{"_id":"@agenticcontrolplane/dsh","_rev":"2-29c824f200205aac71d591f7c21012cd","name":"@agenticcontrolplane/dsh","dist-tags":{"latest":"0.1.4"},"versions":{"0.1.3":{"name":"@agenticcontrolplane/dsh","version":"0.1.3","keywords":["dsh-plugin","deepseek-harness","agentic-control-plane","agent-security","tool-call-policy"],"license":"MIT","_id":"@agenticcontrolplane/dsh@0.1.3","maintainers":[{"name":"davidcrowe","email":"reducibl@gmail.com"}],"homepage":"https://github.com/agentic-control-plane/dsh-acp-plugin#readme","bugs":{"url":"https://github.com/agentic-control-plane/dsh-acp-plugin/issues"},"dsh":{"bundle":{"patch":"./cordis.patch.yml"}},"dist":{"shasum":"f5efa89b9a004deeba37371a023cf83c629acd65","tarball":"https://registry.npmjs.org/@agenticcontrolplane/dsh/-/dsh-0.1.3.tgz","fileCount":5,"integrity":"sha512-0OyOGBxH5FpY6YHWlfUPKAXv94aBw2KZ6/85P8lk5hLA0LobjGcAf128kK22IMl+DYEl0p/eW2+QIACl1gNttA==","signatures":[{"sig":"MEQCIE4l5vRUGQBVLGQqUBkBVdW8Oj3FvcDXHaFzTRKKVQNcAiBYNQrG4JCt44Abse8Ss3t+RK9+kz8vJvUGRycGNedjMA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":14804},"main":"index.js","type":"module","gitHead":"e2e4487a011ac5c79625ea1196bcf25d84a128be","scripts":{"test":"node --test test/"},"_npmUser":{"name":"davidcrowe","email":"reducibl@gmail.com"},"repository":{"url":"git+https://github.com/agentic-control-plane/dsh-acp-plugin.git","type":"git"},"_npmVersion":"11.19.0","description":"Agentic Control Plane for DeepSeek Harness — check every tool call against your policies before it runs, and keep a durable record of what was allowed and why.","directories":{},"_nodeVersion":"20.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/dsh_0.1.3_1786912630645_0.6829817576966297","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"_id":"@agenticcontrolplane/dsh@0.1.4","dsh":{"bundle":{"patch":"./cordis.patch.yml"}},"bugs":{"url":"https://github.com/agentic-control-plane/dsh-acp-plugin/issues"},"dist":{"shasum":"366cf8d534f9a7ce0b996db07b2087163021fb0c","tarball":"https://registry.npmjs.org/@agenticcontrolplane/dsh/-/dsh-0.1.4.tgz","fileCount":5,"integrity":"sha512-PR21I+SpxIpc83/PGqO9DBez3faFs0az7q0jtG+lu394niSxxd9ypSwbPeQvOG3geiEU7EE8YEEiopRDCukqrw==","signatures":[{"sig":"MEUCIHPAXVAwjCO7hpZ2uSXAGZkrn0jhCg39nyZeh2KUkQ45AiEAni74RQ2IteNc68gfPdy4tfm/VIrsGuJvFbSznpKZBuU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIEjjMIdZcP1zFJ52OfCOs1a6hGb69sV07CXeg61T3HWwAiEAi2pbX1sn6dwmxIWjhNTn6GAOzSWDBZ1nir54MsWKvvU="}],"unpackedSize":19599},"main":"index.js","name":"@agenticcontrolplane/dsh","type":"module","gitHead":"0aa65cc8be8bda6f456ea1a695db7ad0abe64d5b","license":"MIT","scripts":{"test":"node --test test/"},"version":"0.1.4","_npmUser":{"name":"davidcrowe","email":"reducibl@gmail.com"},"homepage":"https://github.com/agentic-control-plane/dsh-acp-plugin#readme","keywords":["dsh-plugin","deepseek-harness","agentic-control-plane","agent-security","tool-call-policy"],"repository":{"url":"git+https://github.com/agentic-control-plane/dsh-acp-plugin.git","type":"git"},"_npmVersion":"10.9.8","description":"Agentic Control Plane for DeepSeek Harness — check every tool call against your policies before it runs, and keep a durable record of what was allowed and