阻止DeepSeek Harness代理读取您的凭证文件并将机密粘贴到工具调用中
Stops a DeepSeek Harness agent from reading your credential files and pasting secrets into tool calls
安装
dsh plugin --profile web add github:CharlotteN7/dsh-dlpGitHub 源码安装:首次需按提示配置 allowBuilds 构建授权后重试
安装与环境配置指引、插件开发教程见 DSH 中文社区文档 ↗
安装即在你的机器上以你的权限运行第三方代码——它可读写文件、使用凭据、访问网络,DSH 的工具审批不会为插件代码加沙箱。「检测到 manifest」仅代表发现 dsh.bundle / dsh.plugin 清单,不构成兼容性或安全审查;安装前请审阅源码,不熟悉的插件先在不含密钥的环境试用。
README
目录
Data-loss prevention for DeepSeek Harness, built as an out-of-repo plugin.
What it does
- Denies credential-file access and secrets bound for the network — unconditionally, from
ctx.tools.guard(), testing path-typed arguments against a table of credential stores and following symlinks first. - Redacts secrets out of tool results before the model reads them and before the session log records them, withholding a result it cannot clean.
- Redacts secrets out of exported telemetry, closing a hole where
DSH_TELEMETRY_MODE=FULLships message text, tool arguments, results and workspace paths in the clear. - Strips invisible characters that carry hidden instructions — the Tags block, bidi overrides, runs of variation selectors — and strips terminal control sequences from the audit lane so a tool result cannot forge its own audit record.
- Neutralises remote markdown images in assistant output and detects a tool call another plugin rewrote after the session log recorded it.
- Asks before the agent writes a file that changes future behaviour — agent settings and
hooks,
CLAUDE.md,.claude/rules/**and the other agent rules directories, prompt templates,.vscode/tasks.json,.mcp.json, git hooks, CI workflows, shell startup files,pnpm-workspace.yaml— and before it writes a*_BASE_URLthat would redirect a provider credential. - Asks before a call switches off its own confirmation —
non_interactive: true,approval_mode: auto, anapplywhose approval is still pending. Bothasktiers are prompts rather than controls: they live attools/pre-execute, they can be neutralised, and they abstain wherever the approval seam prompts nobody — which includes every install underDSH_PERMISSION_MODE=danger-full-accessand a stock headless install under any mode. - Writes an audit record for every decision. A redaction or denial names the rule, its
version, the offsets and a keyed hash; the three kinds with no matched region to describe —
an ask, a rewritten call, a neutralised image — carry a rule id, the changed field names or
the destination hostname instead. Never the secret, never the path or command that matched.
dsh-dlp reportreads it back.
What this is not
This is not a containment boundary. The plugin runs in-process, at the agent's own uid.
Anything the agent can execute — a bash command, a run_code program, a mounted MCP server —
can read every file the guard denies and open its own sockets without the plugin seeing anything.
It closes the path where the model asks for credential material through a tool. It does not stop
code that is already running. If you need containment, that is the sandbox, landlock-run,
filesystem permissions and egress firewalling.
Three limits worth knowing before you rely on it:
- Only the guard floor is unconditional. Every other seam can be neutralised by a listener
registered ahead of ours.
ctx.tools.guard()is order-independent only because it has no allow arm. - The shell-command arm is advisory pattern-matching. It tests the whole command line and
each of its tokens, so a credential path left spelled in the command is caught whatever
program would open it:
python3 -c "open('~/.ssh/id_rsa')"is denied. Changing the spelling defeats it — one glob character, quote-splitting,find -exec, a substitution that assembles the path from pieces, a base64 round-trip, each verified. Do not count this arm as a control. - Detection is pattern-based. No entropy rule (measured, not assumed: at a false-positive-free threshold the miss rate is 100% below 22 characters). Encoded forms pass. A homoglyph defeats every rule in this package.
