@nanmicoder/dsh-auto-mode
Sandbox-first automatic permission policy for DeepSeek Harness
21 results
Sandbox-first automatic permission policy for DeepSeek Harness
Provenance-aware execution and output security for DeepSeek Harness, with visible receipts and trusted declassification.
Agentic Control Plane for DeepSeek Harness — check every tool call against your policies before it runs, and keep a durable record of what was allowed and why.
Allow, ask, or deny DeepSeek Harness tool calls before execution
DeepSeek Harness plugin for SecurStack security scans, policy checks, doctor diagnostics, and JSON CLI results.
AI approval answerer using the unified ctx.llm route with fail-closed local policy checks
Content-addressed, value-redacted policy drift evidence for DeepSeek Harness
DeepSeek Harness bundle for the official Wolfram/AgentTools MCP server: kernel discovery, a transparent stdio supervisor that owns only its own Wolfram process tree, and a native DSH permission policy over the Wolfram tools.
Fail-closed DSH compatibility guard for redundant GPT/Codex sandbox escalation arguments
DeepSeek Harness (DSH) host-layer plugin: detects and auto-fixes Windows PowerShell command syntax mistakes — bash constructs, broken line continuations, pasted prompts, CRLF pollution — then executes the corrected command through the host shell seam under the normal sandbox/approval policy
Seam-aligned background command execution for DeepSeek Harness — run_command via ctx.shell under the session sandbox policy, auto-promotion into ctx.jobs
Declarative Claude Code-style permission rules plus a Codex-style process-level network policy for DeepSeek Harness: ordered allow/deny/ask rules with tool-name, argument (glob/regex), workspace-path, and network-target (domain/ip/port/scheme) matching on
Agent governance suite for DeepSeek Harness (enterprise companion): policy-based tool gating (allow/deny/ask), structured JSONL audit trail, and per-agent token quotas against the host token meter — state under $DSH_HOME/gov
A DSH profile bundle that ships the Telegram ↔ DeepSeek Harness bridge as a model-callable install tool. Requires the session sandbox policy to allow subprocess TLS to api.telegram.org (danger-full-access in the default sandbox policy).
Security, Trust & Policy Layer for DeepSeek Harness. Don't trust your agent's tools. Verify them.
Egress policy for DeepSeek Harness: a host allowlist on web_fetch and web_search enforced at connect time, audit-mode by default, with OCSF Network Activity records
A fail-closed, auditable approval policy plugin for DeepSeek Harness
Guard DeepSeek Harness PowerShell, file, image, and search tools on Windows with workspace, credential, approval, and audit policy.
DSH plugin installation gate ported from Codex safe materialization and Claude Code marketplace validation/policy scanning
Offline content-addressed proof that a temporary policy waiver stayed within approved bounds
Configurable auto-approval for DeepSeek Harness: intercepts approval/request and answers allowed-once/rejected by policy (allow-all / allowlist / deny-always), with a full audit log — so the human is only asked when the policy says so.