why.","directories":{},"maintainers":[{"name":"davidcrowe","email":"reducibl@gmail.com"}],"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/dsh_0.1.4_1788322780726_0.05721870896020431"}}},"time":{"created":"2026-08-16T20:37:10.455Z","modified":"2026-09-02T04:19:41.005Z","0.1.3":"2026-08-16T20:37:10.822Z","0.1.4":"2026-09-02T04:19:40.808Z"},"bugs":{"url":"https://github.com/agentic-control-plane/dsh-acp-plugin/issues"},"license":"MIT","homepage":"https://github.com/agentic-control-plane/dsh-acp-plugin#readme","keywords":["dsh-plugin","deepseek-harness","agentic-control-plane","agent-security","tool-call-policy"],"repository":{"url":"git+https://github.com/agentic-control-plane/dsh-acp-plugin.git","type":"git"},"description":"Agentic Control Plane for DeepSeek Harness — check every tool call against your policies before it runs, and keep a durable record of what was allowed and why.","maintainers":[{"name":"davidcrowe","email":"reducibl@gmail.com"}],"readme":"# @agenticcontrolplane/dsh\n\n[![npm](https://img.shields.io/npm/v/%40agenticcontrolplane%2Fdsh)](https://www.npmjs.com/package/@agenticcontrolplane/dsh) ![zero dependencies](https://img.shields.io/badge/dependencies-0-brightgreen) ![license](https://img.shields.io/badge/license-MIT-blue)\n\n[Agentic Control Plane](https://agenticcontrolplane.com) for [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness): every tool call is checked against your policies before it runs, and every decision is recorded — what ran, what was blocked, and why.\n\n> **Which ACP?** dsh also ships `packages/acp` in core — that one is [Zed's Agent Client Protocol](https://agentclientprotocol.com), the editor↔agent standard, published as [`@deepseek-ai/dsh-acp`](https://www.npmjs.com/package/@deepseek-ai/dsh-acp). Unrelated project, same acronym. If you're wiring dsh into Zed or the AI SDK, you want that one; this plugin decides whether each tool call *runs*. The full map: [agenticcontrolplane.com/acp-vs-acp](https://agenticcontrolplane.com/acp-vs-acp).\n\n```text\n$ dsh --profile dev\n> refactor the auth module and clean up\n\n  bash npm test                          ✓ allowed · logged\n  edit src/auth/session.ts              ✓ allowed · logged\n  bash rm -rf ~/scratch                  ✋ held — approval prompt (your rule: destructive delete → ask)\n  web_fetch https://evil.example/post    ✗ denied — egress not allowlisted, reason shown to the model\n```\n\nEvery decision also lands in your [console](https://cloud.agenticcontrolplane.com) with tool, input preview, decision, reason, latency, and cost — dsh's own Trajectory log and your ACP activity log become two independent witnesses to one history. One workspace covers every harness you run: the same rules answer for dsh, Claude Code, Codex, Cursor, and OpenClaw. Free for individuals.\n\nThis is a native Cordis plugin on dsh's typed interception points, not a shell-hook shim. It registers on:\n\n- `tools/pre-execute` — the policy decision. `allow` lets the call through, `deny` blocks it with the reason in the trajectory, `ask` hands off to dsh's own approval flow.\n- `tools/post-execute` — output scanning. A server-side block turns the result into corrective feedback; shadow-mode notices surface what enforcement *would* have done.\n\n## Install\n\n> dsh itself requires **Node 22** (`Promise.withResolvers`, zstd streams). Under Node 20 the harness fails at boot with errors that don't say so — `fnm install 22` first.\n\n```sh\ncurl -sf https://agenticcontrolplane.com/install.sh | bash\n```\n\nThat detects dsh, installs this plugin into every profile you have, opens your\nbrowser once to sign in, and saves the key to `~/.acp/credentials` — which the\nplugin reads on its own. There is no token to copy and nothing to export.