Introduction

In DeepSeek Harness (DSH), the default behavior of the write tool is full-file overwrite. If the model mistakenly uses write to modify an existing file, the original content is completely overwritten. By default, DSH’s fs-observation-policy only requires the file to be read first and does not prohibit overwriting. Rather than relying on post-hoc model self-discipline, it is better to establish “write = create only” as a hard constraint.

Core Capabilities

This plugin provides the following features:
1. Only intercepts write: other tools such as edit and read are completely unaffected.
2. Target already exists → reject: reject the call before tool execution and suggest using edit instead.
3. Target does not exist → allow: file creation operations proceed normally.
4. Conservative allowance: in uncertain cases such as invalid paths or stat errors, always allow the call to avoid incorrectly blocking legitimate usage.
5. Global effect: applies uniformly to all agents and sessions.

Installation and Enablement

After installation, the plugin is mounted automatically and takes effect after restarting DSH web.

Install from GitHub (source code is in src/ and is built automatically during installation):

dsh plugin --profile web add github:better-er/dsh-write-create-only

Install from npm (the package includes the build artifact lib/index.js):

dsh plugin --profile web add dsh-write-create-only

Working Principle

Every tool in DSH goes through the asynchronous tools/pre-execute waterfall before execution. This plugin registers a global listener in that waterfall:
1. It only applies when exec.name === 'write'.
2. It extracts exec.arguments.file_path, resolves it to an absolute target with ctx.fs.resolve, and then calls ctx.fs.stat.
3. If stat returns a non-empty result, the target already exists, and the plugin returns { kind: 'deny', reason } to reject the call.
4. In all other cases, it calls return next() to allow the operation.

tools/pre-execute is chosen instead of fs/write-intent because the latter is a single-slot waterfall that is already occupied by the default policy. tools/pre-execute is a multi-listener waterfall and does not affect the write schema.

Uninstallation

Remove the plugin completely:

dsh plugin --profile web remove dsh-write-create-only

Development and Verification

The plugin provides runtime smoke verification covering assertions for interception, allowance, and error tolerance:

npm install
npm run build
node scripts/smoke.mjs

License

MIT