In the development workflow of DeepSeek Harness (DSH), user messages often contain file paths. If these paths contain sensitive information or content outside the workspace, sending them directly to the model may introduce privacy leakage risks or noise. Existing approaches usually involve manual handling or restrictions in the system prompt, lacking a unified intermediate processing mechanism.

Plugin Overview

dsh-path-anonymizer is a DSH plugin maintained by the user yzhangjy. It detects out-of-workspace paths in user messages, replaces them with numbered placeholders, and asks the user for confirmation before sending the request to the model.

Core Features

  • Path Detection: Scans user messages for file paths using regular expressions.
  • Anonymized Replacement: Replaces detected external paths with numbered placeholders (such as [PATH_1]).
  • Workspace Awareness: Automatically recognizes and preserves paths inside the workspace, avoiding interference with model operations on the current project. Only paths outside the workspace are processed.
  • User Confirmation and Memory: Displays a dialog before initiating the model request, listing the paths and placeholders. The user can choose to send anonymized paths, real paths, or cancel the request, and can choose to remember the current selection for reuse.

Installation

Run the following command in the terminal to install it:

dsh plugin --profile web add github:yzhangjy/dsh-path-anonymizer

After installation, restart the web profile to activate the plugin.

Configuration and Usage

The plugin configuration is mainly set in YAML. Core configuration items include enabled (enable detection), confirmEveryTime (show the confirmation dialog for every request), autoAnonymize (silently replace paths without showing a dialog), anonymizeWorkspacePaths (whether to also anonymize paths inside the workspace, defaults to false), and detector.excludePatterns (exclude paths matching specific patterns).

Example 1: Automatic Anonymization Mode

- id: path-anonymizer
  config:
    enabled: true
    autoAnonymize: true

Example 2: Exclude Specific Path Patterns

- id: path-anonymizer
  config:
    detector:
      excludePatterns:
        - '^/nix/store/'
        - '^/home/ci/'

Notes

  • Regex Limitations: It relies only on regex matching, so paths embedded in complex code syntax may not be recognized or may be misdetected.
  • No File Validation: It does not verify whether the files corresponding to the paths exist.
  • Content Limitations: It only scans text blocks and does not process images or tool call content.
  • Not a Security Sandbox: It only processes user message text. It does not intercept model tool calls, parameters, or results, nor does it restrict file system access (that is the responsibility of the DSH sandbox mechanism).

Summary

If you need to control the leakage of sensitive paths in a DSH workflow, this plugin provides an intermediate processing layer based on user confirmation. It does not replace a security sandbox, but it provides additional privacy control over external paths at the message level.