Back to marketplace

dsh-capability-toggle-plugin

Security

lifeopsgo/dsh-capability-toggle-plugin

Toggle individual agent capabilities (skills, MCP, tools, prompt, approval, guards) from the DSH WebUI composer at session, project, or global scope with runtime enforcement.

  • deepseek-harness
  • deepseek-harness-desktop
  • deepseek-harness-plugin
  • deepseek-harness-plugins
  • dsh
  • dsh-plugin
  • dsh-plugin-desktop
  • dsh-plugins
GitHub Stars
3GitHub
Views
0DSH Plugin Hub
Forks
0GitHub
Open issues
0GitHub Issues
Manifest version
1.1.0dsh-capability-toggle-plugin
Latest push
Sep 2, 2026GitHub
License
MITTypeScript
Plugin type
Host + ClientRuns in both Host and Web Client

Verification and compatibility

This section shows evidence collected by the catalog. Undeclared information is labeled as unknown.

Runtime verified
01Exact source: github · dsh-capability-toggle-plugin@1.1.002Validated: Sep 3, 202603Verified Harness: 0.1.0-rc.7
Current-version compatibility
Verified on the catalog Harness version
Declared Harness range
Not declared
Declared platforms
Not declared
Profiles
web
Build approval
No requirement detected
Permissions
Not declared
External services
Not declared
Telemetry
Unknown
No known risk flags found

This is not a security endorsement. Review source, permissions, and configuration before installing.

View evidence and scope

Verification covers only the named source, version, and Harness environment. It does not guarantee future compatibility.

  • github:lifeopsgo/dsh-capability-toggle-plugin#5e27bd537605b21d8134e3192db50b6359e80356
  • The plugin completed a load check in an isolated environment.

README

View source

dsh-capability-toggle-plugin

Control agent capabilities from the DSH WebUI — with real runtime enforcement.

platform tests release license

English · 简体中文

Session · Project · Global — blue check = on, red cross = off, dashed dash = unset.

What it is

A DeepSeek Harness (DSH) WebUI plugin for controlling skills, MCP servers, tools, prompt injections, approval escalation, and safety guards at session, project, or global scope. Depending on the family, disabling removes, suppresses, rejects, or intercepts the capability on the agent's next step.

Quick start

Requires Node.js ≥ 22.6.

dsh plugin --profile web add github:lifeopsgo/dsh-capability-toggle-plugin#v1.1.0

Restart the existing DSH Web GUI process, then refresh the page. Start it with the command below when it is stopped:

dsh --profile web web

Open the control beside the ➕ button while the agent is idle. Replace web with another profile name when needed.

# Upgrade or downgrade: use any tag listed on the releases page
dsh plugin --profile web add github:lifeopsgo/dsh-capability-toggle-plugin#v1.1.0

# Remove
dsh plugin --profile web remove dsh-capability-toggle-plugin

Features

Three-level resolution

Each capability has three independent levels:

session  ›  project  ›  global  ›  default (enabled)

The nearest explicit value wins. Unset defers to the next level; with every level unset, the capability remains enabled. The row badge always shows the resolved result.

The button displays only its current state: click to toggle on ↔ off, or use its small clear badge to return to unset.

Capability families

TabControls
SkillsIndividual model-invocable skills, including project-level skills discovered from the session's workspace (.dsh/skills, .agents/skills)
MCPMCP servers; expand a row to inspect member tools
ToolsIndividual model-visible tools and their guidance sections
PromptA safe, presence-checked allowlist of prompt injections
SecurityApproval escalation and five opt-in safety guards

Enforcement

Every mechanism is scoped to the current agent; global registrations are not mutated.

FamilyEnforcement
tool / mcpRemoved with ctx.tools.restrict({ deny }); forced calls are refused
skillShadowed by a same-named modelInvocable:false runtime skill
promptShadowed with empty text, or suppressed with suppressRuntimeContext()
approvalScoped approval requests resolve to rejected
guardtools/pre-execute blocks or requests confirmation for matching calls

Security controls

Turning off Approval escalation rejects every approval request from that agent without changing the system /permission setting.

Safety guards are opt-in:

GuardAction
Read-only modeBlock file writes, creates, and edits
Protect secretsBlock access to common secret files and credentials
Dangerous shellConfirm high-risk shell commands
Destructive gitConfirm history- or work-losing git commands
Outbound networkConfirm network tools and outbound shell actions

Additional behavior: switches lock while the agent runs, state survives popup close and turn boundaries, and the UI follows the WebUI language.

Roadmap

Planned, not yet implemented:

  • Cross-project config sync — copy or link project-level settings from another project instead of configuring each project from scratch.
  • Filter and select-all — shipped in v1.1.0: the toolbar's search box filters rows, and each level's bulk menu applies enable/disable/clear to every currently visible row.
  • Bulk actions on a filtered selection — shipped in v1.1.0 together with the filter (search narrows, bulk acts on what's shown).

Comments

0
Newest first