In the DSH (DeepSeek Harness) environment, an Agent typically has read and write access to the local file system. When operating on sensitive paths (such as keys, configuration files, or private data), prompt-only controls cannot guarantee security. The dsh-vault-wall plugin uses an interception layer so that, when an Agent encounters certain paths, it cannot sense that the files exist, access is directly denied, or access requires manual approval before proceeding.

Plugin Overview

This is a client-side plugin running on a DSH host, maintained by lxwallac and released under the MIT license.

  • Core positioning: Provides path isolation for DSH agents, making specified sensitive paths imperceptible and inoperable.
  • Dependency requirements: Requires a DSH host environment (DSH Desktop or the official source build dsh), and Node.js >= 22.0.0.

Core Features

The plugin controls file paths with tiered governance via configured rule sets, mainly including the following capabilities:

1. Three Protection Modes

  • Hidden mode: Paths matching a rule are disguised as non-existent (not-found) to the Agent, even without revealing the path name.
  • Deny mode: Immediately returns an error and indicates that the location is protected by a rule, so the Agent clearly knows it should not touch the area.
  • Ask mode: When matched, it does not deny directly, but opens a confirmation box through the official approval channel. The Agent sees the path, rule, tool, and risk level; access is allowed only after a human clicks “Allow”. If there is no approval channel or the user denies, it falls back to an explicit denial.

2. Risk and Verification Mechanisms

  • Tool risk rating: Built-in four levels: low (read-only), medium (write), high (execute/irreversible), and unknown (unrecognized, default to strict handling).
  • Post-execution verification: After each call, two layers of checks are performed:
    1. Authorization consistency: Compares against the decision made by the guard at that time, preventing internal plugin logic from causing a successful execution after a denial was issued.
    2. Leakage scanning: Checks whether the result contains protected paths, handled as redact (replace with placeholders), audit (record only), or block (block the entire response).
  • Loop correction: When the same Agent repeatedly hits the same rule, additional policy hints are appended to the denial message, preventing meaningless retries.
  • Self-protection: Rule files, audit logs, and historical files are hidden from the current Agent, preventing the Agent from modifying the wall or viewing audits.

3. Rule Management and Operations

  • Guardrail evaluation: Uses /wall report to aggregate interception/allow counts, approval results, bypass situations, and missed-report risks.
  • Rule health check: Uses /wall lint to detect issues such as overly broad coverage, unreachable tool names, and duplicate paths.
  • Rollback support: Uses /wall history and /wall rollback to manage rule revision history and supports rollback operations.

Installation and Enablement

This plugin is not a standalone program and must be installed in a DSH host environment.

  1. Prerequisites:
    • DSH host installed (DSH Desktop or the official source build dsh).
    • Node.js version >= 22.0.0.
  2. Installation command:
    Use the following command to add the plugin to a specified profile:
    dsh plugin --profile <profile> add dsh-vault-wall
If the network environment is unstable (for example, mirrors are out of sync), it is recommended to download the tgz file and install it:
    dsh plugin --profile <profile> add ./dsh-vault-wall-0.4.0.tgz
  1. Activation:
    After installation, restart DSH and configure rules in the “Vault Wall” section of the settings page.

Typical Usage and Examples

Rule Configuration

On the settings page, edit rules in JSON, specifying paths, modes, and parameters:

{
  "version": 1,
  "rules": [
    {
      "id": "keys",
      "mode": "hidden",
      "paths": ["C:\\keys"]
    },
    {
      "id": "archive-ro",
      "mode": "deny",
      "paths": ["C:\\archive"],
      "tools": ["write", "edit", "bash"]
    },
    {
      "id": "wallet-ask",
      "mode": "ask",
      "paths": ["C:\\wallet"],
      "minRisk": "medium",
      "remember": true,
      "borrowTtlMs": 600000
    }
  ]
}

Command-Line Operation Examples

In a DSH session, you can use /wall subcommands to manage it:

# 测试某路径的判定结果(不消耗借出、不改状态)
/wall test C:\work\repo\**\.env read

# 查看护栏评估报告
/wall report

# 检查规则是否有误
/wall lint

# 临时借出(授权整棵目录,默认 10 分钟)
/wall borrow add C:\Users\you\secret-box

Runtime Effects

  • Hidden mode: When the Agent reads a key, it receives Error: cannot read "C:\keys\id_ed25519": not found.
  • Deny mode: When the Agent deletes the archive directory, it receives Error: [vault-wall] access to "C:\archive" is denied by rule "archive-ro".
  • Ask mode: When the Agent writes to the wallet, an approval box is displayed, showing the risk level and tool information, requiring manual confirmation.

Summary

dsh-vault-wall builds an isolation layer within the DSH architecture, addressing security-boundary issues for Agent operations in the local file system. It combines explicit interception, manual approval, and post-execution verification to effectively prevent leakage of sensitive data. Along with the /wall command series, operators can clearly understand the operational boundaries of the Agent.