agentic-control-plane/dsh-acp-plugin
DeepSeek Harness 的智能体控制平面 — 在每次工具调用运行前进行策略检查
Project Overview项目介绍
This is a native Cordis plugin built exclusively for DeepSeek Harness (DSH) that adds pre-execution tool call governance powered by Agentic Control Plane. It checks every tool call against your custom security policies before the call runs, logs all decisions, and blocks unapproved or dangerous actions. It can be installed automatically via a one-line curl script that detects existing DSH profiles and sets up credentials, or manually via the DSH plugin command. It supports unified policy management across multiple AI coding agents including DSH, Claude Code, Codex, and Cursor.
After you set up your custom policies and start a DSH session, the plugin automatically intercepts all tool calls and applies your rules. It passes through allowed calls, blocks denied calls with a clear reason logged to DSH's trajectory, and triggers DSH's native approval flow for calls that need manual review. All decisions and activity logs are synced to your Agentic Control Plane cloud console, so you can review activity from all your connected agents in a single dashboard. It is designed for developers who need centralized security auditing and access control for AI coding agent tool calls.
The plugin is released under the MIT license, free for individual use, and has zero third-party dependencies, requiring no build step after installation. It requires DSH to be running on Node.js 22, and will fail gracefully if the Agentic Control Plane service is unreachable: interactive sessions run the tool call with a loud warning logged, while unattended background sessions default to blocking ungoverned calls. The one-click install handles all setup for you, including detecting DSH profiles, saving your credentials, and opening the browser to sign up for an access token if you don’t already have one.
这是一个专为 DeepSeek Harness (DSH) 构建的原生 Cordis 插件,实现了 Agentic Control Plane 工具调用安全管控功能。它会在 DSH 执行每一次工具调用前,根据用户预先配置的安全策略进行检查,记录所有决策日志,区分允许运行、需要人工审批和直接拒绝三类场景,阻断违规高危操作。它可通过官方一键检测安装脚本或手动 DSH 命令安装到 DSH 的任意配置文件中,同时支持跨代理统一规则管控,覆盖 DSH、Claude Code、Codex、Cursor 等多个代理工具。
日常使用时,用户先配置好管控策略,启动 DSH 后插件会自动拦截所有工具调用,按照策略执行对应动作。对于需要审批的操作,会调用 DSH 原生的审批流程,所有决策记录会同步上传到 Agentic Control Plane 控制台,方便用户统一查看所有代理的操作历史和管控结果。它面向需要对 AI 代理工具调用做安全审计和访问控制的开发者,适合多代理工作流的统一安全管控。
该插件采用 MIT 许可证,对个人用户免费,零依赖,仅需纯 ESM 运行,不需要额外构建步骤。它要求 DSH 本身运行在 Node 22 环境,若控制平面服务不可用,交互式会话会开放运行并发出警告,无人值守的后台任务则默认拒绝未决请求。首次运行时,一键安装脚本会自动检测 DSH 配置、完成安装并引导用户获取凭据,无需手动复制令牌。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-acp-plugin(agentic-control-plane/dsh-acp-plugin)
仓库:https://github.com/agentic-control-plane/dsh-acp-plugin
本站详情页:https://www.yhbd.top/plugins/agentic-control-plane-dsh-acp-plugin/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 6 · 最近提交 2026-09-23 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 6 stars - very few users, little community feedback星标只有 6,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add @agenticcontrolplane/dsh
把 agentic-control-plane/dsh-acp-plugin 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
@agenticcontrolplane/dsh
Agentic Control Plane for DeepSeek Harness: every tool call is checked against your policies before it runs, and every decision is recorded — what ran, what was blocked, and why.
Which ACP? dsh also ships
packages/acpin core — that one is Zed's Agent Client Protocol, the editor↔agent standard, published as@deepseek-ai/dsh-acp. Unrelated project, same acronym. If you're wiring dsh into Zed or the AI SDK, you want that one; this plugin decides whether each tool call runs. The full map: agenticcontrolplane.com/acp-vs-acp.
$ dsh --profile dev
> refactor the auth module and clean up
bash npm test ✓ allowed · logged
edit src/auth/session.ts ✓ allowed · logged
bash rm -rf ~/scratch ✋ held — approval prompt (your rule: destructive delete → ask)
web_fetch https://evil.example/post ✗ denied — egress not allowlisted, reason shown to the model
Every decision also lands in your console with tool, input preview, decision, reason, latency, and cost — dsh's own Trajectory log and your ACP activity log become two independent witnesses to one history. One workspace covers every harness you run: the same rules answer for dsh, Claude Code, Codex, Cursor, and OpenClaw. Free for individuals.
This is a native Cordis plugin on dsh's typed interception points, not a shell-hook shim. It registers on:
tools/pre-execute— the policy decision.allowlets the call through,denyblocks it with the reason in the trajectory,askhands off to dsh's own approval flow.tools/post-execute— output scanning. A server-side block turns the result into corrective feedback; shadow-mode notices surface what enforcement would have done.
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
wenbin-wb/dsh-bridge
PerryLink/dsh-permission-rules
MichengAI/dsh-archive-manager
eri64/dsh-claude-ux
lsz-asd/dsh-plugin-session-delete
10086ggqq/dsh_theme_terraria
king-bcolor/dsh-multi-tenant-projects