cc-safety-net: Blocking Dangerous Commands and Secret Access for DeepSeek Harness
kenryu42/cc-safety-net
A pre-execution guard for DeepSeek Harness and other coding CLIs that blocks destructive Git and filesystem commands and stops access to secrets like SSH keys and .env files before a tool call runs.
cc-safety-net is a pre-execution guard for AI coding agents that stops destructive actions before a tool call actually runs. It targets the real risks of agents deleting files, force-pushing branches, or reading SSH keys and .env credentials, blocking dangerous moves before they happen. The plugin parses what a command really does, so wrapping it or reordering flags does not hide it, and it adds GUI policy tuning, official rulebooks, and team policy sharing. Maintained by kenryu42 under the MIT license and written in TypeScript, it runs on Windows, macOS, and Linux and works as a DSH plugin inside DeepSeek Harness.
How to Install
dsh plugin --profile web add github:kenryu42/cc-safety-net- Category
- Development & Operations
- Platform
- DSH Plugin
- Author
- kenryu42
- Distribution
- Plugin
cc-safety-net Key Features
cc-safety-net Repo Summary
What Does It Do?
CC Safety Net is a DSH plugin for DeepSeek Harness that acts as a pre-execution guard, blocking destructive commands and secret access before a tool call actually runs. It solves the risk of AI coding agents deleting files, force-pushing branches, or reading SSH keys and .env credentials, stopping dangerous actions before they happen. Maintained by kenryu42 under the MIT license and written in TypeScript, it works on Windows, macOS, and Linux. Because it parses what a command really does, wrapping it or reordering flags does not hide it.
Core Features
- Blocks destructive commands: catches git reset --hard, git push --force, and rm -rf on dangerous targets, even when hidden inside bash -c or python -c.
- Protects secrets: stops the shell and the agent's file tools from reaching SSH keys, .env files, ~/.aws, and coding-CLI credentials.
- GUI policy tuning: offers Standard, Strict, and Paranoid presets with per-rule toggles, no hand-written config required.
- Rulebook extensions: ships official packs for Terraform, AWS, gcloud, and Azure, and accepts your own JSON rules.
- Team policy sharing: commit the policy directory to git so clones and cloud sessions inherit the same rules.
- Embeddable API: call the check function from Node.js to reuse the same logic without installing the hook.
How to Use This Plugin?
Once enabled in DSH, the plugin inspects every command and file access before the tool call runs, blocking matches and explaining why. Start by running a self-check to confirm protection is active, then use the GUI to switch presets or disable individual rules. For team-wide policy, commit the policy directory so other members and cloud sessions inherit the same rules. To reuse the logic in your own program, call the check function from Node.js. Note that it is not a sandbox: it does not contain processes, set filesystem permissions, or watch network egress.
How to Troubleshoot This Plugin?
A broken config file never blocks anything, which is a deliberate safety fallback, so if protection seems inactive, first verify the policy file parses correctly. If a command slips through, the rule is usually disabled or the preset is too permissive; adjust that rule in the GUI and retry.
This page is an independent rewrite of the plugin's official README — for authoritative documentation and the latest changes, refer to the source: kenryu42/cc-safety-net. The plugin is third-party code that runs on your machine once installed; inclusion does not imply endorsement — please review the source before installing.
