Introduction¶
DeepSeek Harness (DSH) provides infrastructure for agent development. However, during use, credential leakage, sensitive data appearing in logs or telemetry, and tampered tool calls are common risks. dsh-dlp is a Data Loss Prevention plugin for DeepSeek Harness, designed to strengthen security boundaries through tool guardrails, result redaction, and telemetry redaction.
Plugin Overview¶
dsh-dlp is a configuration-free tool guardrail, tool result redaction, and fail-closed telemetry redaction utility. It is maintained by CharlotteN7 and released under the MIT License. The plugin runs inside the DSH process to intercept model requests for credential material and remove sensitive information from output.
Core Features¶
The plugin provides the following core capabilities:
- Rejects credential file access and network-bound keys: This is the plugin’s only unconditional restriction, implemented by testing the path-type parameter with
ctx.tools.guard(). - Redacts keys from tool results: Cleans results before the model reads them and before session logging. Any part that cannot be redacted causes the result to be withheld.
- Redacts keys from step input messages: Processes content such as context, captured terminal panels, and hooks’
additionalContext. - Redacts keys from exported telemetry: Prevents
DSH_TELEMETRY_MODE=FULLfrom sending message text, tool parameters, results, and workspace paths in plaintext. - Detects payment card numbers: Uses issuer range, length, and the Luhn check digit for detection.
- Strips invisible characters: Removes invisible characters that may carry hidden instructions (such as Tags blocks, bidirectional control characters, and variant selectors), and strips terminal control sequences from the audit lane.
- Neutralizes remote Markdown images: Handles remote images in assistant output.
- Detects tool call rewriting: Detects tool calls that are rewritten by other plugins after session logging.
- Asks before file writes that change future behavior: Prompts before writing configuration files, rules directories, prompt templates, Git hooks, and similar files.
- Asks before calls that suppress its own confirmation: Prompts before setting
non_interactive: true,approval_mode: auto, or a pendingapply. - Writes decision audit records: Writes an audit record for each decision, including denials, redactions, prompts, and rewriting detections.
Installation and Configuration¶
Installation¶
Install the plugin using the DSH CLI:
dsh plugin --profile <name> add dsh-dlp
Configuration¶
After installation, configure the plugin parameters. The following is a typical configuration example:
- id: dsh-dlp
config:
aggressiveness: medium # low | medium | high
auditLog: /var/log/dsh-dlp.audit.l
redactionKeyFile: /var/lib/dsh/dsh-dlp.redaction-key
policyFile: ./.dsh-dlp.yml # optional
breadthTier: true
resultRedaction: true
telemetryRedaction: true
stepContextRedaction: true
claimedInputRedaction: true
configWriteAsk: true
approvalSuppressionAsk: true
Parameters¶
- aggressiveness: Aggressiveness level:
low(only guarantees switch independence),medium(default; ensures all switches are enabled), andhigh(redacts user input). - redactionKeyFile: Path to the redaction key file. A 32-byte random key is automatically created during installation with permissions set to
0600. It should not be included in version control. - auditLog: Path to the audit log.
Notes¶
- Runtime model: The plugin runs in-process and is not an isolation boundary. Any command that a DSH process can execute (such as
bash,run_code, or mounted MCP servers) can still read files denied by the plugin or open its own sockets. The plugin can only intercept credential material requested by the model through tools; it cannot stop code that is already running. - Unconditional restriction: Only “rejecting credential file access” is absolute and unconditional. Other restrictions (such as result redaction and prompts) can be overridden or neutralized by listeners registered by other plugins.
- Shell command limits: Shell command limits are advisory pattern matching, not hard controls. If the path spelling is altered (for example, glob characters, Base64 encoding, or homoglyph substitution), detection may be bypassed.
- Detection mechanism: Detection is pattern-based and does not support entropy rules. Encoded forms (such as Base64) can bypass detection, and homoglyphs can also bypass rules. Payment card number detection is based on the Luhn checksum and issuer range.
Summary¶
By adding a Data Loss Prevention layer to DeepSeek Harness, dsh-dlp helps developers protect sensitive information. It is suitable for scenarios where sensitive data leakage in logs, telemetry, and tool results must be prevented. Before using it, carefully review the source code and license, and understand the limitations of its in-process operation and pattern-based detection.
- Catalog page: dsh-dlp - SkillHub
- GitHub repository: CharlotteN7/dsh-dlp