Runtime tool policy
lonelymoon87/dsh-guardian · skills
Runtime tool policy, dangerous-command guard, and output redaction for DeepSeek Harness.
★ 2GitHub stars
0Forks
2026-08-21Last updated
TypeScriptLanguage
MITLicense
Key features
- A tools/pre-execute waterfall classifies dangerous shell, SQL, and structured file-write arguments as deny, ask, or unchanged.
- Guardian inspects tool names, arguments, canonical results, and rendered output inside the current DSH process.
- standard, strict, and permissive profiles provide different approval levels while retaining non-negotiable deny rules.
- Custom regular-expression rules add deployment-specific deny or ask decisions.
Install command
dsh plugin --profile web add github:lonelymoon87/dsh-guardian