safety 4
Declarative Claude Code-style permission rules plus a Codex-style process-level network policy for DeepSeek Harness: ordered allow/deny/ask rules with tool-name, argument (glob/regex), workspace-path, and network-target (domain/ip/port/scheme) matching on
dsh plugin add dsh-permission-rulesSelf-protection guardrails for the DeepSeek Harness: protected-path interception, backup-before-destroy, CLI self-recovery commands, and strict sandbox defaulting
dsh plugin add dsh-safety-netAuto-reject unanswered permission requests with a model-visible timeout notice
dsh plugin add @jiesou/dsh-timeout-auto-rejectInstallation safety gate & data-protection guard for DeepSeek Harness: 60 static signature rules (31 high/24 medium/5 low) scan plugin sources for malicious install scripts, credential theft, obfuscation, persistence and network callbacks before 'dsh plug
dsh plugin add dsh-plugin-gate