DSH | Windows Workspace Guard | Windows 防误删、凭据外泄与越界变更 #2429
Replies: 8 comments
|
Windows 工作区/审批/审计防护——Windows 安全工具链又补一块(之前沙箱/权限都是 macOS 优先)。 已收录进手册第 13 章配套工具 + 生态章节:https://github.com/Electricitysheep/dsh-handbook/blob/main/docs/13-security.md |
|
已更新到 v0.3.0,适配 DSH 这次新增了实时设置、可配置工具名,并补齐注册表、服务、计划任务、ACL/所有权、junction/symlink、嵌套 PowerShell、终止进程和更多 Git 恢复路径防护。28/28 测试通过,Release 包也完成了独立安装与主模块加载验证。 版本说明与下载:https://github.com/julescules/dsh-windows-workspace-guard/releases/tag/v0.3.0 |
|
v0.4.0 已发布,现已适配 DeepSeek Harness rc.8 的持久化 |
|
v0.5.0 已发布并通过 DeepSeek Harness |
|
v0.6.0 已发布。新增既有路径实时检查:执行变更前逐级检查目标前缀,遇到 Windows junction/symlink 或检查失败时强制阻断,并加入可实时配置的 |
|
你好,可以的
…---- 回复的原邮件 ----
| 发件人 | ***@***.***> |
| 发送日期 | 2026年08月24日 09:02 |
| 收件人 | deepseek-ai/deepseek-harness ***@***.***> |
| 抄送人 | julescules ***@***.***>,
Author ***@***.***> |
| 主题 | Re: [deepseek-ai/deepseek-harness] DSH | Windows Workspace Guard | Windows 工作区、审批与审计防护 (Discussion #2429) |
你的插件我可以收录吗? 挺好的。
欢迎来提PR 。
#4278
—
Reply to this email directly, view it on GitHub, or unsubscribe.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS and Android. Download it today!
You are receiving this because you authored the thread.Message ID: ***@***.***>
|
|
v0.8.0 已发布:新增官方 str_replace_editor 覆盖、覆盖率 Doctor、不可覆盖的越界路径硬阻断,以及 SHA-256 + SBOM。主楼已更新安装与验证结果。 |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Important
非官方社区项目,由社区成员独立开发和维护,未经 DeepSeek 官方审核或背书。
Unofficial community project; independently maintained and not reviewed or endorsed by DeepSeek.
项目:https://github.com/julescules/dsh-windows-workspace-guard
当前版本:v0.8.0 · DSHBase 已验证页面
DeepSeek Harness 的 Windows 安全护栏:在工具执行前保护工作区、原始素材、凭据与 Git 恢复路径。
v0.8.0 有什么用
pwsh与str_replace_editor,不是只检查 Shell。create / str_replace / insert / 敏感 view走结构化参数适配;不把文件正文写进策略预览。安装
升级旧 Profile 后请确认
toolNames同时包含pwsh与str_replace_editor;旧设置会被保留,不会被默认值强行覆盖。验证
@deepseek-ai/dsh@0.1.1-rc.2Web Profile 安装成功。7A323647B94FEB3BEE0337904AADFD85EB6FE0B36A3589DD07B92148A27ECE27边界:它是工具调用边界策略,不是操作系统沙箱或通用 DLP;链接检查与执行之间仍可能存在 TOCTOU。遇到误报/漏报,请用仓库的 Guard report 模板提交脱敏 finding,切勿公开 Token、密码或私钥。
如果它确实保护了你的 Windows 工作区,欢迎 Upvote,帮助其他用户找到它。
All reactions