a destructive-command interception gate for coding agents. It is maintained by JohnXu22786 and released under the MIT license. Its core function is to parse and assess commands such as rm -rf and git reset --hard before they actually take effect, and to require human confirmation. It does not sandbox or restrict agent capabilities; it focuses solely on intercepting destructive operations that even a sandbox cannot prevent (such as overwriting remote history and deleting untracked files).
Core Features¶
Barricade’s core capabilities focus on command parsing and risk assessment:
- Semantic-level command parsing: It does not rely on simple string matching. It includes a built-in POSIX lexer that can recognize quotes, escape characters, command substitution
$(...), subshells, and pipeline chains. This means complex forms such assudo rm -rf /,bash -c "rm -rf /", oreval "rm -rf /"cannot bypass detection. - 41 built-in rules: They cover many dangerous operations, including 13 dangerous Git forms, scope-tiered
rmassessment, combinations involvingdd/mkfs/shred/chmod/chown,find -delete, andcurl|sh. - Three decision modes: It provides
relaxed,balanced(default), andvigilantmodes. Depending on severity, it allows, asks for confirmation, or rejects commands. In vigilant mode, unparseable input is denied by default. - Interactive confirmation: In a TTY environment, the system displays the command and the matched rules. Supported actions include confirming within the current session, permanently allowing it (writing to policy), and showing details.
- Cross-Harness integration: The decision core is decoupled from the Harness. Three integration forms are provided: a DSH plugin, a generic stdin-hook JSON contract, and a
gateshell wrapper. - Audit logs: Interception and confirmation records are persisted in JSONL format, and sensitive content is automatically redacted.
Installation and Activation¶
Barricade requires a Node.js >= 18.13 runtime and has no other runtime dependencies.
1. Install the Plugin¶
Add the plugin to the target DSH profile:
dsh plugin --profile demo add github:JohnXu22786/safety-net
2. Load the Configuration¶
After installation, the bundle needs to be loaded. It can be loaded via a local directory or a package name:
# 方式一:通过本地目录加载
dsh plugin --profile web add ../dsh-barricade
# 方式二:通过已发布包名加载
dsh plugin --profile web add dsh-barricade
# 启动 Harness
dsh --profile web
After successful loading, cordis.patch.yml inserts the plugin definition into the configuration layer.
DSH Plugin Integration¶
When Barricade runs as a DSH plugin, it listens for the tools/pre-execute event. If the decision is to block, it throws a BarricadeBlocked exception, causing the tool call to fail and feeding the reason back to the model.
Configuration Options¶
The plugin supports the following optional configuration:
| Key | Default | Description |
|---|---|---|
mode |
"deny" |
deny: block on match; ask: request human confirmation via the ctx.approval service; denial or an unavailable service is treated as blocking |
toolNames |
common shell name list | Block only specified tool names; can also be overridden by the BARRICADE_TOOLS environment variable |
commandPath |
"args.command" |
Dot-path to the command text in the tool call |
level |
policy file | Specify the decision level; supports relaxed / balanced / vigilant |
Configuration Example¶
Add it to cordis.patch.yml or the --patch overlay:
- insert:
- id: barricade
name: dsh-barricade
config:
mode: ask
toolNames: [bash, run_code, run_command]
Typical Usage¶
Command-Line Tool¶
Barricade provides a standalone CLI tool that can directly analyze command risk:
# 判定命令,放行返回 0,拦截返回 1
barricade check -c "rm -rf /"
# 分析命令并输出详细 JSON 信息(不执行)
barricade analyze -- -c "git push --force origin main"
stdin-hook Integration¶
For Harnesses that support PreToolUse-style hooks, you can use gate mode:
echo '{"command":"git push --force origin main"}' | node bin/barricade.js hook
The output format conforms to the agreed JSON contract and includes action, severity, and reason.
Notes¶
- Execution model: The plugin runs with the permissions of the DSH process, rather than inside an isolated sandbox. Check the source code and license before installation.
- Fail-safe: In non-TTY environments, the default behavior is deny (fail-safe), meaning the command is blocked directly when interactive confirmation is unavailable.
- Interface evolution: DSH is currently in developer preview, and interfaces may change. The plugin uses defensive programming internally to recognize tool-call shapes and multiple forms of
ctx.approvalto maintain compatibility.
Summary¶
Barricade provides coding agents with a line of defense against destructive commands. Through semantic-level parsing and flexible decision modes, it can effectively prevent high-risk operations such as rm -rf or git push --force from being executed accidentally, without restricting agent capabilities.