When developing agents in the DeepSeek Harness (DSH) environment, manually copying and pasting API keys is a frequent operation. This operation can easily cause keys to leak into logs or model context. DSH itself does not provide an interception mechanism for paste behavior.
Below is an introduction to dsh-airbag, a non-intrusive security plugin that intercepts API keys pasted to the Agent, tracks leakage events, prevents keys from being written, and provides an initial workspace security health check.
Plugin Positioning¶
dsh-airbag is a security management plugin maintained by developer uwu9039 (MIT license). Its core value lies in building a security protection layer for keys within the DSH ecosystem by detecting paste and write behavior to prevent accidental exposure of sensitive information.
Core Features¶
The plugin mainly includes the following security capabilities:
- Paste Interception (A1): Synchronously detects content when users paste into the input box. It includes 45+ built-in key patterns (DeepSeek, OpenAI, AWS, GitHub PAT, JWT, PEM private keys, etc.) and supports block, redaction, or warning actions based on settings. All determinations are completed on the client side; plaintext keys are not sent to the model.
- Write Interception (A2): Detects whether model tool calls (such as
write,edit,bash,run_code) contain key parameters. It provides two handling options: hard interception or hand-off to the native approval channel. - Approval Fatigue Insights (B): As an observer of the native approval chain, it tracks decision time and marks “blind approvals” (<2s grants) and “fatigue periods” (dense approvals within 30 minutes).
- Corner Notification Center (G1): Provides four-level notifications (L0 silent, L1 badge, L2 toast, L3 persistent), supports aggregation of similar events within a 5-minute window, and supports global do-not-disturb.
- Initial Security Health Check (G6): Performs a read-only scan of the workspace, checking
.envfiles, credential files, embedded keys, etc., and reports only masked fragments. - Privacy First: Plaintext keys are never written to disk, recorded in logs, or included in telemetry. Only masked fragments (e.g.,
sk-0***cdef) and SHA-256 prefixes are persisted.
Installation and Enablement¶
Install the plugin using npm, then restart the DSH Web interface after installation.
dsh plugin --profile web add dsh-airbag
After successful installation, a 🛡️ Airbag button appears in the lower-right corner of the DSH interface. On first launch, the button displays a badge prompting you to run a security health check.
Typical Usage¶
- Open the panel: Click the 🛡️ button in the lower-right corner.
- Run the health check: Enter the workspace path in the “Check” tab of the panel and run the read-only security scan.
- Configure interception policy: Configure the default handling action (block / redact / warn) and notification level in the “Settings” tab.
- Customize rules: The plugin supports custom rules. The configuration file is located at
~/.dsh/airbag/rules.yaml.
Example configuration:
- pattern: 'INT_[A-Z0-9]{12}'
label: 内网 Token
action: block
severity: high
notice: 3
Notes¶
- System Requirements: Running the plugin requires Node.js
^22.19 || >=24and apnpmenvironment. - Privacy Mechanism: Ensure the privacy-first policy in the plugin configuration is active; plaintext keys will not be stored.
- Responsibility Boundary: Content redaction in the read direction is handled by the
dsh-guardianplugin;dsh-airbagfocuses only on paste and write interception. - Uninstall: To remove the plugin, run
dsh plugin --profile web remove dsh-airbag.
dsh-airbag provides a basic security protection layer for DSH workflows by intercepting paste and write behavior, combined with health check functionality. Developers can configure interception policies according to their actual needs. For more details and source code, refer to GitHub.