Safety harness plugin for DeepSeek Harness (DSH)
sugarxl/dsh-safety · skills
Safety harness plugin for DeepSeek Harness (DSH): execution-time guard, trash-based safedelete, composition snapshots & rollback, pre-restart validation.
★ 2GitHub stars
0Forks
2026-08-25Last updated
JavaScriptLanguage
MITLicense
Key features
- Execution-time guard (ctx.tools.guard) — denies destructive tool calls before they run.
- destructive agent calls are denied before they run, with an educational message explaining what the target is, why it matters, and what the sanctioned alternative is
- Requestingwhen a call is blocked, the denial message tells the agent to call safety_ask with the causality.
- DSH won't boot after a plugin change: run dsh-safety check to find mojibake / JSON / duplicate-id problems
- Recursive directory deletes (rm -r/-rf, Remove-Item -Recurse, rd /s, rmdir, shutil.rmtree, fs.rm recursive, require('fs').rmSync…) are denied by default and routed to safe_delete (trash, undoable).
Install command
dsh plugin --profile web add github:sugarxl/dsh-safety