{"_id":"@amaster.ai/dsh-policy","_rev":"3-119830c5f849d73695a2ac364983f85b","name":"@amaster.ai/dsh-policy","dist-tags":{"latest":"0.1.3"},"versions":{"0.1.1":{"name":"@amaster.ai/dsh-policy","version":"0.1.1","license":"MIT","_id":"@amaster.ai/dsh-policy@0.1.1","maintainers":[{"name":"qianchuan","email":"qdgemi@gmail.com"},{"name":"thornhill","email":"gpyx529@gmail.com"},{"name":"licy_mail","email":"licy_mail@qq.com"},{"name":"weaxs","email":"459312872@qq.com"},{"name":"2betop","email":"2betop.cn@gmail.com"},{"name":"lmaomaoz","email":"lmaomaoz@live.com"},{"name":"xiaojiaolv","email":"dfsq757@sina.com"},{"name":"xudong.ray","email":"xudzhang0914@gmail.com"}],"homepage":"https://github.com/TGYD-helige/dsh-plugins#readme","bugs":{"url":"https://github.com/TGYD-helige/dsh-plugins/issues"},"dsh":{"bundle":{"patch":"./cordis.patch.yml"}},"dist":{"shasum":"468b95b1e2c92a2c5e749cfb03a889b9cae5d06f","tarball":"https://registry.npmjs.org/@amaster.ai/dsh-policy/-/dsh-policy-0.1.1.tgz","fileCount":11,"integrity":"sha512-dpfrl7w8rDrGGgVWnRKwrB8OukTs06kAq8ydltMJ5Z5p2yAOrfBtjLPr9M7XrIM9y69SOebbLmljcN4HI6p3+A==","signatures":[{"sig":"MEUCIGAr0Vs+h3eicaNdoFILsNVUkQ+Cbpv65ptiq3jj+ws8AiEAkIpzM6sMe+ab+mvub7K1611s9bMtcB8A/bb0Tl8UST0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1591939},"main":"lib/index.js","type":"module","_from":"file:amaster.ai-dsh-policy-0.1.1.tgz","types":"lib/types/index.d.ts","engines":{"node":"^20.19 || ^22.12 || >=24.0"},"exports":{".":{"types":"./lib/types/index.d.ts","default":"./lib/index.js"},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"xiaojiaolv","email":"dfsq757@sina.com"},"_resolved":"/tmp/9d4c8416f2df990995b2a5084adaf810/amaster.ai-dsh-policy-0.1.1.tgz","_integrity":"sha512-dpfrl7w8rDrGGgVWnRKwrB8OukTs06kAq8ydltMJ5Z5p2yAOrfBtjLPr9M7XrIM9y69SOebbLmljcN4HI6p3+A==","repository":{"url":"git+https://github.com/TGYD-helige/dsh-plugins.git","type":"git","directory":"packages/dsh-policy"},"_npmVersion":"10.9.8","description":"Declarative tool-call policy for DeepSeek Harness: config-driven allow/deny/ask rules (tool name, args pattern, shell command prefix/regex, priority) on the tools/pre-execute gate — Gemini CLI-style policy files expressed as plain plugin config.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"@deepseek-ai/schemastery":"^3.18.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","typescript":"^5.6.3","@types/node":"^22.0.0","@deepseek-ai/cordis":"^4.0.1","@deepseek-ai/dsh-llm":"0.1.5-rc.1","@deepseek-ai/dsh-jobs":"0.1.5-rc.1","@deepseek-ai/dsh-agent":"0.1.5-rc.1","@deepseek-ai/dsh-scope":"0.1.5-rc.1","@deepseek-ai/dsh-shell":"0.1.5-rc.1","@deepseek-ai/dsh-tools":"0.1.5-rc.1","@deepseek-ai/dsh-sandbox":"0.1.5-rc.1","@deepseek-ai/dsh-shell-env":"0.1.5-rc.1","@deepseek-ai/dsh-tool-bash":"0.1.5-rc.1","@deepseek-ai/dsh-home-paths":"0.1.5-rc.1","@deepseek-ai/dsh-http-proxy":"0.1.5-rc.1","@deepseek-ai/dsh-invariants":"0.1.5-rc.1","@deepseek-ai/dsh-subprocess":"0.1.5-rc.1","@deepseek-ai/dsh-system-prompt":"0.1.5-rc.1","@deepseek-ai/dsh-user-approval":"0.1.5-rc.1","@deepseek-ai/dsh-sandbox-policy":"0.1.5-rc.1"},"peerDependencies":{"@deepseek-ai/cordis":"^4.0.1","@deepseek-ai/dsh-tools":"0.1.5-rc.1"},"_npmOperationalInternal":{"tmp":"tmp/dsh-policy_0.1.1_1789115147