dsh-policy-waiver-proof
Offline content-addressed proof that a temporary policy waiver stayed within approved bounds
305 results
Offline content-addressed proof that a temporary policy waiver stayed within approved bounds
Offline content-addressed evidence that an approved Windows control-plane change settled across required surfaces
Corner approval popup: answer pending permission requests from any session while the agent window is away
Blocks high-confidence secrets before dsh-TUI sends them to a model.
Offline content-addressed proof for supplied credential-retirement closure
DSH 权限预设 workspace-write++:工作区内写文件,可在设置里配置放行 Git Bash / PowerShell 等进程沙箱(修复 Windows ACL 下 MSYS 内存映射错误)。
DSH 规则执行引擎 v3:容器解析 AGENTS.md + 理解器 + 匹配机 + 执行框架
Plugin security inspector for the DeepSeek Harness web GUI: statically audits installed plugins (dangerous API patterns + dependency review), layers an AI (default-model) online audit, and renders a green/yellow/red report panel.
Approval-free writes into whitelisted directories: wraps ctx.fs.checkedTarget for write/edit, auto-approves bash escalations that touch whitelisted paths, with a Settings GUI. 白名单目录写入免审批(write/edit + bash),设置页可视化调整。
Audit a DSH profile for capabilities nothing consumes, and record completion claims with the evidence that supports them.
DeepSeek Harness MCP client bridge with OAuth 2.1, connection/discovery timeouts, environment-indirected secrets, optional indefinite reconnection, and a mcp_status diagnostic tool
Human intent verification and cryptographic action authorization for AI agents. AI can propose an action. Only a human can authorize it.
macOS Keychain credentials provider for DeepSeek Harness (dsh) — refs and records both stored in the login keychain, never in a plaintext file
Layered, approval-gated, auditable cross-session memory for DeepSeek Harness — a capability seam (ctx.memory service + local SQLite provider + memory tool + frozen snapshot injection), not another memory warehouse
Autonomous six-phase security audit engine for DSH: vendored cloudflare/security-audit-skill + sandboxed execution + subagent orchestration
DeepSeek Harness plugin: one model-facing `shell` tool whose shell is a user setting. Resolves and validates through the harness's own seams, and refuses to run when the selected shell cannot be confined.
DeepSeek Harness 发送前隐私检查:在你把手机号、身份证号、银行卡号或 API 密钥发给模型之前提醒你,并支持一键打码。
DSH memory plugin gated by the TypeSafe Jev decision model: mem_* tools whose every read/write is a typed judgement (choice/noul) — write gate, recall gate and a fail-closed injection gate with budget, audit log and restore/merge.
AI-reviewed auto-approval for DeepSeek Harness: judges each pending approval ask with one auxiliary model call before any human answerer runs, auto-grants the safe ones, and escalates everything else with the review analysis attached
Explain what a pending dsh approval will actually do, with one LLM call: an Explain button beside Allow/Reject plus the Host /explain command behind it
Feishu (Lark) OAuth login gate for the DeepSeek Harness web GUI.
dsh plugin: shows the model name the upstream actually reported for each assistant step, backfilling pi-ai replay metadata from a non-invasive fetch observer when the adapter omits it
Plays a Windows system notification sound when the agent opens a question dialog, when it asks for permission, and when a conversation turn ends. DSH 组合包:弹出选项卡时、请求权限时、对话回合结束时播放系统提示音。
GitHub operations for DeepSeek Harness: releases, tags, a guarded generic API pass-through, workflow runs, secrets and sanitized mirror publication.