Guard plugin
Khorsheed/dsh-ankh-guard · skills
The Guard plug-in (dsh plug-in) prevents the Agent from modifying itself and causing the service to crash: the green build credentials are bound to git HEAD, and modifications do not allow restart
★ 7GitHub stars
0Forks
2026-08-16Last updated
TypeScriptLanguage
MITLicense
Key features
- A — Pure guardno external supervisor
- The instance uses supervise to adopt a watchdog before restarting itself.
- Easiest, but nothing to pull back the host after an unexpected crash.
- B — Pure launchd/systemdlauncher owns ports with KeepAlive.
- Resistant to crashes, but self-modifying restarts are not subject to credential gates.
Requirements
- The gate is forced in restart/supervise, but not in launcher yet - both will refuse to stop the instance when rejected, but manual kill/launch that bypasses guard can still be bypassed
- The watchdog (P2) is an automatic safety net that makes bypassed gates recoverable.
Install command
dsh plugin --profile web add github:Khorsheed/dsh-ankh-guard