DeepSeek Harness (DSH) uses a pluggable architecture. When developing or debugging agents, models often receive inputs containing sensitive information such as API keys and tokens during the agent/pre-step phase. This data may be recorded in session logs, creating security risks. The dsh-model-redactor plugin rewrites these sensitive data entries into redacted versions before they enter session logs or model requests.
This plugin is maintained by zerodegress and is designed to intercept and rewrite the input stream visible to the model. It focuses on processing data before it reaches the model or persistent logs, ensuring that sensitive credentials are not leaked.
Core Features¶
The plugin intervenes in the data flow at two key stages: input and output.
-
Input redaction (
agent/pre-step)
Before user messages enter session logs and model requests, the plugin rewrites redacted copies of those messages. Recorded tool results are also redacted through session surface replacement, while the originalappend-originevents are retained in persistent logs. -
Output redaction (
llm/stream)
Before the agent loop records output, the plugin strips incremental data from text, reasoning traces, and tool call parameters. This ensures that logs and future model context remain consistent. At the same time,block-endpayloads are also redacted to prevent assembled assistant messages from reintroducing keys. -
Built-in rules
The plugin includes a fixed set of built-in redaction rules covering common formats, including OpenAI-stylesk-, Bearer, Basic authentication headers, GitHub and Slack tokens, JWTs, assignment patterns, PEM private key blocks, and AWSAKIAaccess key IDs.
Installation and Enabling¶
Installation requires adding an entry to the Cordis patch. Add the following lines to the configuration file:
- insert:
- id: dsh-model-redactor
name: dsh-model-redactor
config:
enabled: true
The package includes a cordis.patch.yml file and declares dsh.bundle.patch for bundled configuration files.
Configuration and Usage¶
Basic Configuration¶
Specify the replacement text through the replacement field. The default is [REDACTED]. The replacement text must be between 1 and 128 characters long and must not match built-in key patterns.
Custom Rules¶
customRegexes: Defines additional regular expression rules.customWords: Defines exact word matching rules.
Limitations¶
- Built-in rules are fixed and cannot be disabled.
- The replacement text must not match any built-in key patterns.
Use Cases and Cautions¶
This plugin is suitable for developers who need to handle sensitive data in DSH environments. Before use, check the source code and license (MIT). The plugin runs with the same permissions as the current DSH process, so ensure the source is trustworthy.
By implementing redaction in the context visible to the model, the plugin helps maintain secure logging and context management.