Plugin directory / Developer / dsh-safe-workflow
dsh-safe-workflow
Unverified cnwutianhao
What it does
Safety-first workflow plugin for DeepSeek Harness with task contracts, approval gates, checkpoints, verification evidence, and best-effort rollback. 为 DeepSeek Harness 提供任务契约、审批门禁、检查点和验证能力,让 Agent 工作流更安全。
Unverified — not yet verified
Safety-first workflow plugin for DeepSeek Harness with task contracts, approval gates, checkpoints, verification evidence, and best-effort rollback. 为 DeepSeek Harness 提供任务契约、审批门禁、检查点和验证能力,让 Agent 工作流更安全。 Not yet verified — install and test it yourself.
“Unverified” means our automated CI has not yet installed this plugin. Feature descriptions and version compatibility are the author’s claims. This is not a security audit and not an endorsement of third-party code.
README
dsh-safe-workflow
English | 简体中文
An independent DeepSeek Harness plugin for safer, evidence-backed coding workflows.
It provides one model-facing tool, safe_workflow, with these operations:
start: create a task contract;status: inspect the active contract;checkpoint: snapshot the selected workspace state;restore: restore a checkpoint;verify: run a verification command and record its output;close: close the contract.
It also installs two native policy listeners:
tools/pre-execute: checks path rules and asks for approval before mutating tools;tools/execute: creates an automatic best-effort checkpoint before mutation.
Install into a DSH source checkout
Build this project first:
npm install
npm run check
Then, from the DSH checkout, install this directory into the Web profile:
DSH_DIR=/path/to/deepseek-harness
PLUGIN_DIR=/path/to/dsh-safe-workflow
cd "$DSH_DIR"
pnpm dsh plugin --profile web add "$PLUGIN_DIR"
pnpm dsh --profile web --dump-config | grep dsh-safe-workflow
pnpm dsh web
After installation, the plugin appears in the DSH plugin list and is enabled for the Web profile:

The plugin writes state into the current session workspace under .dsh-safe-workflow/:
contract.json active task contract and verification records
audit.jsonl append-only session/tool/checkpoint evidence
checkpoints/ checkpoint manifests and copied files
Example workflow
Start a safe workflow titled "Fix parser regression".
Goal: fix the parser regression without changing public APIs.
Acceptance checks: run npm test and npm run typecheck.
Only allow changes under src/ and test/.
Require approval before bash, write, edit, or str_replace_editor.
Then ask the agent to use safe_workflow verify after the implementation and safe_workflow close only when the acceptance checks pass.
When a mutating tool is about to run, the approval gate explains the requested operation and lets you approve or keep the contract unchanged:

Important limitations
This is a workflow guard, not a process sandbox. A plugin runs in the host process and has the host's permissions. The first version provides policy, evidence, and best-effort file snapshots; it does not promise atomic rollback of arbitrary shell side effects, network operations, databases, or files that were not included in a checkpoint.
For production use, review the source, pin the plugin version or commit, keep .dsh-safe-workflow out of sensitive repositories if needed, and run it with DSH's normal sandbox and approval layers enabled.
Install
Install the catalog once, then DeepSeek Harness can find and install any plugin from this site automatically:
dsh plugin add dshbase-catalog Then say "install dsh-safe-workflow for me" — your agent finds it in the directory and installs it. Docs: dshbase-catalog · verified packs.
This plugin is GitHub source (not published to npm) — install it straight from the repo:
Web profile:
dsh plugin --profile web add github:cnwutianhao/dsh-safe-workflow Headless (CLI) profile:
dsh plugin --profile headless add github:cnwutianhao/dsh-safe-workflow Test report
Not yet L3-verified — see failure note below if we already ran it.