dsh-web-search-ddg
aooyoo
Zero-token DuckDuckGo search provider for the DeepSeek Harness (DSH) web seam — local headless browser, no API key, no m…
PROJECT TOPICS
PROJECT README
Runtime dangerous-operation policy, canonical output redaction, and security-review workflow for DeepSeek Harness.
The installable v0.1.2 release targets DSH 0.1.0-rc.6. This project currently distributes prebuilt packages through GitHub Releases and is not published on npm.
tools/pre-execute waterfall classifies dangerous shell, SQL, and structured file-write arguments as deny, ask, or unchanged.standard, strict, and permissive profiles provide different approval levels while retaining non-negotiable deny rules.deny or ask decisions.tools/post-execute waterfall redacts common credentials from canonical JSON results, failures, rendered text, and block feedback./security-review loads a bundled, read-only security-review skill.The MVP is not a process sandbox, authorization system, data-loss-prevention service, or substitute for the provider policies mounted below it.
The built-in rules deny recursive forced deletion of root or home paths, network-response pipes into shells, raw writes to /dev, and writes to /etc. Force pushes, destructive SQL, and other recursive forced deletions ask for approval. Strict mode additionally asks for sudo; permissive mode retains only deny rules.
Guardian always delegates through next(). When another policy listener returns a decision, the most restrictive result wins: deny outranks ask, which outranks allow.
Built-in patterns cover AWS access-key IDs, GitHub tokens, sk- API keys, PEM private-key blocks, and common credential assignments. Redaction is applied to the canonical JSON value when one exists, preserving arrays, objects, numbers, booleans, and null values. This prevents Code Mode and downstream renderers from retaining an unredacted value behind safe-looking display text.
Logs contain only the tool name, match count, and redaction labels. The plugin does not append custom session events because the current external plugin API does not expose an ignorable event envelope; emitting a required unknown event would make old sessions unreadable after uninstall.
The package currently targets DSH 0.1.0-rc.6 plugin APIs and Node.js ^22.19 || >=24.
dsh plugin --profile web add https://github.com/lonelymoon87/dsh-guardian/releases/download/v0.1.2/dsh-guardian-0.1.2.tgz
The release tarball is prebuilt and needs no build allowance. A pinned source install is also supported:
dsh plugin --profile web add github:lonelymoon87/dsh-guardian#v0.1.2
The source install runs this package's prepare build. pnpm 10 and later reject it until the profile allowlists the exact package key printed by the failed command; apply that instruction and rerun the same dsh plugin add command. Replace web with headless to install into the one-shot agent profile.
To upgrade, rerun dsh plugin add with the newer release URL. To uninstall:
dsh plugin --profile web remove dsh-guardian
- id: guardian
name: dsh-guardian
config:
profile: standard
rules:
- name: production-host
pattern: production\\.internal
action: ask
reason: production target requires review
redaction:
enabled: true
patterns:
- label: internal-token
pattern: INT_[A-Z0-9]{12}
Regular-expression flags may contain only i, m, s, and u. Invalid expressions and labels fail during plugin loading.
The tests cover positive and negative cases for every built-in rule, structured paths, profile behavior, downstream policy composition, nested canonical values, custom credentials, block feedback, split text blocks, disabled redaction, command dispatch, and invalid configuration.
dsh --dump-config.@deepseek-ai/dsh@latest.CLASSIFICATION EVIDENCE
系统优先读取 GitHub Topics,再与站内分类词典和词根规则比对。