430_0.7239027796299506","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@amaster.ai/dsh-policy","version":"0.1.2","license":"MIT","_id":"@amaster.ai/dsh-policy@0.1.2","maintainers":[{"name":"qianchuan","email":"qdgemi@gmail.com"},{"name":"thornhill","email":"gpyx529@gmail.com"},{"name":"licy_mail","email":"licy_mail@qq.com"},{"name":"weaxs","email":"459312872@qq.com"},{"name":"2betop","email":"2betop.cn@gmail.com"},{"name":"lmaomaoz","email":"lmaomaoz@live.com"},{"name":"xiaojiaolv","email":"dfsq757@sina.com"},{"name":"xudong.ray","email":"xudzhang0914@gmail.com"}],"homepage":"https://github.com/TGYD-helige/dsh-plugins#readme","bugs":{"url":"https://github.com/TGYD-helige/dsh-plugins/issues"},"dsh":{"bundle":{"patch":"./cordis.patch.yml"}},"dist":{"shasum":"f76672c6b8c25f35e7d72436650069c267f6eb9c","tarball":"https://registry.npmjs.org/@amaster.ai/dsh-policy/-/dsh-policy-0.1.2.tgz","fileCount":11,"integrity":"sha512-0aN+dJubjg07eDhewVxd3QQjp4+TIfPYLZPkizgWqhjBgpzilr6wuTe9B1tafSWZp2T9Ig8diQrJ1nWL2XPGKQ==","signatures":[{"sig":"MEYCIQDj3pAObiDxg35HFxkTgfX83S+mwUA2B5bDuPNzWX23TwIhAImpt3HxIp8Q+ioTqGShMJpHo6rwRiz4wmHjgksZyaiB","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIHWDV/F+CVFgklfughlpXjJvC1oSiDbvlOOEy/JFx+7tAiEA/P7N5OEpXms20WtEAjhhGzmObHwybcK2R9S/srBMtkc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1591939},"main":"lib/index.js","type":"module","_from":"file:amaster.ai-dsh-policy-0.1.2.tgz","types":"lib/types/index.d.ts","engines":{"node":"^20.19 || ^22.12 || >=24.0"},"exports":{".":{"types":"./lib/types/index.d.ts","default":"./lib/index.js"},"./package.json":"./package.json"},"scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"xiaojiaolv","email":"dfsq757@sina.com"},"_resolved":"/tmp/8a918fbaa6e267e2a3c437d72181266f/amaster.ai-dsh-policy-0.1.2.tgz","_integrity":"sha512-0aN+dJubjg07eDhewVxd3QQjp4+TIfPYLZPkizgWqhjBgpzilr6wuTe9B1tafSWZp2T9Ig8diQrJ1nWL2XPGKQ==","repository":{"url":"git+https://github.com/TGYD-helige/dsh-plugins.git","type":"git","directory":"packages/dsh-policy"},"_npmVersion":"10.9.8","description":"Declarative tool-call policy for DeepSeek Harness: config-driven allow/deny/ask rules (tool name, args pattern, shell command prefix/regex, priority) on the tools/pre-execute gate — Gemini CLI-style policy files expressed as plain plugin config.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"@deepseek-ai/schemastery":"^3.18.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","typescript":"^5.6.3","@types/node":"^22.0.0","@deepseek-ai/cordis":"^4.0.1","@deepseek-ai/dsh-llm":"0.1.5-rc.1","@deepseek-ai/dsh-jobs":"0.1.5-rc.1","@deepseek-ai/dsh-agent":"0.1.5-rc.1","@deepseek-ai/dsh-scope":"0.1.5-rc.1","@deepseek-ai/dsh-shell":"0.1.5-rc.1","@deepseek-ai/dsh-tools":"0.1.5-rc.1","@deepseek-ai/dsh-sandbox":"0.1.5-rc.1","@deepseek-ai/dsh-shell-env":"0.1.5-rc.1","@deepseek-ai/dsh-tool-bash":"0.1.5-rc.1","@deepseek-ai/dsh-home-paths":"0.1.5-rc.1","@deepseek-ai/dsh-http-proxy":"0.1.5-rc.1","@deepseek-ai/dsh-invariants":"0.1.5-rc.1","@deepseek-ai/dsh-subprocess":"0.1.5-rc.1","@deepseek-ai/dsh-system-prompt":"0.1.5-rc.1","@deepseek-ai/dsh-user-approval":"0.1.5-rc.1","@deepseek-ai/dsh-sandbox-policy":"0.1.5-rc.1"},"peerDependencies":{"@deepseek-ai/cordis":"^4.0.1","@deepseek-ai/dsh-tools":"0.1.5-rc.1"},"_npmOperationalInternal":{"tmp":"tmp/dsh-policy_0.1.2_1789115334192_0.8394084879053654","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"_id":"@amaster.ai/dsh-policy@0.1.3","dsh":{"bundle":{"patch":"./cordis.patch.yml"}},"bugs":{"url":"https://github.com/TGYD-helige/dsh-plugins/issues"},"dist":{"shasum":"809f4eabef67e303e400851e7ca19e744ae5c44b","tarball":"https://registry.npmjs.org/@amaster.ai/dsh-policy/-/dsh-policy-0.1.3.tgz","fileCount":11,"integrity":"sha512-jrbEbegJ6Fe/8O+GpbSJBoCb4G/ZZyMJAk0nBLaLAp3f9LEh7SlFWv/ugTR5yTpfgkc6iDx5eADqB5CKJNLB/A==","signatures":[{"sig":"MEYCIQDxBc0Kd5BE5qDuqa/ozG35uK7ct6ZL1JFzCwVfqDElGQIhAJQxJNaE9QZv6v+QzUXsAsDtwi+/glgmcJz85Zxs3i46","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIHYvMJ39NfKuATkqdSgh4sHVOkXrlNT188DQvZoinqwQAiEAzn5Br+/CL1WhTT5snEWBlSywv/58ArbRXhT9BGPLaXw="}],"unpackedSize":1591940},"main":"lib/index.js","name":"@amaster.ai/dsh-policy","type":"module","_from":"file:amaster.ai-dsh-policy-0.1.3.tgz","types":"lib/types/index.d.ts","engines":{"node":"^20.19 || ^22.12 || >=24.0"},"exports":{".":{"types":"./lib/types/index.d.ts","default":"./lib/index.js"},"./package.json":"./package.json"},"license":"MIT","scripts":{"test":"vitest run","build":"tsc -p tsconfig.build.json","typecheck":"tsc -p tsconfig.json --noEmit"},"version":"0.1.3","_npmUser":{"name":"xiaojiaolv","email":"dfsq757@sina.com"},"homepage":"https://github.com/TGYD-helige/dsh-plugins#readme","_resolved":"/tmp/a9522ff957c74d1499f9e0e8daef5c29/amaster.ai-dsh-policy-0.1.3.tgz","_integrity":"sha512-jrbEbegJ6Fe/8O+GpbSJBoCb4G/ZZyMJAk0nBLaLAp3f9LEh7SlFWv/ugTR5yTpfgkc6iDx5eADqB5CKJNLB/A==","repository":{"url":"git+https://github.com/TGYD-helige/dsh-plugins.git","type":"git","directory":"packages/dsh-policy"},"_npmVersion":"10.9.8","description":"Declarative tool-call policy for DeepSeek Harness: config-driven allow/deny/ask rules (tool name, args pattern, shell command prefix/regex, priority) on the tools/pre-execute gate — Gemini CLI-style policy files expressed as plain plugin config.","directories":{},"maintainers":[{"name":"qianchuan","email":"qdgemi@gmail.com"},{"name":"thornhill","email":"gpyx529@gmail.com"},{"name":"licy_mail","email":"licy_mail@qq.com"},{"name":"weaxs","email":"459312872@qq.com"},{"name":"2betop","email":"2betop.cn@gmail.com"},{"name":"lmaomaoz","email":"lmaomaoz@live.com"},{"name":"xiaojiaolv","email":"dfsq757@sina.com"},{"name":"xudong.ray","email":"xudzhang0914@gmail.com"}],"_nodeVersion":"22.23.2","dependencies":{"@deepseek-ai/schemastery":"^3.18.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^4.1.11","typescript":"^5.6.3","@types/node":"^22.0.0","@deepseek-ai/cordis":"^4.0.1","@deepseek-ai/dsh-llm":"0.1.5-rc.1","@deepseek-ai/dsh-jobs":"0.1.5-rc.1","@deepseek-ai/dsh-agent":"0.1.5-rc.1","@deepseek-ai/dsh-scope":"0.1.5-rc.1","@deepseek-ai/dsh-shell":"0.1.5-rc.1","@deepseek-ai/dsh-tools":"0.1.5-rc.1","@deepseek-ai/dsh-sandbox":"0.1.5-rc.1","@deepseek-ai/dsh-shell-env":"0.1.5-rc.1","@deepseek-ai/dsh-tool-bash":"0.1.5-rc.1","@deepseek-ai/dsh-home-paths":"0.1.5-rc.1","@deepseek-ai/dsh-http-proxy":"0.1.5-rc.1","@deepseek-ai/dsh-invariants":"0.1.5-rc.1","@deepseek-ai/dsh-subprocess":"0.1.5-rc.1","@deepseek-ai/dsh-system-prompt":"