Destructive-command interception gate for dsh: parses shell semantics, judges risk against 41 built-in rules, and holds irreversible rm -rf, git reset --hard, and git push --force style commands at a confirmation gate.
- License
- MIT
- Added
- 2026-08-16
GitHub info
- License
- MIT
- Primary language
- JavaScript
- Last push
- Aug 16, 2026, 3:13 PM
- Maintainer
- JohnXu22786
- Added
- 2026-08-16
Install
dsh plugin --profile web add github:JohnXu22786/safety-netREADME badge
Add this Markdown to your plugin README to link back to its listing.
[](https://dshget.com/plugins/JohnXu22786/safety-net)Related plugins
Security & Permissionssecret-guard
★ 1Blocks agents from reading or writing sensitive files (.env, credentials, key material), masks leaked secret-shaped values in tool results, keeps an audit journal, and exposes safe sg_* inspection tools that never print raw values.
api-relay-audit
★ 819Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.
dsh-pentest
★ 324Authorized pentest mode for DeepSeek Harness — exploration chain, assets and findings with a Web view.