julescules / dsh-windows-workspace-guard

已收录

Windows workspace, immutable-path, Git-risk, approval, and audit guard for DeepSeek Harness.

main其他 查看源代码

安装

npx -y @deepseek-ai/dsh plugin --profile web add github:julescules/dsh-windows-workspace-guard

此安装命令根据 GitHub 仓库地址生成,是未经验证的安装起点。

README

维护者编写的文档快照。

在 GitHub 查看 ↗
提交版本 217173c同步于 2026年8月18日

dsh-windows-workspace-guard

中文 | English

[!IMPORTANT] Unofficial community plugin. Independently developed and maintained; not reviewed or endorsed by DeepSeek.

Safety policy for DeepSeek Harness on Windows. It checks model-issued PowerShell calls before execution and protects workspaces, original files, Windows system state, processes, and Git recovery paths.

Policy decisions: allow, ask, and hard block

What it does

  • keeps destructive PowerShell targets inside trusted workspace roots;
  • makes original/, signing files, or any configured path immutable;
  • reviews risky Git commands such as reset --hard, clean -fdx, worktree restore, stash deletion, and force push;
  • hard-blocks registry, service, scheduled-task, ACL/ownership, junction/symlink, and nested-shell mutations;
  • reviews process termination and supports configurable guarded tool names;
  • supports block, one-time ask, and audit-only report modes;
  • adds a live settings card to the official DSH plugin settings page (DSH v0.1.0-rc.7 or newer);
  • writes optional append-only JSONL audit records with redacted previews and command hashes;
  • permanently blocks disk operations, broad roots, encoded execution, System.IO bypasses, and protected paths.

Install

dsh plugin --profile web add github:julescules/dsh-windows-workspace-guard#v0.3.0
dsh --profile web --dump-config

Restart DSH after installation.

- id: windows-workspace-guard
  name: dsh-windows-workspace-guard
  config:
    mode: ask
    workspaceRoots:
      - 'D:\projects\current-project'
    protectedPaths:
      - 'D:\projects\current-project\original'
    guardGit: true
    guardSystem: true
    guardProcesses: true
    auditPath: 'D:\projects\current-project\operation_logs\dsh-guard.audit.jsonl'

On DSH v0.1.0-rc.7 or newer, the same fields can be changed from Settings → Plugins → Windows Workspace Guard and apply immediately without restarting the plugin.

Resultblockaskreport
Safeallowallowallow
Needs reviewdenyask onceallow + audit
Hard blockdenydenydeny

Hard blocks cannot be bypassed by allowExact or report mode.

Check without running

The plugin registers windows_workspace_guard_check. The agent can inspect a command and receive stable PASS, REVIEW, or FAIL JSON without executing it.

Verified

  • 28/28 unit, browser-contract, and adversarial tests pass;
  • official dsh.bundle.patch package shape;
  • official keyed settings.plugin.item card and settingsScope live-config contract;
  • official tools/pre-execute allow/deny/ask contract;
  • package contains no install-time build step;
  • UTF-8 append-only audit with common secret redaction.
npm run check
npm pack --dry-run

Limits

  • Static inspection is not a complete PowerShell parser or OS sandbox.
  • pwsh is intercepted by default; add other PowerShell tool names in toolNames.
  • Existing junction/symlink targets are not resolved against the live filesystem; creation is hard-blocked.
  • DeepSeek Harness is in developer preview; pin a reviewed release or commit.

License

MIT

项目文件与信号

以下项目是目录快照中检测到的公开仓库信号。

测试已检测
文档已检测

仓库信息

开发语言
JavaScript
许可证
MIT
最新发布
v0.3.0
最后更新
2026年8月18日 03:38

谨慎安装

请检查源代码、权限、生命周期脚本、依赖与网络访问;不受信任的插件应先在隔离环境中测试。