DeepSeek Harness (DSH) uses a pluggable architecture. When developing or debugging agents, models often receive inputs containing sensitive information such as API keys and tokens during the agent/pre-step phase. This data may be recorded in session logs, creating security risks. The dsh-model-redactor plugin rewrites these sensitive data entries into redacted versions before they enter session logs or model requests.

This plugin is maintained by zerodegress and is designed to intercept and rewrite the input stream visible to the model. It focuses on processing data before it reaches the model or persistent logs, ensuring that sensitive credentials are not leaked.

Core Features

The plugin intervenes in the data flow at two key stages: input and output.

  1. Input redaction (agent/pre-step)
    Before user messages enter session logs and model requests, the plugin rewrites redacted copies of those messages. Recorded tool results are also redacted through session surface replacement, while the original append-origin events are retained in persistent logs.

  2. Output redaction (llm/stream)
    Before the agent loop records output, the plugin strips incremental data from text, reasoning traces, and tool call parameters. This ensures that logs and future model context remain consistent. At the same time, block-end payloads are also redacted to prevent assembled assistant messages from reintroducing keys.

  3. Built-in rules
    The plugin includes a fixed set of built-in redaction rules covering common formats, including OpenAI-style sk-, Bearer, Basic authentication headers, GitHub and Slack tokens, JWTs, assignment patterns, PEM private key blocks, and AWS AKIA access key IDs.

Installation and Enabling

Installation requires adding an entry to the Cordis patch. Add the following lines to the configuration file:

- insert:
    - id: dsh-model-redactor
      name: dsh-model-redactor
      config:
        enabled: true

The package includes a cordis.patch.yml file and declares dsh.bundle.patch for bundled configuration files.

Configuration and Usage

Basic Configuration

Specify the replacement text through the replacement field. The default is [REDACTED]. The replacement text must be between 1 and 128 characters long and must not match built-in key patterns.

Custom Rules

  • customRegexes: Defines additional regular expression rules.
  • customWords: Defines exact word matching rules.

Limitations

  • Built-in rules are fixed and cannot be disabled.
  • The replacement text must not match any built-in key patterns.

Use Cases and Cautions

This plugin is suitable for developers who need to handle sensitive data in DSH environments. Before use, check the source code and license (MIT). The plugin runs with the same permissions as the current DSH process, so ensure the source is trustworthy.

By implementing redaction in the context visible to the model, the plugin helps maintain secure logging and context management.