x2802490130-prog/dsh-shield
DSH 脱手模式安全网:删除目录先进回收站、删除链接绝不跟随,零审批。
Listed
0
Dev
Bundle verified
What it does
A hands-off safety net: directories the agent deletes go to a trash folder first and symlinks are never followed, with zero approvals.
Best for
- Hands-off agent workflows that need directory deletions moved to recoverable trash without approval prompts.
- Users who want local trash inspection, restoration, deletion, and retention management from Settings.
- Workflows where symlinks must not be followed during protected deletion.
Not ideal for
- Workflows requiring deletion to be blocked until explicit approval; the plugin rescues targets but lets commands continue.
- Cases relying on unusual shell constructions beyond the documented single-target and common-glob coverage.
- Users who do not permit automatic cleanup after the configured age or size thresholds without adjusting those settings.
README
dsh-shield
DSH 脱手模式安全网:删除目录先进回收站、删除链接绝不跟随。零审批、零弹窗,agent 体验不变。
能力
-
目录删除先进回收站:bash 的
rm -r/-rf、cmd 的rmdir/rd/del /s、fs 工具的目录删除,执行前把目标 rename 进回收站(同卷瞬时),命令照常执行 -
glob 抢救:
rm -rf dir/*、dir/*.log逐个抢救子项;父目录是链接时顺链接解析,抢救真实目标内容 -
链接绝不跟随:
rm -rf link/自动改写为删链接本身 - 回收站管理:设置页「回收站」分区 —— 查看 / 恢复 / 删除 / 清空;超 14 天或 5GB 自动清理
-
可选系统回收站:配置
trashMode: system走系统回收站(失败自动回落)
配置(profile 补丁层,均可省略)
- id: dsh-shield
config:
trashRoot: D:\\path\\to\\trash # 默认 $DSH_HOME/trash
retentionDays: 14
maxTrashBytes: 5368709120
trashMode: dir # dir | system
安全边界
- 只抢救不拦截:命令仍会执行,agent 无感
- 单目标 + 常见 glob 场景已覆盖;极端 shell 花样以回收站兜底
- 管理 API 仅本机回环可用
测试
node test.mjs # 27 项
License
MIT
Frequently Asked QuestionsFAQ
Use the verified command dsh plugin --profile default add github:x2802490130-prog/dsh-shield in a DSH-enabled shell. The command resolves the public package metadata and keeps the plugin attached to the catalog identity shown on this page.
Compatibility follows the bundle and profile status shown above. If a profile is not detected, keep the plugin disabled there and check the repository documentation before enabling it in production.
The GitHub link and activity metadata are the source of truth for releases and maintenance. Revisit this page after a new release to confirm the catalog has observed the latest version.