0.1.5-rc.1","@deepseek-ai/dsh-user-approval":"0.1.5-rc.1","@deepseek-ai/dsh-sandbox-policy":"0.1.5-rc.1"},"peerDependencies":{"@deepseek-ai/cordis":"^4.0.1","@deepseek-ai/dsh-tools":"^0.1.5-rc.1"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/dsh-policy_0.1.3_1789442902680_0.12437540160073923"}}},"time":{"created":"2026-09-11T08:25:47.205Z","modified":"2026-09-15T03:28:23.003Z","0.1.1":"2026-09-11T08:25:47.643Z","0.1.2":"2026-09-11T08:28:54.296Z","0.1.3":"2026-09-15T03:28:22.819Z"},"bugs":{"url":"https://github.com/TGYD-helige/dsh-plugins/issues"},"license":"MIT","homepage":"https://github.com/TGYD-helige/dsh-plugins#readme","repository":{"url":"git+https://github.com/TGYD-helige/dsh-plugins.git","type":"git","directory":"packages/dsh-policy"},"description":"Declarative tool-call policy for DeepSeek Harness: config-driven allow/deny/ask rules (tool name, args pattern, shell command prefix/regex, priority) on the tools/pre-execute gate — Gemini CLI-style policy files expressed as plain plugin config.","maintainers":[{"name":"qianchuan","email":"qdgemi@gmail.com"},{"name":"thornhill","email":"gpyx529@gmail.com"},{"name":"licy_mail","email":"licy_mail@qq.com"},{"name":"weaxs","email":"459312872@qq.com"},{"name":"2betop","email":"2betop.cn@gmail.com"},{"name":"lmaomaoz","email":"lmaomaoz@live.com"},{"name":"xiaojiaolv","email":"dfsq757@sina.com"},{"name":"xudong.ray","email":"xudzhang0914@gmail.com"}],"readme":"# @amaster.ai/dsh-policy\n\n![dsh-policy preview](preview.png)\n\nDeclarative tool-call policy for [DeepSeek Harness (dsh)](https://github.com/deepseek-ai/deepseek-harness): config-driven `allow` / `deny` / `ask` rules on dsh's `tools/pre-execute` gate — the semantics of Gemini CLI's TOML policy files, expressed as plain plugin config (Schemastery-validated YAML, no code, no rule files).\n\n## Install\n\n```sh\ndsh plugin --profile my-agent add @amaster.ai/dsh-policy\n```\n\n## Configuration\n\nThe plugin is **disabled by default**. Rules live in the profile's `cordis.patch.yml` like every other dsh plugin config (edits hot-reload with the config layer):\n\n```yaml\n- name: '@amaster.ai/dsh-policy'\n  config:\n    enabled: true\n    rules:\n      - tool: '*'                      # every tool\n        decision: allow\n        priority: 20\n      - tool: bash                     # dsh's shell tool (pwsh works the same)\n        decision: deny\n        commandPrefix: npm\n        priority: 200\n        message: 'npm is not allowed. Use bun install / bun add / bun test instead.'\n      - tool: bash\n        decision: deny\n        commandPrefix: bun run\n        priority: 200\n      - tool: bash                     # …but one specific subcommand is fine\n        decision: allow\n        commandPrefix: bun run lint\n        priority: 300                  # higher priority overrides the broader deny\n      - tool: bash                     # grep as a pipe filter stays allowed\n        decision: allow\n        commandPrefix: grep\n        priority: 300\n      - tool: write\n        decision: deny\n        argsPattern:\n          file_path: '\\.md$'           # matched against the file_path value directly\n        priority: 200\n      - tool: write                    # …except the project contract