Preface¶
In agent development, it is essential to prevent XSS attacks when handling user input. DeepSeek Harness (DSH) uses a plugin-based architecture that allows users to extend local capabilities. dsh-html-escape is a utility plugin for HTML entity encoding and decoding, designed to address the conversion between special characters in user input and HTML entities.
Plugin Overview¶
This plugin is maintained by uckkk and is a pure Node.js implementation for escaping or unescaping HTML special characters and common entities.
Installation and Configuration¶
To install the plugin, run the following command in your local terminal:
dsh plugin add github:uckkk/dsh-html-escape
After installation, add "dsh-html-escape" to the dsh.profile.bundles configuration item in the package.json file of your profile for the plugin to take effect.
In addition, the following Peer Dependencies are required to install this plugin:
* @deepseek-ai/cordis (^4.0.1)
* @deepseek-ai/dsh-tools (>=0.1.0-rc.6)
Core Features¶
The plugin provides two core utility functions:
- html_escape: Used to escape HTML special characters. The specific scope includes
&,<,>,", and'. - html_unescape: Used to unescape HTML entities.
Usage Example¶
You can use the above utility functions by calling them in a DSH session. For example, escape user input containing a script tag to prevent XSS:
html_escape(text="<script>alert(1)</script>")
Notes¶
This plugin is a pure Node implementation. Installing it executes third-party code on your local machine, so please review the source code yourself.