In the plugin-based ecosystem of DeepSeek Harness (DSH), permission control and auditing for agents are core requirements for secure development. When an agent needs to invoke sensitive tools or access specific resources, it often requires a configurable, approvable, and auditable interception mechanism. dsh-agent-gate aims to provide such a permission gate function, helping developers finely manage the behavioral boundaries of agents through layered interception and audit logs.

Plugin Purpose

dsh-agent-gate is a permission gate plugin maintained by xingyingyuzhui. It is based on DSH’s hook mechanism (tools/pre-execute + tools.guard), intercepts tool calls according to layered permissions, supports official one-time approval, and records audit logs for Claw sessions.

Core Features

  1. Layered Interception
    The plugin uses the tools/pre-execute and tools.guard mechanisms to intercept tool calls based on layered permissions.
  2. Approval and Auditing
    Intercepted calls trigger the official one-time approval process. Audit logs are written to ~/.dsh/agent-gate/audit.l.
  3. Skill and MCP Filtering
    Removes skills in the agent skill blocklist from the session’s official skill directory and / menu. Rejects unauthorized MCP services and removes them from the tools visible to the model at session start.
  4. Policy Reuse
    Policy calculation reuses the dsh-session-permissions file in the same directory (Official ∩ Agent ∩ Session).
  5. Sandbox Isolation
    After unloading the gate, new calls are no longer intercepted, but the official file sandbox remains pinned by the permissions plugin and does not expand due to gate removal.

Install and Enable

Official Installation

dsh plugin --profile web add github:xingyingyuzhui/dsh-agent-gate

Local Development

dsh plugin --profile web add link:/abs/path/to/dsh-agent-gate

Notes
It is recommended to also install the dsh-session-permissions plugin. After installation, restart dsh web.

Typical Usage

  1. Configure Permission Policy
    Ensure that the dsh-session-permissions file exists in the same directory as the plugin for calculating permission policies.
  2. Session Interaction
    When an agent attempts to call an intercepted tool, the official approval workflow is triggered.
  3. View Audit Logs
    Check the ~/.dsh/agent-gate/audit.l file to review interception history and results.
  4. Manage MCP
    Configure the MCP blocklist in settings; the plugin takes effect at session start.

Use Cases and Cautions

  • Session Type
    The gate intercepts only Claw sessions; workspace sessions only use official permissions and are not affected by this gate.
  • Uninstall Impact
    After uninstalling the plugin, interception stops, but the pinned official file sandbox permissions are maintained independently by the permissions plugin and do not loosen as a result.
  • Runtime Environment
    The plugin runs under the current dsh process permissions. Review the source code and license before installation.

This plugin provides a fine-grained permission control layer for DSH. For more details and source code, visit GitHub.