policy 8
Declarative Claude Code-style permission rules plus a Codex-style process-level network policy for DeepSeek Harness: ordered allow/deny/ask rules with tool-name, argument (glob/regex), workspace-path, and network-target (domain/ip/port/scheme) matching on
dsh plugin add dsh-permission-rulesCommitment write-gate for AI coding agents: two-tier (deterministic + LLM judge) pre-execution policy. Engine-agnostic core with a DeepSeek Harness (dsh) adapter.
dsh plugin add dsh-write-gateEnforces your comment policy at write time, inside DeepSeek Harness, Pi, and oh-my-pi. Reads the policy from your AGENTS.md or CLAUDE.md, blocks violating writes, and re-injects the policy verbatim so the model stops drifting from it.
dsh plugin add stupid-commentsPrompt hygiene, observability, and policy middleware for DeepSeek Harness
dsh plugin add @yadsh/dsh-prompt-firewallOperator policy and a tamper-evident decision log for DeepSeek Harness. Every tool call judged against your organisation's pack, and written down.
dsh plugin add prae-gateDeclarative tool-call permission control for DeepSeek Harness β allow/deny/ask rules over tools, paths and commands, fail-closed by default, with JSONL audit log.
dsh plugin add dsh-tool-policyMiOpIIk fail-closed route requirement for the native DSH subagent tool
dsh plugin add dsh-miopiik-policyThe authority layer for agentic AI, as a DeepSeek Harness plugin. Governs every tool call against your business rules via the TapPass /v1/govern policy decision point.
dsh plugin add @tappass/dsh-governance