cdxiaodong/dsh-guardian

Plugin插件 Native原生 ⭐ 3 Approval & Security审批与安全

Project Overview项目介绍

This is a native security plugin built exclusively for DeepSeek Harness, based on the Cordis composable meta-kernel. Its core function is to run a security check before every tool call made by the agent, and either block dangerous operations automatically or require manual approval from the user. It ships with five separate detection engines that cover dangerous commands, credential access protection, secret key leaks, SSRF attacks, and prompt injection/tool poisoning. It also adds an optional path sandbox and a weighted risk scoring engine to reduce false positive detection rates, and draws rule inspiration from multiple trusted open source projects.

LLM agents like DeepSeek Harness can autonomously run shell commands, read and write files, and make network requests. Without a safety layer, agents can be led astray by prompt injection, tool poisoning, or model misjudgment, leading to accidental data deletion, credential theft, or secret leaks. This plugin acts as a runtime safety net that intervenes before any risky action completes. It sorts detected risks into three tiers: automatic deny, manual approval required, or audit logging only, matching the risk level to the response. It is intended for any DSH user that wants to add a safety layer to their agent workflows.

To install the plugin, run the command dsh plugin --profile web add github:cdxiaodong/dsh-guardian via the DSH CLI. Users can customize the plugin by setting allowed root directories for the path sandbox, toggling individual detection engines on or off, and connecting a custom UI for manual approval prompts. The project is released under the open source MIT license. The plugin’s documentation notes that all heuristic and regex-based safety guards can be bypassed by adversarial samples, so it only reduces risk rather than eliminating it entirely, and cannot replace manual confirmation and least-privilege sandboxes.

这是一款专为 DeepSeek Harness 开发的原生安全插件,基于 Cordis 时空可组合元内核构建,核心能力是在 Agent 每次调用工具前执行安全审查,对命中危险规则的操作直接拦截或要求人工确认。它内置五大检测引擎,涵盖危险命令检测、凭据保护、密钥泄露检测、内网/元数据端点 SSRF 检测、提示注入与工具投毒检测,还额外提供路径沙箱和风险评分引擎。

该插件解决了 LLM Agent 自主执行 shell 命令、读写文件时的安全风险问题,当 Agent 被提示注入、工具投毒或模型误判带偏时,可能意外执行高危操作导致数据泄露或损坏,此插件就是 Agent 运行时的安全网。工作流程为:Agent 发起工具调用请求后,插件先执行前置审查,根据风险评分分级处置,分为直接拒绝、要求人工批准和仅记录审计三种处理方式。

安装方式为通过 DSH CLI 执行 dsh plugin --profile web add github:cdxiaodong/dsh-guardian,用户也可自定义配置白名单根目录、开启或关闭各检测引擎,接入自定义人工确认 UI。项目采用 MIT 许可证开源,同时提示所有启发式护栏都可能被对抗样本绕过,本插件仅用于降低风险,不能替代人在环确认和最小权限沙箱。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 2 warnings2 项注意
  • No license declared - all rights reserved by default; ask the author before commercial use or redistribution未声明开源许可证 —— 默认「保留所有权利」,商用或再分发前先问作者
  • Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:cdxiaodong/dsh-guardian

把 cdxiaodong/dsh-guardian 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-guardian

Agent 安全护栏 · 基于 Cordis 时空可组合元内核的 DeepSeek Harness 插件。 在 Agent 每次工具调用前做安全审查,命中危险即拦截或要求人工确认。

CI


🎯 解决什么问题

LLM Agent(Claude Code / DeepSeek Harness)能自主执行 shell、读写文件、发网络请求。一旦被提示注入、工具投毒或模型误判带偏,可能在你不知情时 rm -rf、读取 .ssh/id_rsa、把密钥外泄到远程。本插件是一道运行时安全网:

Agent 想执行工具 → guardian/check 前置审查 → 命中规则 → 拦截 / 人工批准 → 才放行

🛡️ 五大检测引擎

引擎 检测内容 借鉴来源
CMD/INJ 危险命令 rm -rf、dd、mkfs、fork炸弹、反弹shell、管道执行、提权 Sigma 规则、PayloadsAllTheThings
CRED 凭据保护 读 .ssh/.aws/.env/kubeconfig、/etc/shadow mcp-safeguard CRED 系列
SECRET 密钥泄露 AWS/GitHub/OpenAI/Anthropic/Slack/Stripe 等 25+ 种密钥正则 + Shannon 熵过滤降误报 gitleaks、trufflehog
SSRF 网络目标 云 metadata(169.254.169.254)、内网网段、file://、gopher:// mcp-safeguard SS 系列
PI/TP 提示注入+工具投毒 ignore previous instructions、DAN越狱、零宽字符、HTML注释藏指令、瞒用户指令 Rebuff、LLM Guard、Vigil

外加:

  • 路径沙箱(guardian/path):realpath 解析 + 白名单根目录 + 编码变体解码 + 空字节截断检测——比纯正则可靠
  • 风险评分引擎(risk.ts):多信号并集概率式加权成 0~1 分,按阈值分级处置(deny/block/warn/allow)

🚦 三级处置

级别 行为 例子
deny 直接拒绝 反弹shell、mkfs、读 /etc/shadow、明文密钥
block 需人工确认(走 guardian/approve) rm -rf ~、读 .ssh、curl 上传文件
log 仅记录审计 路径穿越、读取 shell history

📦 安装

dsh plugin --profile web add github:cdxiaodong/dsh-guardian

🚀 用法

import { Context } from 'cordis'
import * as guardian from 'dsh-guardian'

const ctx = new Context()
ctx.plugin(guardian, {
  allowedRoots: ['/home/user/workspace'],   // 可选:文件访问沙箱白名单
  scanSecrets: true, scanSSRF: true,        // 开关各引擎
})

// ① 接入人工批准(无此监听器时 block 级默认拒绝)
ctx.on('guardian/approve', async ({ tool, rule, snippet }) => {
  const ok = await confirm(`${rule.reason}:${snippet}`)  // 你的 UI 弹窗
  return { approved: ok }
})

// ② 工具调用前审查(同步短路)
const r = ctx.bail('guardian/check', toolName, args)
if (r && r.intercepted) throw new Error(`已拦截:${r.reason}`)

// ③ 文件访问前校验路径
const v = ctx.bail('guardian/path', filePath)
if (v && v.safe === false) throw new Error(`路径被拦截:${v.reason}`)

// ④ 查审计日志
console.log(ctx.guardian.readAudit(20))

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-workspace-explorer 下一个 Next dsh-negative-ledger →