dsh-acp-plugin
DeepSeek Harness 的 Agentic Control Plane:每次工具调用执行前按你的策略检查,并持久记录允许了什么、为什么
agentic-control-plane
@agentic-control-plane
⬇ 1
★ 2
main
安装
dsh plugin --profile web add github:agentic-control-plane/dsh-acp-plugin
需要可复现安装时,可在仓库后追加 #commit 固定提交。
DeepSeek Harness 的 Agentic Control Plane:每次工具调用执行前按你的策略检查,并持久记录允许了什么、为什么
该插件未提供要点说明,请参考仓库 README。
agent-securitydeepseek-harnessdsh-plugin
- 安装并启动 DeepSeek Harness:
npx @deepseek-ai/dsh web - 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
- 用 dsh plugins list 确认已安装,必要时重启 Harness 生效
插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。
| 代码仓库 | github.com/agentic-control-plane/dsh-acp-plugin |
| 许可证 | MIT |
| 主要语言 | main |
| 下载量 | 1 |
| GitHub 星标 | 2 |
| 最近推送 | 2026-08-14 |
| 收录日期 | 2026-09-19 |
| 分类 | 安全与权限 |
事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。
以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。
# dsh-plugin-acp
[Agentic Control Plane](https://agenticcontrolplane.com) for [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness): every tool call is checked against your policies before it runs, and every decision is recorded — what ran, what was blocked, and why.
This is a native Cordis plugin on dsh's typed interception points, not a shell-hook shim. It registers on:
- `tools/pre-execute` — the policy decision. `allow` lets the call through, `deny` blocks it with the reason in the trajectory, `ask` hands off to dsh's own approval flow.
- `tools/post-execute` — output scanning. A server-side block turns the result into corrective feedback; shadow-mode notices surface what enforcement *would* have done.
## Install
```sh
dsh plugin --profile add dsh-plugin-acp
export ACP_BEARER_TOKEN=gsk_... # or keep it in ~/.acp/credentials
dsh --profile
```
No build step, no dependencies, plain ESM. Installing from git works too (`dsh plugin add github:agentic-control-plane/dsh-acp-plugin`) and needs no build allowance.
Get a key at [cloud.agenticcontrolplane.com](https://cloud.agenticcontrolplane.com). No key? The plugin says so loudly and stays out of the way — it never bricks a session.
## Configuration
Override the row in your profile's `cordis.patch.yml`:
```yaml
- id: acp
name: dsh-plugin-acp
config:
governBase: https://govern.agenticcontrolplane.com # or your self-hosted gateway
agentTier: interactive # default: interactive when an approval service is mounted, background otherwise
timeoutMs: 4000
```
`ACP_GOVERN_BASE`, `ACP_BEARER_TOKEN`, `ACP_AGENT_TIER`, and `ACP_SHADOW=off` work as environment variables too.
## Failure posture
An outage of the control plane must not brick the harness, and a lapse in coverage must never be silent:
- **Interactive sessions fail open, loudly.** Gateway unreachable → the call proceeds, a `[ACP] ⚠ UNGOVERNED` warning is logged, and a line lands in `~/.acp/lapse.log`.
- **Unattended agents fail closed.** With nobody watching, the block is the safety net.
- Policy denies are unaffected — this posture only covers the inability to *ask* the policy.
In headless compositions with no approval service mounted, dsh itself resolves `ask` to deny — unattended runs cannot self-approve.
## Two things to know
- dsh's `packages/acp` is Zed's Agent Client Protocol — an unrelated project that shares an acronym. This plugin is the Agentic Control Plane.
- Already running our Claude Code hook? dsh's `@deepseek-ai/dsh-hooks-claude-code` bridge runs an unmodified `hooks.json`, so `govern.mjs` works today with zero new code — deny and ask are honored, but input rewriting is not. This native plugin is the recommended path.
## Test
```sh
npm test
```
MIT
数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。