The plugin-based architecture of DeepSeek Harness (DSH) allows developers to flexibly extend agent capabilities. When handling sensitive data and compliance auditing, manual checks are both tedious and prone to omissions. The enterprise-compliance plugin addresses compliance pain points in the DSH ecosystem by providing automated SOC2/GDPR checks, sensitive information interception, and operation log auditing.

Plugin Overview

This is an enterprise-level compliance plugin for DeepSeek Harness, maintained by xiaoliang2 and released under the MIT license. It provides automated SOC2/GDPR checks, sensitive information redaction, and audit traceability, and supports installation in Web and Desktop Profiles.

Core Features

1. Automated SOC2 / GDPR Compliance Self-Check

The compliance_report model tool reads runtime facts, evaluates CC6.1 / CC6.2 / CC7.2 / CC6.6 and GDPR Art.5 / Art.25 item by item, returns PASS / WARN / FAIL, and assigns scores. It supports export in summary / json / markdown formats and records historical score trends.

2. Sensitive Information Interception and Redaction

The compliance_redact model tool integrates nine regex rules (email addresses, mobile phone numbers, national IDs, bank cards, API keys, JWTs, Bearer tokens, private keys, and IP addresses). It is mounted to the session-telemetry/record waterfall pipeline and automatically redacts data before telemetry export, in line with the GDPR data minimization principle.

3. Operation Audit Traceability

The compliance_audit model tool listens to tools/result and records the timestamp, tool name, success/failure, session ID, and redacted parameters for each tool invocation. Audit data is persisted to settings.yaml, so evidence is not lost after restart. It supports filtering and export by tool/session/time.

4. Sensitive Data File Scanning

The compliance_scan model tool scans plaintext sensitive information in workspace files or directories and returns per-file hit statistics with redacted samples. It respects .gitignore by default and skips .git / node_modules directories. Scanning is limited to the workspace by default, but external scanning can be enabled with the allowOutside switch.

5. GDPR Data Subject Rights

Provides data export and erasure capabilities:
* compliance_data_export: exports collected data in accordance with GDPR Art.20.
* compliance_data_erase: one-click erasure of audit/history/alert status in accordance with GDPR Art.17 (confirmation required).

6. Threshold Alerts and Policy Management

  • Policy read/write: The compliance_policy model tool can read/modify alert thresholds, audit persistence count, check toggles, redaction rule toggles, and the alert webhook.
  • Threshold alerts: Emits an enterprise-compliance/alert event when the score drops below alertThreshold.
  • Alert webhook: After configuring alertWebhook, when the score drops below the threshold or recovers, it POSTs JSON to the specified URL (5s timeout).

Installation and Activation

Install using npm:

dsh plugin add @xiaobanli/dsh-enterprise-compliance

After installation, this package is added to the profile’s dsh.profile.bundles, and cordis.patch.yml is automatically applied at the next startup. The plugin supports Web and Desktop Profiles.

Typical Usage

Generate a Compliance Report

# 读取运行时事实,输出 JSON 格式报告
compliance_report --format json

Redact Sensitive Information

# 对输入文本进行脱敏,返回脱敏后的结果与命中统计
compliance_redact "请拨打 13800138000 或访问 user@example.com"

View Audit Logs

# 导出审计日志,支持按工具或会话过滤
compliance_audit --export csv

Scan Sensitive Files

# 扫描当前工作区,跳过二进制文件与超过 1MB 的文本文件
compliance_scan

Erase Data

# 确认后擦除本插件采集的审计/历史/报警状态
compliance_data_erase --confirm true

Known Limitations

  • Audit persistence does not include parameters: args exists only in the in-memory ring; the persisted fields are timestamp/tool/result/session/error, so parameters can no longer be queried after restart.
  • Persistence count limit: The default persistence count is 100 (adjustable via policy.auditPersist), and the in-memory ring limit is 500.
  • File scanning limit: compliance_scan skips binary files and text files larger than 1MB by default.
  • Data erasure scope: compliance_data_erase only erases data collected by this plugin and does not affect other DSH data.
  • Runtime dependencies: Some check item results depend on whether runtime services are mounted (such as approval, credentials, persistence, and telemetry).
  • Page dependency: The Compliance Center page depends on the settings service being present; if it is missing, only page display is affected, not the model tools.

Ecosystem and Catalog

The plugin has been published to npm, and the source code is hosted on GitHub. The community catalog includes a detailed index for this plugin: https://www.skillhub.cn/plugins/xiaoliang2/enterprise-compliance.