Introduction

A local plugin for DeepSeek Harness (DSH), maintained by jackeyunjie. The plugin centrally manages rule files scattered across layers (AGENTS.md, rules/*.md), providing load visualization, budget governance, hard blocking, and compliance auditing capabilities.

Core Features

  • Layered rule discovery and injection
  • Write-back protection
  • FORBID hard rules
  • Rule Linting
  • Injection logs and compliance rate
  • Web panel

Installation and Enablement

  1. Ensure the environment has Node >= 22.
  2. Run npm install in the plugin directory to install dependencies.
  3. Add it to the web profile: dsh plugin --profile web add link:"$PWD".
  4. Verify the configuration: dsh --profile web --dump-config | grep -A3 rule-lens.
  5. Start DSH: dsh --profile web, then access the panel at http://127.0.0.1:3080/rule-lens.

Configuration and Rule Syntax

YAML Configuration

Global toggles are stored in ~/.dsh/settings.yaml:

rule-lens:
  writeGuard: true        # 写回防护开关
  budgetBytes: 65536      # 注入预算(字节)
  whitelistDirs: ['.cursor']  # 白名单目录

FORBID Hard Rule Syntax

Write a line in any loaded rule file:

FORBID: write *.env
FORBID: * **/secrets/**
FORBID: bash *rm -rf*

The tool-name glob matches exec.name (e.g., write, bash); the path glob simultaneously matches the original argument, absolute path, and relative path.

Layered Rule Injection Mechanism

The plugin injects rules by hierarchy and order; multiple files are sorted by numeric prefix (00-*.md before 01-*.md):
- L1: ~/.agents/AGENTS.md, injected at session startup.
- L2: ~/.agents/rules/*.md, injected at session startup.
- L4: <workspace>/.agents/rules/*.md, injected at session startup.
- L5: <subdirectory>/rules/*.md, injected on demand after the directory is first reached by read/write/edit.

Budget Governance

The injection budget defaults to 64KB. When the content exceeds the limit, files are dropped starting with the broadest-scoped file (L1 first); drops are logged and trigger an alert in the panel.

Logs and Compliance

  • Log paths: ~/.dsh/rule-lens/log.jsonl, compliance.jsonl.
  • Panel features: displays the status of each layer, budget bar, Lint results, compliance rate, warm-up toggle, and log download.
  • Dependencies are limited to @deepseek-ai/* peers and Node built-in modules; zero build, pure ESM.
  • GitHub: https://github.com/jackeyunjie/dsh-rule-lens
  • Directory: https://www.skillhub.cn/plugins/jackeyunjie/dsh-rule-lens