The plugin ecosystem of DeepSeek Harness (DSH) emphasizes modularity. When developing agents that involve sensitive information, session logs, terminal UI, and tool execution usually retain the real values, but raw data carries a leak risk once it is sent in a network request. dsh-llmasking addresses this problem: it masks the data before it leaves the process, ensuring that the model only sees placeholders, while session logs, the UI, and tool execution still see restored real values in real time.

Plugin Overview

Name: yolorouter/dsh-llmasking
Category: admin-security
License: MIT
Maintainer: yolorouter

The plugin runs on DSH’s llm/stream plane. It intercepts every model call and builds an immutable masked copy to send to the model; at the same time, it wraps the response stream, restoring placeholders back to real values in the stream in real time. This achieves a security model in which logs preserve the truth while transmission carries masks.

Installation and Enablement

Before installing, make sure the environment meets the requirements: Node >= 22, DSH >= 0.1.0-rc.6 (last verified on 2026-08-16).

  1. Install the plugin:
    dsh plugin --profile my add dsh-llmasking
  1. Start the Harness:
    dsh --profile my
  1. Verify the plugin status:
    dsh --profile my --dump-config | grep -A1 "id: llmasking"
Or check the plugin status in the Web UI settings; it should be **active**.

Core Features

  • Transport-layer masking: Sensitive values are masked only during transit from the DSH process to the model provider; the raw values never leave the process.
  • General detectors: Supports emails, bank cards (with Luhn validation), IPs, URLs, international phone numbers, and key families (cloud keys/PEM/JWT/Git tokens/high-entropy secrets).
  • Regional rules:
    • CN: mobile numbers, ISO 7064-validated national IDs, landline numbers.
    • US: SSNs, phone numbers.
  • Custom keywords: Supports adding extra literal keywords for masking.
  • Session consistency: The same value is always mapped to the same placeholder in the current session.
  • One-way deletion: Masked placeholders (e.g., [SECRET_1]) cannot be reverse-mapped to the original values.
  • Stream processing: Intercepts every call on the llm/stream plane and handles placeholders split across SSE boundaries (flushing and concatenating at chunk end).
  • Zero-overhead passthrough: Requests without sensitive data take the zero-overhead passthrough path.
  • Failure safety:
    • Masking failure: The request is refused (Fail Closed).
    • Restoration failure: It is allowed through after logging a warning (Fail Open).

Configuration

The default configuration is sufficient and usually does not need modification. Configuration is performed through cordis.patch.yml and uses line replacement rather than deep merging.

- replace:
    - id: llmasking
      config:
        keywords: ["acme-corp-token"]
        regions: ["CN", "US"]
        maskSystem: true
        teachModel: true

Option descriptions:
* mode (default enforce): enforce enforces masking; monitor is shadow mode, counting only without masking, used to build trust.
* keywords (default []): Additional keywords that must be masked.
* regions (default all): Enabled geographic rule packages (e.g., CN, US).
* maskSystem (default true): Whether to mask system prompt slots.
* teachModel (default true): Whether to add an explanation of placeholders to the system prompt, requiring the model to reproduce them verbatim.

Usage and Monitoring

Slash Commands

  • /llmasking: View the current session’s masking status, mode, detector configuration, and statistics.
  • /llmasking verify: Run sentinel values locally through the real masking pipeline, displaying original value -> placeholder results to verify that the pipeline is working.
  • /llmasking status: Same as /llmasking.

Logging

Every masking operation writes a receipt line to the DSH log (only recording count and type, not specific values):

llmasking: 3 value(s) masked on the wire this turn (PHONE, EMAIL, SECRET)

Permissions and Data

  • File access: None. The plugin does not read or write user files; it only reads its own package manifest to obtain the version number.
  • Network calls: None. The plugin does not call any endpoints, telemetry, or third-party services; it only transforms requests already issued by DSH.
  • Credential access: None. API keys are transmitted via adapter headers; the plugin sits above the adapter and cannot access key material.

Ecosystem Context

DeepSeek Harness’s philosophy is “everything is a plugin.” dsh-llmasking, a community-maintained plugin, follows the MIT license. You can view the source code and directory in its GitHub repository: https://github.com/yolorouter/dsh-llmasking