245678000000/dsh-shield
245678000000★ 0TypeScript最后同步: 2026-08-16
Security, Trust & Policy Layer for DeepSeek Harness. Don't trust your agent's tools. Verify them.
README 摘要
dsh-shield DeepSeek Harness 的安全防火墙。 安装前扫描。执行前拦截。动作后审计。 Don't trust your agent's tools. Verify them. English 安装 需要 Node.js 20+ 和 pnpm。 1. 装 CLI(预检扫描器) 装完就可以在装任何 Harness 插件 之前 先扫一遍: 验证: 不想链到全局的话,在仓库里直接跑: 2. 装进 DeepSeek Harness(运行时护栏) 先有可用的 dsh 。用 本地目录 安装,不要先 allowBuilds 去跑未知 git 包的 prepare : 装好后重启 dsh web (或对应 profile)。默认策略是 balanced 。 自定义策略可以放在: 示例见 examples/policy/balanced.yaml。 3. 立刻试一下 process 夹具会报 HIGH / REVIEW BEFORE INSTALLING 。 干净包显示 NO HIGH-RISK FINDINGS DETECTED ——这不是「SAFE」,静态扫描不能证明代码安全。 不要这样装 git 安装拿到的是源码,不是编好的产物。官方 Harness 也写了: allowBuilds 等于允许安装期在你机器上跑代码。 要走 git,先扫再 pin commit: 这不是一个普通 Harness 插件 安装阶段的恶意行为,不能靠「装完才加载」的插件来拦。 dsh-shield 因此是 两层 ,共用同一套安全模型: 层 是什么 何时生效 预检 CLI dsh-shield scan 下载 / 解包 / 解析 / 检查。 绝不执行待扫描包 在 dsh plugin add 之前 运行时插件 挂在官方 tools/pre-execute 与 ctx.tools.guard() 上 每一次工具 / MCP 调用 产品能力就六个词: 它做的是 风险发现、策略执行、信任元数据、人工审批、可审计性 。 它不是「完美安全」,也不会声称 100% 防住 Prompt Injection。 为什么需要它 DeepSeek Harness( dsh )里,插件、MCP、内置工具都跑在宿主机 Node 进程权限下。 用户用 dsh plugin add github:someone/plugin 安装插件时,底层是 pnpm 。 prepare / preinstall 这类 lifecycle 脚本,会在任何 Harness 插件 apply() 之前执行。 运行时,模型可以调用 mcp ,把本地文件、密钥、客户资料送出本机。 dsh-shield 卡在这些边界上: - 安装插件之前 - 运行插件期间 - 调用 MCP 之前 - 数据离开本机之前 - 执行高风险 Tool…
在 GitHub 查看完整 README →分类
🎨 Best DeepSeek Harness Design Plugin. The open-source Claude Design alternative. 🖥️ Local-first desktop app. 🖼️ Your coding agent becomes the design engine: prototypes, landing pages, dashboards, slides, images & video — real files, HTML/PDF/PPTX/MP4 export. 🤖 Claude Code / Codex / Cursor / DeepSeek Harness / OpenCode & 20+ CLIs via BYOK.
★ 87,271
volcengine/OpenVikingSelf-evolving Context Database for AI Agents. Unify Agent Memory, Knowledge RAG and Skills.
★ 28,588
titanwings/colleague-skill将冰冷的离别化为温暖的 Skill,欢迎加入数字生命1.0!Transforming cold farewells into warm skills? It's giving rebirth era. Welcome to Digital Life 1.0. 🫶
★ 22,692