jilian-dsh/dsh-rule-engine
Project Overview项目介绍
This is a native rule engine plugin built exclusively for DeepSeek Harness (DSH). It reads all user rules from ~/.dsh/AGENTS.md, which it treats as the single source of truth. It automatically parses rule attributes and enforcement levels, then enforces user-defined rules via tool guards, text detection, timing checks, and an audit log, instead of relying on a built-in generic security list. It is compatible with DSH versions from >=0.1.0-rc.3 <0.2.0, and has been fully tested and verified to work on DSH 0.1.5-rc.2. All unit tests, cold load probes, and 13 layers of verification checks pass on the latest version.
The plugin is designed for DSH users who prioritize rule enforcement and compliance. All rules are parsed dynamically from AGENTS.md, so you do not need to modify the plugin code when you add, remove, or edit your rules. You can explicitly bind an executor to a rule via a comment annotation in AGENTS.md or via a configuration override. You can also disable rules you do not want to use, and they will not trigger any enforcement until you re-enable them. Unbound rules only trigger self-verification prompts and are not forcibly blocked, and the plugin loads without errors even if you do not have an AGENTS.md file.
This project is released under the open source MIT license. It supports full customization of lexicons, detection patterns, and local integration settings via a user-owned rule-engine.json file. The project is currently in a working but actively developed state, with several features still incomplete, including cross-session authorization persistence and deep enforcement for complex process rules. To run the full test suite before contributing, you can execute npm test and node scripts/verify-all.mjs to check for code health and consistency. It is not an official DeepSeek product, so all use is at your own risk after testing.
这是专为 DeepSeek Harness (DSH) 开发的原生规则执行引擎插件,它以用户目录下的 ~/.dsh/AGENTS.md 作为唯一规则源,自动解析规则要素与执行等级,通过工具守卫、文本检测、时序检查和审计台账强制执行用户自定义规则,而非依赖内置通用安全清单。当前兼容 DSH 版本范围为 >=0.1.0-rc.3 <0.2.0,已在 DSH 0.1.5-rc.2 测试验证通过。
该插件面向重视规则执行管控的 DSH 用户,所有规则都从 AGENTS.md 动态解析,修改规则后无需重新编写插件代码。用户可以通过声明式绑定指定规则对应的执行器,也可禁用不用的规则,未声明绑定的规则默认仅做自证提示,不会强制拦截操作,无 AGENTS.md 也能正常零错加载。
本项目基于 MIT 许可证开源,支持用户自定义词表、检测规则和本地集成配置,目前仍处于可运行但需持续打磨的阶段,存在部分功能尚未完全实现,比如跨会话授权持久化、流程类规则深度执行等,欢迎社区提交 Issue 或 PR 贡献改进。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-rule-engine(jilian-dsh/dsh-rule-engine)
仓库:https://github.com/jilian-dsh/dsh-rule-engine
本站详情页:https://www.yhbd.top/plugins/jilian-dsh-dsh-rule-engine/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 3 · 最近提交 2026-09-23 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-rule-engine
