dsh-plugin-warroom-garak
by lukethecat
新增一个面向模型的 garak scan 工具:对目标 LLM 端点做经授权的 garak 基线红队扫描,内置授权门
A DeepSeek Harness plugin that adds one model-facing tool, garak scan — an authorized garak baseline red-team sweep against a target LLM endpoint, with a built-in authorization…
安装
dsh plugin --profile web add github:lukethecat/dsh-plugin-warroom-garakGitHub 源码安装:首次需按提示配置 allowBuilds 构建授权后重试
安装与环境配置指引、插件开发教程见 DSH 中文社区文档 ↗
安装即在你的机器上以你的权限运行第三方代码——它可读写文件、使用凭据、访问网络,DSH 的工具审批不会为插件代码加沙箱。「检测到 manifest」仅代表发现 dsh.bundle / dsh.plugin 清单,不构成兼容性或安全审查;安装前请审阅源码,不熟悉的插件先在不含密钥的环境试用。
README
A DeepSeek Harness plugin that adds one model-facing tool, garak_scan — an authorized
garak baseline red-team sweep against a target LLM endpoint,
with a built-in authorization gate, a budget cap, and an auto-written evidence report.
Part of the war-room approach: garak owns the probes (the "weapons"); this plugin is the orchestrator that runs them against an authorized target, keeps the run in the dsh session log (auditable/replayable), and produces a compliance-ready evidence artifact.
v0 / developer preview. Built against
@deepseek-ai/dsh-*0.1.0-rc.xand modeled on the officialdsh-tool-webplugin. Two seams are version-sensitive and may need a small fix on first build in your environment — both are commented in the source:
defineToolparameter/output schema DSL (src/index.ts)- garak report JSONL field names / hit detection (
src/garak.ts)
What it does
- Refuses to run unless
authorization.authorized === truewith a non-emptyscope. - Caps attempts per probe at
maxGenerations(budget / circuit-breaker). - Spawns garak against your REST target, parses the JSONL report into per-probe hit rates.
- Writes a one-page Markdown evidence report (target, scope, tool+time, per-probe table, overall hit rate, pointer to the raw garak report for reproduction).
- Returns a summary + report path + metrics as the tool result (a durable session event).
Prerequisites
- A working DeepSeek Harness install.
- garak on PATH (
pipx install garakorpip install garak; verifygarak --version).
Build
# pin dsh-* deps to your installed dsh version first: npm ls @deepseek-ai/dsh-tools
npm install
npm run build # tsdown -> lib/
Install into dsh
Add the plugin as an entry in your dsh profile / cordis config (the composition file that lists plugins), then restart dsh:
# in your dsh profile's cordis config (e.g. cordis.patch.yml / cordis.yml)
- name: 'dsh-plugin-warroom-garak'
config:
garakBin: 'garak' # 'garak' (CLI on PATH), an absolute path to the garak console
# script (pipx/pip install), or 'python' to use `python -m garak`
maxGenerations: 5
reportDir: '.warroom/reports'
Confirm it mounted: dsh --profile <yours> --dump-config should list the entry, and the agent
should now have a garak_scan tool.
Use (example tool call)
{
"target_id": "staging-chatbot",
"authorization": { "authorized": true, "scope": "staging API only, 2026-08", "authorized_by": "jaco" },
"rest_config": {
"rest": {
"RestGenerator": {
"uri": "http://127.0.0.1:8080/v1/chat/completions",
"method": "post",
"headers": { "Authorization": "Bearer $TOKEN", "Content-Type": "application/json" },
"req_template_json_object": { "model": "target", "messages": [{ "role": "user", "content": "$INPUT" }] },
"response_json": true,
"response_json_field": "$.choices[0].message.content"
}
}
},
"probes": ["promptinject", "dan"],
"generations": 3
}
The evidence report lands under reportDir. The raw garak report path is embedded for full reproduction.
Safety
- Authorized targets only. The tool hard-refuses without an authorization scope.
- No attack payloads in this repo — garak provides the probes. This plugin only orchestrates, bounds, and documents. Defensive use (hardening your own / authorized systems) only.
License
MIT. Wraps garak (Apache-2.0); built on DeepSeek Harness / Cordis (MIT).
原始 README: https://github.com/lukethecat/dsh-plugin-warroom-garak/blob/main/README.md ↗
同类插件
查看全部 →
dsh-anchored-standard
两阶段 DeepSeek Harness 预设:先 Minimal 对齐的 bootstrap,再切完整 Standard 工具(Project2 98/99)

PicGo-Core
极致的图片上传引擎,CLI 与 API 双支持

awesome-deepseek-harness
DeepSeek Harness(DSH)及其优秀社区插件的精选指南。

awesome-deepseek-harness
DeepSeek Harness (DSH)生态系统:来自dsh-external/hub和公共dsh-plugin主题的精选插件、工具和基础设施。

AI-Novel-Writer
本地优先 AI 小说创作工作台,提供 Windows/macOS 桌面版与 DeepSeek Harness 插件开发预览,支持角色、大纲、章节蓝图、审稿修稿和本地模型。

mcp-for-stata
MCP-for-Stata:把 Stata 集成进你的 agent