dsh-security-requirements
SQL 优化模式:EXPLAIN 分析、索引策略、N+1 解决、查询改写。受 wshobson/agents(38k★ MIT)启发。
265 results
SQL 优化模式:EXPLAIN 分析、索引策略、N+1 解决、查询改写。受 wshobson/agents(38k★ MIT)启发。
SQL 优化模式:EXPLAIN 分析、索引策略、N+1 解决、查询改写。受 wshobson/agents(38k★ MIT)启发。
Deny an AI agent access to .env files, credential stores, keys and any path you hide — across file tools, shell commands, search selectors and run_code. A DeepSeek Harness (dsh) plugin.
Allowlisted git execution for DeepSeek Harness: a model-facing git tool that runs outside the file sandbox, with a settings page where the user ticks which git subcommands are permitted and, per path, which reads and writes are allowed, prompted or refused
Plug/unplug any DeepSeek Harness plugin cleanly: list every mounted layer, disable/enable without deleting, remove bundles + patch rows + dependencies in one pass, and audit for orphaned/dangling plugin state. Zero runtime dependencies; read-only by defau
Tolerate redundant sandbox_permissions requests: a tool call asking to escalate to a mode that is not strictly wider than the session's standing mode runs as-is at the standing mode instead of failing with "not strictly wider". Genuine escalations still route through the approval flow.
北极星 (Polaris):通用能力聚合与择优进化层——异构嗅探、双轨竞技场、SLSA 出处、不可变索引与语义调度。
Codex-style auto reviewer (approve for me) permission mode for DSH
Natural-language driven dynamic assembler for DeepSeek Harness (dsh): discovers plugins at runtime (official-first, third-party optional), generates assembly plans, and loads them via Cordis — with built-in security audit gates for unofficial plugins.
Verification toolkit for DeepSeek Harness agents: evidence-based claim checking against workspace files with line citations, config validation (JSON/YAML), HTTP URL status checks, npm package checks, GitHub repo submission-readiness checks, and batch verification with bounded concurrency and per-result confidence grading
Corner approval popup: answer pending permission requests from any session while the agent window is away
DeepSeek Harness MCP client bridge with OAuth 2.1, connection/discovery timeouts, environment-indirected secrets, optional indefinite reconnection, and a mcp_status diagnostic tool
Layered, approval-gated, auditable cross-session memory for DeepSeek Harness — a capability seam (ctx.memory service + local SQLite provider + memory tool + frozen snapshot injection), not another memory warehouse
dsh-voredteam —— 单模式(网络安全模式)DSH 插件合集:黑板书 Fact/Intent/Hint 引擎 + 总控派发专业子 agent + 作战面板/设置 两个面板 + 唯一门禁(禁 DDoS/禁爆破/模糊测试低频)。
DeepSeek Harness plugin: one model-facing `shell` tool whose shell is a user setting. Resolves and validates through the harness's own seams, and refuses to run when the selected shell cannot be confined.
DSH memory plugin gated by the TypeSafe Jev decision model: mem_* tools whose every read/write is a typed judgement (choice/noul) — write gate, recall gate and a fail-closed injection gate with budget, audit log and restore/merge.
Explain what a pending dsh approval will actually do, with one LLM call: an Explain button beside Allow/Reject plus the Host /explain command behind it
Preset-agnostic global tool masking for DeepSeek Harness — presentation-layer filtering plus execution-layer guard veto, with a WebUI editor and self-protection gate.
Feishu (Lark) OAuth login gate for the DeepSeek Harness web GUI.
Plays a Windows system notification sound when the agent opens a question dialog, when it asks for permission, and when a conversation turn ends. DSH 组合包:弹出选项卡时、请求权限时、对话回合结束时播放系统提示音。
Isolated private chat with reversible context selection and retained audit records for DSH Web
Bitwarden/Vaultwarden credentials in every DSH session: vault tools + proactive prompt guidance + a settings card for the master password.
Fix and diagnose DeepSeek Harness on native Windows. Official PowerShell, Workspace Write, shortcuts, and legacy preset repair. No WSL.
Password gate for dsh-web: opening the web port requires a username/password login; account credentials are stored salted+scrypt-hashed and AES-256-GCM encrypted in a local config file under $DSH_HOME. Host-only cordis plugin, no dsh source changes.