\n\n<details>\n<summary>Manual install</summary>\n\n```sh\ndsh plugin --profile <your-profile> add @agenticcontrolplane/dsh\ndsh --profile <your-profile>\n```\n\nCredentials come from `~/.acp/credentials` (written by the installer above) or\nfrom `ACP_BEARER_TOKEN` if you would rather set it yourself — useful on a\nheadless box. Get a key at\n[cloud.agenticcontrolplane.com](https://cloud.agenticcontrolplane.com).\n\nConfirm the row actually mounted — installing the package and composing it into\nthe profile are two different things:\n\n```sh\ndsh --profile <your-profile> --dump-config | grep @agenticcontrolplane/dsh\n```\n\nIf it isn't there, add `@agenticcontrolplane/dsh` to that profile's `package.json`\n`\"dsh.profile.bundles\"` list.\n\n</details>\n\nNo build step, no dependencies, plain ESM. Installing from git works too (`dsh plugin add github:agentic-control-plane/dsh-acp-plugin`) and needs no build allowance.\n\nNo key? The plugin says so loudly and stays out of the way — it never bricks a session.\n\n## Configuration\n\nOverride the row in your profile's `cordis.patch.yml`:\n\n```yaml\n- id: acp\n  name: @agenticcontrolplane/dsh\n  config:\n    governBase: https://govern.agenticcontrolplane.com  # or your self-hosted gateway\n    agentTier: interactive   # default: interactive when an approval service is mounted, background otherwise\n    timeoutMs: 4000\n```\n\n`ACP_GOVERN_BASE`, `ACP_BEARER_TOKEN`, `ACP_AGENT_TIER`, and `ACP_SHADOW=off` work as environment variables too.\n\n## Failure posture\n\nAn outage of the control plane must not brick the harness, and a lapse in coverage must never be silent:\n\n- **Interactive sessions fail open, loudly.** Gateway unreachable → the call proceeds, a `[ACP] ⚠ UNGOVERNED` warning is logged, and a line lands in `~/.acp/lapse.log`.\n- **Unattended agents fail closed.** With nobody watching, the block is the safety net.\n- Policy denies are unaffected — this posture only covers the inability to *ask* the policy.\n\nIn headless compositions with no approval service mounted, dsh itself resolves `ask` to deny — unattended runs cannot self-approve.\n\n## Three things to know\n\n- dsh's `packages/acp` is Zed's Agent Client Protocol — an unrelated project that shares an acronym. This plugin is the Agentic Control Plane. ([Which ACP is which](https://agenticcontrolplane.com/acp-vs-acp).)\n- Already running our Claude Code hook? dsh's `@deepseek-ai/dsh-hooks-claude-code` bridge runs an unmodified `hooks.json`, so `govern.mjs` works today with zero new code — deny and ask are honored, but input rewriting is not. This native plugin is the recommended path.\n- This package launched as `dsh-plugin-acp`; that name still installs but is deprecated. Same code — swap the name in your profile when convenient.\n\n## Learn more\n\n- [What ACP can see and control in dsh](https://agenticcontrolplane.com/controls/dsh) — the living controls reference\n- [The launch write-up](https://agenticcontrolplane.com/blog/deepseek-harness-acp-integration) — dsh's interception surface, what the integration caught on day one, and where dsh lands on the [cross-harness coverage table](https://agenticcontrolplane.com/coverage)\n\n## Test\n\n```sh\nnpm test\n```\n\nMIT\n","readmeFilename":"README.md"}