Preamble

DeepSeek Harness (DSH) agents place third-party text into the same context channel as operator instructions when browsing webpages or reading repositories. Because the model lacks a reliable means of distinguishing sources, web content, README files, or MCP tool results may induce the agent to execute sensitive commands or publish files. This plugin does not attempt to make the model immune to such attacks; instead, it uses source taint to limit the scope of influence of third-party text, intercepts subsequent privileged calls, and directly refuses when credentials are detected in parameters.

Plugin Overview

This plugin is maintained by sashankh, belongs to the admin-security category, and is licensed under MIT. It is an indirect prompt injection protection tool designed for DeepSeek Harness, aiming to provide relatively controllable protection through data-flow tracking.

Core Features

This plugin primarily provides the following capabilities:
* Indirect prompt injection protection: Detects and responds to indirect injection attempts.
* Source taint: Marks whether tool output comes from an untrusted source.
* Privileged call interception: Restricts subsequent privileged tool calls based on taint status.
* Credential refusal: Unconditionally refuses to pass credential material to network tools.
* Operating modes: Supports observe, ask, and deny modes.

Installation and Enablement

During installation, specify the profile name and use the official prebuilt package:

dsh plugin --profile <name> add https://github.com/sashankh/dsh-taintguard/releases/download/v0.1.0/dsh-taintguard-0.1.0.tgz

After installation, verify that the plugin layer has been added by running dsh --profile <name> --dump-config.

Configuration and Usage

It is recommended to run in observe mode first, observe how the plugin marks traffic, and then switch to ask or deny mode after confirming the behavior is correct.

- id: taintguard
  name: dsh-taintguard
  config:
    mode: observe

How It Works and Limitations

The plugin was evaluated using AgentDojo v1.2.1:
* Content detector: Captured only 9.9% of attack payloads (35/355), and was ineffective against misspellings (such as iunstructions). Therefore, it cannot serve as a security boundary and can only be used as a telemetry signal.
* Source taint: Captured 100% of injection attacks, but restricted 97.6% of critical calls (80/82). This is a “rough but comprehensive” defense strategy.

The core value of the plugin lies in unconditionally refusing to pass credential material to network tools, thereby blocking data exfiltration paths.

Compatibility

  • Node.js: Requires Node.js >= 22.
  • DeepSeek Harness: Compatible with @deepseek-ai/dsh-tools, dsh-llm ^0.1.0-rc.6, and @deepseek-ai/cordis ^4.0.1.

Summary

dsh-taintguard provides a source-based data-flow tracking mechanism for DeepSeek Harness. Although its pattern detector has limitations, the source taint and credential refusal mechanisms can mitigate the risk of indirect prompt injection to some extent.