Install
A profile carrying only @deepseek-ai/dsh-base has no agent loop, so add a runnable bundle
alongside it or there is nothing for this plugin to guard:
dsh plugin --profile <name> add @deepseek-ai/dsh-headless@0.1.0-rc.6
dsh plugin --profile <name> add dsh-dlp
dsh --profile <name> --dump-config # the dsh-dlp row should appear
Any harness from 0.1.0-rc.6 onwards in the 0.1.x line works: the peer ranges accept it and CI
runs the end-to-end suite against every published rc in that range.
Pin @deepseek-ai/dsh-headless explicitly — its npm latest tag still points at 0.0.1-rc.1.
The package ships a cordis.patch.yml bundle layer, so listing it in dsh.profile.bundles mounts
it with working defaults.
Install from the registry or a packed tarball, not from a git spec: lib/ is a build output
git does not carry and no prepare script rebuilds it, so a git-spec row mounts and then fails to
load.
Configure
- id: dsh-dlp
config:
auditLog: /var/log/dsh-dlp.audit.jsonl
redactionKeyFile: /var/lib/dsh/dsh-dlp.redaction-key
policyFile: ./.dsh-dlp.yml # optional, lowest trust
breadthTier: true
resultRedaction: true
telemetryRedaction: true
configWriteAsk: true
approvalSuppressionAsk: true
redactionKeyFile is created on first mount with 32 random bytes at mode 0600. Keep it out of
version control — it is what makes a placeholder's hash keyed rather than a bare digest anyone
holding a candidate secret could confirm.
The guard floor has no configuration. Credential-path denial and secret-argument denial are
security invariants, not deployment-varying tunables. A repo-local policyFile is the lowest
trust rank and may only tighten: add deny patterns, add egress tool names, raise a severity,
switch a pass on. Any downgrade makes the whole file invalid.
Configuration reference → · What gets denied → · Redaction and detection →
Reading the audit log
dsh-dlp report # everything in the audit sink
dsh-dlp report --since 24h
dsh-dlp report --session <id>
dsh-dlp report --would-have # everything except the denials
A redaction or denial record carries a rule id, rule version, span offsets and a keyed hash — never the matched value. An ask carries its rule id, a rewritten call the names of the fields that changed, and a neutralised remote image the destination hostname in the clear; none of those has a matched region to hash.
Mitigations for defects in the harness itself
Three registrations work around defects in DeepSeek Harness rather than in your configuration:
remote markdown images in assistant output, a tool call rewritten between tools/pre-execute and
the guard, and a telemetry redactor that cannot run under the shipped default. None of them
closes its channel and an upstream fix is better in all three cases.
What each one does and does not close →
Development
nvm use 22 # Node ^22.19.0 || >=24, and pnpm 11
pnpm install
pnpm run typecheck
pnpm run test:coverage
pnpm run test:e2e # boots a real dsh against a mock model; no API key
Coverage is gated at 100% per file: this is a security control, so an untested branch in a deny path is an unproven deny path.
Design decisions and their rationale live in ADR.md. Security policy is in SECURITY.md.
License
MIT
原始 README: https://github.com/CharlotteN7/dsh-dlp/blob/main/README.md ↗
同类插件
查看全部 →
deepseek-harness
从仓库或系统描述生成经过校验的自包含交互式架构图、流程图、时序图、数据流图和生命周期图。

dsh-plugin
通过 DSH MCP 客户端挂载 Ouroboros 的纯配置包,在 DSH 中提供 36 个涵盖需求访谈、Seed、执行、评估与演化流程的工具。

dsh-tongflow
基于 TongFlow 的“片场”插件,用于图片、配音、音乐与视频制作:agent 为每个资产生成 TongFlow 工作流文件(.tongflow.json)并通过 TongFlow 插件执行,内嵌工作流画布,按镜头/角色/take 组织项目,附漫剧模板;以 @tongflow 开头的会话进入 Studio 界面。

helloagents
AI 编码 CLI 的工作流层:技能、项目知识、交付检查、更安全的配置写入与可恢复执行

dsh-ai-novel-writer
安装专用 AI 小说创作预设与工作台:提供带修订号的本地项目资产、紧凑侧边工作台,以及需要原生审批的逐文件变更。

rea
用 agent 逆向任何东西:从应用行为到原生二进制