把 jilian-dsh/dsh-rule-engine 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-rule-engine
项目背景
这个项目来自一个非常具体的个人需求:
- 作者是零编程基础用户,但极其重视规则的制定、执行、遵守与复盘。
- 作者发现:规则如果只写在文本里、靠模型“自觉”执行,会反复失效(例如时间词写错、内联命令违规、交付前漏验证等)。
- 因此核心思路是:规则的执行不能只靠自觉,要尽量靠插件在机制层强制。
- 本插件所有规则均从
AGENTS.md动态解析,规则增删改后无需重写插件。
当前实现基于已有的 AGENTS.md 规则体系拓展,社区暂无类似插件供参考(大概率为该等约束可能限制开发自由性,不适用于专业编程人员),可能存在大量不完备、误判或边界问题。欢迎任何使用者提出调整建议、提交 issue 或 PR。项目仍处于“可运行但需要持续打磨”的阶段。
这是什么
DSH 规则执行引擎 v3 的插件实现。它把 ~/.dsh/AGENTS.md 当作唯一真相源,自动解析规则四要素与执行等级,再通过「工具守卫 + 文本检测 + 时序检查 + 审计台账」执行你的规则——不是内置一套与用户无关的安全清单。
四层骨架:
- 容器:解析
AGENTS.md的全部规则(可生成理解产物); - 匹配机 + 工具守卫 + 文本检测:判断某次动作落在哪条规则上;
- 时序检查 + 授权询问:把“什么时候做的”纳入判定,必要时弹窗询问;
- 自证调度 + 命令面:对语义类规则做自证提示,并提供
/guard命令。
规则全部从 AGENTS.md 实时解析,规则增删改后无需重写插件。语义类判定按「词表只产嫌疑 → 模型裁决确认」两段走:只有裁决确认为违规才提醒;无真实用户消息的回合不检测、不投递。
当前版本
0.6.6(以 package.json 的 version 为准)。
使用指引
安装
本插件已按官方 bundle 规范打包,包内自带 cordis.patch.yml。推荐:
dsh plugin --profile web add dsh-rule-engine
或手动把 dsh-rule-engine 加入 profile 的 dsh.profile.bundles 数组,包内 cordis.patch.yml 会自动挂载插件行:
- insert:
- id: dsh-rule-engine
name: 'dsh-rule-engine'
从源码手动调试时也可以沿用 insert 方式挂载;正式安装建议走 bundle。
最低准备
- 一份规则文件:
~/.dsh/AGENTS.md(或你的DSH_HOME下的同名文件)。没有它也能用——引擎零错加载、零规则、零误拦。 - Node.js
>=22(见package.json的engines)。 - 无运行时依赖;两个 peer 依赖由 DSH 侧提供。
何时需要配置
默认零配置即可用。 只有下面两类需求才需要写 ~/.dsh/rule-engine.json:
- 想让引擎懂你的语言习惯(例如把中文词当作许可词、动作词);
- 想启用本机专属集成(统一入口脚本保护、手册/技能豁免、记忆沉淀链、追加受保护文件)。
配置在插件启动时读取;改完保存后重载插件(或重启 DSH)生效。命令面见下一章。
配置
两轨:通用层与个人层
| 层 | 在哪 | 内容 | 谁维护 |
|---|---|---|---|
| 通用层 | lib/(随包发布) |
机制 + 语言无关最小集 | 插件作者 |
| 个人层 | ~/.dsh/rule-engine.json |
你的语言/习惯词表、本机集成开关 | 你 |
一句话:代码里只有机制;中文与本机专属设置都写在 rule-engine.json。
键的取值语义
- 键缺省(不写)→ 用内置默认(通用最小集);
- 键存在 → 按键完全替换(不做合并,配置即真相);
- 写
{}或删键 → 回退内置默认。
个人层能配什么(示例一律占位名)
{
"lexicons": {
"approval": "确认|同意|可以",
"action_words": "执行|落盘|部署"
},
"patterns": {
"time_words": "今天|昨天|刚才",
"self_cert_hints": { "example": "占位词一|占位词二" }
},
"criticismPersonal": ["示例词一", "示例词二"],
"localIntegrations": {
"entryScript": "your-entry-script.mjs",
"protectedFiles": ["skills/your-manual/SKILL.md"],
"m8": { "enabled": true, "entryMarker": "your-entry-script.mjs" },
"manualExempt": {
"skills": ["your-manual", "your-planner"],
"paths": ["your-manual/SKILL.md"]
}
},
"qualityLedger": { "enabled": true, "window": 5 }
}
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
Vithrive/Deepseek-Harness-for-VS-Code
Minglink/dsh-infinite-gen-4
kenryu42/cc-safety-net
hyhmrright/brooks-lint
toby-bridges/api-relay-audit
hashgraph-online/hol-guard
SeaOf0/dsh-redteam-model
howmp/dsh-pentest