DeepSeek Harness (DSH) uses a plugin-based architecture. When building an Agent, policy definitions and MCP initialization configurations can easily become scattered, causing version inconsistencies or making configuration reuse difficult. dsh-agent-policy provides a shared policy contract. It is not responsible for intercepting tools; instead, it defines schemas, preset bases, and default MCP behavior for other plugins to consume.

Basic Information

  • Name: dsh-agent-policy
  • Maintainer: xingyingyuzhui
  • Category: admin-security
  • License: MIT
  • Core focus: Shared Claw/session policy schema for DeepSeek Harness.

Core Features

This plugin mainly provides the following capabilities:

  1. Shared Claw/session policy schema: Defines the structure of the policy contract.
  2. Preset bases: Provides preset base classes for quick configuration.
  3. MCP initialization defaults: Sets default values for the MCP panel of new Agents.
  4. Does not deny tools: The plugin itself does not perform interception; permission control is handled by dsh-agent-gate.

Installation and Enablement

Use the official command to install the plugin. It is recommended to install it in sequence before dsh-agent-registry, dsh-session-permissions, or dsh-agent-gate. After installation is complete, restart dsh web.

dsh plugin --profile web add github:xingyingyuzhui/dsh-agent-policy

Configuration Details

Configuration data is written to ~/.dsh/agent-policy/defaults.json and mainly contains the following fields:

  • preset: The resident template when creating a new Claw Agent, such as research or developer. It corresponds to Claw Agent template in settings.
  • mcp: Default values for the MCP panel of new Agents; options are none (turn all off), explicit (allow only servers.allow), or init-defaults (allow when the list is empty).
  • servers.allow / servers.deny: MCP server names visible during initialization.

Permissions and MCP Mechanism

  • MCP tool naming: Tool names follow the format mcp__<service>__<tool>.
  • Permission control: Uninstalling this plugin does not relax permissions. Actual denials and hiding are in dsh-agent-gate; by default, behavior falls back to DSH’s original permission-presets.
  • Bootstrap exception: When BOOTSTRAP.md exists, the gate additionally allows asking for the name and writing persona files in the current workspace, but it does not relax terminal access permissions in this default configuration.
  • Persistence: Written defaults remain on disk and are not automatically cleaned up even if the plugin is uninstalled.

Uninstall

To remove the plugin, use the following command:

dsh plugin --profile web remove dsh-agent-policy