Security

Permissions

The default-deny policy for phones and plugins, and what each client is allowed to do.

DSH’s default posture is deny: anything not explicitly allowed is refused.

Session permission modes

ModeScope
Planread-only exploration, produce a plan
Read-onlyread files, search, browse
Workspace writeedit files and run commands inside the workspace
Full accessstep outside the workspace, broader system actions

Per-client boundaries

ClientCanCannot
Phone (paired)the RPC channel and a short allowlist of routesplugin routes are default-deny; pairing and revocation return 403
Chrome extensionbrowse and control using the current profileupload cookies
Computer useread the accessibility tree, screenshot, deliver background inputact irreversibly without asking

Why plugin routes are denied by default

The mobile channel uses an exact route allowlist (such as /api/file, /api/session/uploadFileBinary, /api/remote.mux); any unlisted plugin route returns 404. This came out of an adversarial security review: a reachable device used to get the whole of /api, and now gets only what it needs.

Next