file\n        decision: allow\n        argsPattern:\n          file_path: 'PRODUCT\\.md$'\n        priority: 300\n      - tool: write\n        decision: ask                  # resolved via ctx.approval (human/answerer chain)\n        argsPattern:\n          file_path: '(^|/)etc/'\n        message: 'writes to a system path'\n```\n\n### Rule fields\n\n| Field | Required | Meaning |\n| --- | --- | --- |\n| `tool` | yes | Tool name or list of names; `*` matches every tool |\n| `decision` | yes | `allow` runs the call, `deny` blocks it (the `message` reaches the model as the tool error), `ask` defers to dsh's approval seam |\n| `priority` | no (0) | Higher priority wins among rules competing for the same command segment; ties break fail-closed (deny > ask > allow) |\n| `message` | no | Deny reason / ask explanation (a generated default names the matched rule) |\n| `argsPattern` | no | Regex (or list, any-of) matched against the JSON-stringified arguments — or a map of argument name → regex (or list): each key's pattern is matched against that argument's **value** (non-string values are JSON-stringified first), all keys must hold. Prefer the map form for field-targeted rules — no quote escaping, no key-order or cross-field accidents |\n| `commandPrefix` | no | Anchored prefix match (or list, any-of) on each shell command segment, at a word boundary (`npm` matches `npm install`, never `npmx`) |\n| `commandRegex` | no | Regex (or list, any-of) anchored at each shell command segment's start — Gemini-compatible; use `.*` to match mid-segment |\n\nPlugin-level fields: `enabled` (master switch) and `commandKeys` (argument keys holding a shell command string — default `['command']`, covering dsh's `bash`/`pwsh` tools).\n\n### Matching semantics\n\n- **Every condition on a rule must hold** for the rule to match (AND). A rule with no conditions beyond `tool` matches every call of that tool.\n- **Shell commands are checked segment by segment.** Compound commands (`a && b | c`, newlines, background `&`) are split, quote-aware, and `$( )` / backtick substitutions are extracted as their own segments — `cd /tmp && npm install` and `echo \"$(npm install)\"` both hit the `npm` rule.\n- **Priority resolves competition within one segment**; across segments the aggregation is conservative: any segment's `deny` denies the whole call, then any `ask` escalates, and `allow` requires every segment decided allow. A broad deny is still overridable by a specific allow because both compete on the same segment (`bun run lint` at 300 vs `bun run` at 200).\n- **No rule matches → the call passes through** to the rest of the `tools/pre-execute` chain (`next()`), so dsh's own gates and other plugins keep their say. Invalid regexes are config errors and fail the plugin load; a runtime evaluation failure is logged with the `[dsh-policy]` prefix and delegates onward — the gate never breaks the agent loop.\n\n### What the gate covers\n\nEverything registered in `ctx.tools` passes `tools/pre-execute` — the gate is tool-agnostic and needs no per-tool support:\n\n- **Official tools** (verified against the 0.1.5-rc.1 sources): `bash`, `pwsh`, `read`, `write`, `edit`, `read_image`, `web_search`, `web_fetch`, `list_subagent_models` and the delegation tool, `run_code`, plus goal/skill/workflow/cordis tools. Match them by `tool` + `argsPattern` (the object form fits their argument shapes: `file_path` for `write`/`edit`, `url` for `web_fetch`, `query` for `web_search`, …).