Dsh Tool Policy
Drifter-yh/dsh-tool-policy · skills
Declarative deny-by-default tool policy plugin for DeepSeek Harness.
★ 4GitHub stars
0Forks
2026-08-27Last updated
TypeScriptLanguage
MITLicense
Key features
- dsh-tool-policy does not implement sandboxing, capability enforcement, shell semantic analysis, or equivalent-operation detection.
- allow selected tool namespaces or families such as read_
- Harness sandbox — capability enforcement: Can this agent perform this class of operation at all?
- A deny rule makes the matched call unavailable, not destructive behavior impossible in general.
- It does not rewrite arguments or execute tool bodies.
Requirements
- The plugin targets the Harness API range =0.1.0-rc.5 =4.0.1 <5.
- It is currently validated against the published 0.1.1-rc.2 registry packages and upstream tag dsh-v0.1.1-rc.2 at commit b150a551b8d465e31e418e1b2eaf5e79bbb7d28e.
Install command
dsh plugin --profile web add github:Drifter-yh/dsh-tool-policy