AI Agent Hub
Back to plugins
dsh-plugin-tool-guard preview

dsh-plugin-tool-guard

admin-security Updated 2026.09.08

Run the following command in DeepSeek Harness:

dsh plugin install zhaoxuejie/dsh-plugin-tool-guard

Paste the following prompt into your AI chat to install this plugin:

Install it in DeepSeek Harness by running dsh plugin install zhaoxuejie/dsh-plugin-tool-guard; the source repository is at https://github.com/zhaoxuejie/dsh-plugin-tool-guard .

About this plugin

When an AI agent gains the ability to invoke shell commands and read or write local files, a single misjudgment can run rm -rf, leak a .env, or write outside the intended workspace. dsh-plugin-tool-guard adds a standalone security layer to DeepSeek Harness: a rule engine that evaluates every tool call before execution, with zero changes to business code. It activates on install and deactivates on removal, letting you govern agent behavior without touching a single line of application logic.

Five layered defenses work together: a regex blacklist for dangerous commands (rm -rf, mkfs, fork bombs — matched calls are denied outright with no approval step), a glob-based sensitive-file blocklist (.ssh, *.pem, /etc/passwd and more), a path whitelist hardened with resolve and realpath to prevent symlink and traversal bypass, three switchable security levels (loose, standard, strict — where strict requires human approval for every write and shell invocation), and a full audit trail with auto-sanitized parameters and per-session isolation capped at 200 entries. High-risk actions surface a native GUI approval card; timeouts default to deny so the system always fails closed.

The plugin is aimed at DSH users who let AI manipulate files and terminals on a local dev machine, especially when running untrusted third-party code, working in directories that hold API keys, or establishing a team-wide security policy. The zero-dependency DOM panel, runtime hot-switching of levels and whitelists, and per-profile isolation make ongoing security governance practical without service restarts.

Screenshots

Use Cases

  • Block dangerous shell commands like rm -rf before execution
  • Prevent AI from reading sensitive files such as .env or .ssh
  • Enforce a unified security policy for AI tool usage across the team

Best For

  • Developers running DeepSeek Harness on local dev machines
  • Technical teams that let AI operate files and shell commands
  • Ops engineers building audit trails for AI agent tool calls