Introduction¶
DeepSeek Harness (DSH) adopts an “everything is a plugin” architecture. When a model returns parameters through a tool call, they may contain sensitive information, such as API keys, private keys, or user credentials. dsh-secret-guard aims to intercept such payloads before tool execution, using a Fail-closed policy to prevent sensitive data leakage or misuse.
Plugin Scope¶
This is a security protection plugin for DSH tool calls, designed to detect sensitive payloads in tool parameters provided by the model.
- Owner: MkaliezZ
- Category: admin-security
- License: MIT
Core Features¶
The plugin intervenes at the tools/pre-execute stage, inspecting model-provided parameters before the tool body runs, and returns allow, ask, or deny.
- Heuristic detection: Recognizes common private key, token, or key patterns, as well as obvious sensitive field names.
- Size limit and Fail-closed: Limits the serialized payload size and directly blocks execution when the configured upper limit is exceeded.
- Scope control: Configures the list of protected tools via
protectedTools. When this field is empty, it means all tools are checked. - Action configuration: Specifies the behavior after sensitive information is detected via
actionOnFinding, supportingblock(blocking) orask(asking).
Installation and Enablement¶
No official installation command is currently provided. The plugin has been published to npm (package name @mkaliezz/dsh-secret-guard) and can be obtained via the catalog or repository.
Typical Usage¶
Include the plugin in the DSH configuration and set the corresponding policy. The following is an example based on verified features:
plugins:
- dsh-secret-guard:
protectedTools: [] # 空列表表示检查所有工具
actionOnFinding: block # block 或 ask
maxPayloadSize: 1024 # 载荷大小限制(需根据实际环境调整)
The plugin execution flow is as follows:
1. The model prepares to call a tool.
2. DSH triggers the tools/pre-execute hook.
3. The plugin checks the parameters and returns allow, ask, or deny.
4. If deny is returned, the tool body does not run; if allow or ask is returned, execution continues.
Applicable Scenarios and Cautions¶
Applicable scenarios: Scenarios that require preventing the model from accidentally leaking keys or sensitive data during tool calls.
Cautions:
1. This is heuristic-rule-based detection, not a complete DLP (Data Loss Prevention) solution, and cannot guarantee detection of all credential formats.
2. The v0.1 version does not include parameter desensitization; after detecting sensitive information, it only blocks or asks, and does not modify the original parameters.
3. It is not a sandbox or malware detector.
4. If broader action authorization is needed, it should be used together with policy boundaries (such as AgentFuse).
Summary¶
dsh-secret-guard provides the basic capability to intercept sensitive payloads before DSH tool calls. By configuring protectedTools and actionOnFinding, developers can perform a secondary validation before the model executes sensitive operations.
For more information, see: Plugin Directory | GitHub repository