The plugin-based architecture of DeepSeek Harness (DSH) allows developers to flexibly extend agent capabilities. When handling sensitive data and compliance auditing, manual checks are both tedious and prone to omissions. The enterprise-compliance plugin addresses compliance pain points in the DSH ecosystem by providing automated SOC2/GDPR checks, sensitive information interception, and operation log auditing.
Plugin Overview¶
This is an enterprise-level compliance plugin for DeepSeek Harness, maintained by xiaoliang2 and released under the MIT license. It provides automated SOC2/GDPR checks, sensitive information redaction, and audit traceability, and supports installation in Web and Desktop Profiles.
Core Features¶
1. Automated SOC2 / GDPR Compliance Self-Check¶
The compliance_report model tool reads runtime facts, evaluates CC6.1 / CC6.2 / CC7.2 / CC6.6 and GDPR Art.5 / Art.25 item by item, returns PASS / WARN / FAIL, and assigns scores. It supports export in summary / json / markdown formats and records historical score trends.
2. Sensitive Information Interception and Redaction¶
The compliance_redact model tool integrates nine regex rules (email addresses, mobile phone numbers, national IDs, bank cards, API keys, JWTs, Bearer tokens, private keys, and IP addresses). It is mounted to the session-telemetry/record waterfall pipeline and automatically redacts data before telemetry export, in line with the GDPR data minimization principle.
3. Operation Audit Traceability¶
The compliance_audit model tool listens to tools/result and records the timestamp, tool name, success/failure, session ID, and redacted parameters for each tool invocation. Audit data is persisted to settings.yaml, so evidence is not lost after restart. It supports filtering and export by tool/session/time.
4. Sensitive Data File Scanning¶
The compliance_scan model tool scans plaintext sensitive information in workspace files or directories and returns per-file hit statistics with redacted samples. It respects .gitignore by default and skips .git / node_modules directories. Scanning is limited to the workspace by default, but external scanning can be enabled with the allowOutside switch.
5. GDPR Data Subject Rights¶
Provides data export and erasure capabilities:
* compliance_data_export: exports collected data in accordance with GDPR Art.20.
* compliance_data_erase: one-click erasure of audit/history/alert status in accordance with GDPR Art.17 (confirmation required).
6. Threshold Alerts and Policy Management¶
- Policy read/write: The
compliance_policymodel tool can read/modify alert thresholds, audit persistence count, check toggles, redaction rule toggles, and the alert webhook. - Threshold alerts: Emits an
enterprise-compliance/alertevent when the score drops belowalertThreshold. - Alert webhook: After configuring
alertWebhook, when the score drops below the threshold or recovers, it POSTs JSON to the specified URL (5s timeout).
Installation and Activation¶
Install using npm:
dsh plugin add @xiaobanli/dsh-enterprise-compliance
After installation, this package is added to the profile’s dsh.profile.bundles, and cordis.patch.yml is automatically applied at the next startup. The plugin supports Web and Desktop Profiles.
Typical Usage¶
Generate a Compliance Report¶
# 读取运行时事实,输出 JSON 格式报告
compliance_report --format json
Redact Sensitive Information¶
# 对输入文本进行脱敏,返回脱敏后的结果与命中统计
compliance_redact "请拨打 13800138000 或访问 user@example.com"
View Audit Logs¶
# 导出审计日志,支持按工具或会话过滤
compliance_audit --export csv
Scan Sensitive Files¶
# 扫描当前工作区,跳过二进制文件与超过 1MB 的文本文件
compliance_scan
Erase Data¶
# 确认后擦除本插件采集的审计/历史/报警状态
compliance_data_erase --confirm true
Known Limitations¶
- Audit persistence does not include parameters:
argsexists only in the in-memory ring; the persisted fields are timestamp/tool/result/session/error, so parameters can no longer be queried after restart. - Persistence count limit: The default persistence count is 100 (adjustable via
policy.auditPersist), and the in-memory ring limit is 500. - File scanning limit:
compliance_scanskips binary files and text files larger than 1MB by default. - Data erasure scope:
compliance_data_eraseonly erases data collected by this plugin and does not affect other DSH data. - Runtime dependencies: Some check item results depend on whether runtime services are mounted (such as approval, credentials, persistence, and telemetry).
- Page dependency: The Compliance Center page depends on the
settingsservice being present; if it is missing, only page display is affected, not the model tools.
Ecosystem and Catalog¶
The plugin has been published to npm, and the source code is hosted on GitHub. The community catalog includes a detailed index for this plugin: https://www.skillhub.cn/plugins/xiaoliang2/enterprise-compliance.