DeepSeek Harness (DSH) uses a plugin-based architecture. When building an Agent, policy definitions and MCP initialization configurations can easily become scattered, causing version inconsistencies or making configuration reuse difficult. dsh-agent-policy provides a shared policy contract. It is not responsible for intercepting tools; instead, it defines schemas, preset bases, and default MCP behavior for other plugins to consume.
Basic Information¶
- Name: dsh-agent-policy
- Maintainer: xingyingyuzhui
- Category: admin-security
- License: MIT
- Core focus: Shared Claw/session policy schema for DeepSeek Harness.
Core Features¶
This plugin mainly provides the following capabilities:
- Shared Claw/session policy schema: Defines the structure of the policy contract.
- Preset bases: Provides preset base classes for quick configuration.
- MCP initialization defaults: Sets default values for the MCP panel of new Agents.
- Does not deny tools: The plugin itself does not perform interception; permission control is handled by
dsh-agent-gate.
Installation and Enablement¶
Use the official command to install the plugin. It is recommended to install it in sequence before dsh-agent-registry, dsh-session-permissions, or dsh-agent-gate. After installation is complete, restart dsh web.
dsh plugin --profile web add github:xingyingyuzhui/dsh-agent-policy
Configuration Details¶
Configuration data is written to ~/.dsh/agent-policy/defaults.json and mainly contains the following fields:
- preset: The resident template when creating a new Claw Agent, such as
researchordeveloper. It corresponds to Claw Agent template in settings. - mcp: Default values for the MCP panel of new Agents; options are
none(turn all off),explicit(allow onlyservers.allow), orinit-defaults(allow when the list is empty). - servers.allow / servers.deny: MCP server names visible during initialization.
Permissions and MCP Mechanism¶
- MCP tool naming: Tool names follow the format
mcp__<service>__<tool>. - Permission control: Uninstalling this plugin does not relax permissions. Actual denials and hiding are in
dsh-agent-gate; by default, behavior falls back to DSH’s original permission-presets. - Bootstrap exception: When
BOOTSTRAP.mdexists, the gate additionally allows asking for the name and writing persona files in the current workspace, but it does not relax terminal access permissions in this default configuration. - Persistence: Written
defaultsremain on disk and are not automatically cleaned up even if the plugin is uninstalled.
Uninstall¶
To remove the plugin, use the following command:
dsh plugin --profile web remove dsh-agent-policy