\n- **`commandPrefix`/`commandRegex`** apply to tools whose arguments carry a shell command string — `bash` and `pwsh` both use `command` (covered by the default `commandKeys`).\n- **PTC mode**: `run_code` sub-dispatches re-enter the scheduler's `prepare` stage, which runs the same pre-execute gate — rules apply per sub-call, not just per `run_code`.\n- **MCP tools** bridged by `dsh-mcp-client` register into the same `ctx.tools` pipeline — match them by their registered names like any other tool.\n\n### The `ask` decision\n\n`ask` is resolved by dsh itself: through the composed answerers of `@deepseek-ai/dsh-user-approval` (a UI prompt, an auto-answerer, …), failing closed to deny when no approval service is composed, and short-circuiting to reject under a session's `approval/policy: never`. The model-facing deny reason is the rule's `message` only when no approval service exists at all; a `rejected`/`cancelled`/`unavailable` outcome carries dsh-tools' own reason wording (verified against `dsh-tools@0.1.5-rc.1`). Gemini's `modes` (`default`/`autoEdit`/`yolo`/`plan`) have no dsh counterpart — dsh models that axis as the per-session approval policy (see `dsh-permission-presets` for the user-facing selector), and dsh profiles/`cordis.patch.yml` already scope config per deployment, so the plugin carries no mode axis of its own.\n\n## Gemini CLI policy mapping\n\n| Gemini TOML | dsh-policy config |\n| --- | --- |\n| `toolName = \"*\" / \"name\" / [\"a\", \"b\"]` | `tool: '*' / name / [a, b]` |\n| `decision = \"allow\" / \"deny\" / \"ask_user\"` | `decision: allow / deny / ask` |\n| `priority = 300` | `priority: 300` (same direction) |\n| `denyMessage` | `message` |\n| `argsPattern` (regex on the serialized args) | `argsPattern` — plus a dsh-native object form `{ file_path: '…' }` matching per-argument values (the string form keeps JSON.stringify key order, not Gemini's sorted-key form — patterns spanning multiple keys may need adjusting; the object form has no such issue) |\n| `commandPrefix` / `commandRegex` (single or list) | same names, matched per command segment; `commandRegex` anchors at the segment start, like Gemini's at the command start |\n| `modes = [...]` | no counterpart — use separate dsh profile patch rows |\n| `allowRedirection` | not supported (dsh has no per-call redirection gate) |\n\n## Security\n\nA policy plugin is advisory gating, not containment: deny rules keep a well-behaved agent off dangerous commands, but the agent process still runs with host privileges. Pair with dsh's sandbox stack (`dsh-sandbox` + a confining executor) for OS-level enforcement, and note that dsh ships no authentication or authorization of its own.\n\n## Compatibility\n\n| @amaster.ai/dsh-policy | dsh | cordis |\n| --- | --- | --- |\n| 0.1.x | `0.1.5-rc.1` | `^4.0.1` |\n\nPeer dependency: `@deepseek-ai/dsh-tools` (the `tools/pre-execute` gate). The approval seam (`@deepseek-ai/dsh-user-approval`) is optional and only involved in `ask` decisions.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}