Introduction¶
Ecosystem plugins for DeepSeek Harness (DSH) usually scan configuration files before an agent runs. dsh-egress-guard sits in the tool execution pipeline and performs security checks on the tool call itself. It works through three extension points: an egress host whitelist before execution, ciphertext redaction after execution, and a comprehensive append-only audit log.
Core Capabilities¶
As a runtime security gateway, dsh-egress-guard provides the following capabilities:
- Egress host whitelist (pre-execute): Checks network targets before tool execution. If the target is not in the allowlist (for example, initiating
curlto an unknown site or an unrecognizedgit push), it blocks or prompts for approval. - Ciphertext redaction (post-execute): Rewrites sensitive information in the result before it is returned to the model or persisted in the session.
- Append-only audit log (JSONL): Records every decision, including audit-only decisions in
monitormode that do not block. - Implementation approach: Based on documented extension point listeners, with no forking and no patch loops.
Installation and Activation¶
Installing the plugin does not break existing workflows. It defaults to monitor mode:
dsh plugin --profile <name> add dsh-egress-guard
The default configuration sets mode: monitor, meaning rules are evaluated and logged but do not block or rewrite anything. After confirming that the audit logs behave as expected, you can enable enforcement mode in cordis.patch.yml.
Configuration¶
The configuration file is located in the plugin’s cordis.patch.yml. After installation, completely override the config section for id: egress-guard in your configuration.
Basic Configuration Items¶
| Configuration item | Default | Description |
|---|---|---|
mode |
monitor |
monitor audits only; enforce blocks and redacts; off registers no rules. |
egress.allowHosts |
[] |
List of allowed hosts, with wildcard support (for example, *.github.com). An empty list means only the denylist is used. |
egress.denyHosts |
[] |
List of permanently denied hosts, with higher precedence than allowHosts. |
egress.allowLoopback |
true |
Allows loopback addresses such as localhost, 127.0.0.0/8, and ::1. |
egress.onViolation |
deny |
Action on violation. deny rejects directly; ask requests approval (falling back to deny if no approval service is mounted). |
redact.builtins |
true |
Automatically redacts built-in patterns (private keys, API keys, JWTs, Bearer headers, and so on). |
redact.extraPatterns |
[] |
Additional regular expression sources for matching custom ciphertext formats. |
redact.placeholder |
[redacted:{name}] |
Placeholder after redaction; {name} is the matched regular expression name. |
audit.path |
$DSH_HOME/egress-guard.jsonl |
Local path for the audit log. |
audit.logAllowed |
false |
Log calls that pass the check. Enable this option to build an allowlist from real traffic. |
Example Configuration¶
- id: egress-guard
config:
mode: enforce
egress:
enabled: true
allowHosts: ['*.github.com', '*.npmjs.org', 'api.deepseek.com']
denyHosts: []
allowLoopback: true
onViolation: deny
redact:
enabled: true
builtins: true
extraPatterns: []
placeholder: '[redacted:{name}]'
audit:
enabled: true
path: ''
logAllowed: false
Typical Usage: Building an Allowlist from Logs¶
After enabling audit.logAllowed: true and running the plugin for a while, you can analyze the hosts that are actually accessed and generate an allowlist with the following steps:
- Install the plugin and keep it running in
monitormode. - Modify the configuration to enable
audit.logAllowed: true, recording all requests that pass. - Analyze the log file and count the most frequently accessed hosts:
jq -r '.hosts[]?' ~/.dsh/egress-guard.jsonl | sort | uniq -c | sort -rn
- Add the legitimate hosts identified to
allowHostsand changemodetoenforce.
Limitations and Notes¶
- Security boundary positioning: It is a guardrail, not a fence. It raises the barrier for accidents or prompt injection but cannot stop an attacker who can run code on the machine.
- Detection mechanism: Detection is based on text scanning. Destinations constructed at runtime through string concatenation, Base64 encoding, or decimal IP assembly may not be detected.
- Process-level limitation: If a tool opens a socket by itself (unless the target address appears in its arguments), the gateway cannot intercept it.
- Redaction mechanism: It is based on regex patterns and may produce false positives on non-sensitive content or miss unknown ciphertext formats. Check audit logs for false positives before enabling enforcement mode.
- Binary content: The plugin does not scan binary content (for example, image blocks).
- Audit logs: Logs are stored locally and unsigned; any process that can write to the filesystem can tamper with them.
Compatibility¶
This plugin is built against the @deepseek-ai/dsh-tools 0.1.0-rc pipeline contract. The test suite runs on 0.1.0-rc.6, and four installation methods were validated in a dsh 0.1.0-rc.5 environment.
Summary¶
By inserting checkpoints into the tool call pipeline, dsh-egress-guard provides runtime-level egress control and data redaction capabilities for DeepSeek Harness. Combined with audit logs, it enables incremental construction of security policies, making it suitable for production scenarios that require controlling agent network behavior and reducing data leakage risk.
- Plugin directory: https://www.skillhub.cn/plugins/tancheng33/dsh-egress-guard
- Source code: https://github.com/tancheng33/dsh-egress-guard