The "guardrails" topic on GitHub groups 11 open-source projects in the DeepSeek Harness (DSH) ecosystem, led by dsh-memory with 308 GitHub stars. dsh-memory — White-box AGI architecture exploration: metacognition (self-awareness loop), continual learning (knowledge flywheel), world model (condition space + semantic spatiotemporal graph), self-improvement (bootstrapping discipline), zero-LLM white-box pipeline and auditable trust guardrails. Every project here is indexed by DSH Universe with live GitHub data — stars, activity and install status — so you can compare and install directly.
A teammate posts one Slack message. Your AI assistant reads it, believes it, and hands over your keys through a link preview — nothing shows in the channel. Three plugins for the dsh agent harness stop the message before it leaves. Live demo you can run: real detectors, a real model as the victim.
Nine deterministic hooks that block a coding agent from weakening tests, swallowing errors, or stubbing type checks — each backed by a planted-failure test proving the guard can actually fire. Runs on Claude Code and DeepSeek Harness.
Indirect prompt-injection guard for DeepSeek Harness: taints tool output by origin, gates privileged calls that follow untrusted content, and refuses credentials heading off the machine.
DeepSeek Harness plugin: per-tool-call Auto-permission review powered by TypeSafe Jev, with account usage and API-key management inline on its settings page