Introduction¶
DeepSeek Harness (DSH) runs under Node process permissions on the host machine. When installing plugins via dsh plugin add, underlying lifecycle scripts such as prepare / preinstall are executed before the plugin’s apply(). In addition, when the Agent invokes MCP or external tools, it has permissions to read or write local files, access secrets, and send data. The traditional “install first, then load” plugin mechanism cannot intercept malicious behavior during the installation stage.
dsh-shield is a security, trust, and policy layer designed to address these issues. It does not rely on “blind trust” to run tools, but instead builds security boundaries through “verification.”
What Is It¶
dsh-shield is a security firewall for DeepSeek Harness. It adopts a two-layer architecture that shares the same security model to intercept risks both before installation and at runtime:
- Pre-check Scanner (CLI): Before
dsh plugin add, it downloads, unpacks, and parses target code without executing it. It analyzes source code using AST (Abstract Syntax Tree) rather than simple regex matching. - Runtime Guardrails (Harness Plugin): Inside Harness, it intercepts tool calls, MCP interactions, and data egress. It hooks into the official
tools/pre-executeandctx.tools.guard()interfaces.
Core Features¶
Based on verified facts, dsh-shield provides the following capabilities:
- Pre-installation scanning: Performs static scans of directories, archives, GitHub repositories, or npm packages to check source code risks.
- Runtime interception: Intervenes before tool execution and returns
allow,ask, ordenybased on policy. - Post-operation audit: Records all security decisions and operation logs.
- MCP security management: Distinguishes “unknown” MCP Servers from “reviewed” ones and controls read/write permissions.
- Data egress control: Restricts data leaving the local machine based on data classification (public, internal, personal, confidential, credential, secret).
- Prompt Injection detection: Identifies imperative injection phrasing and combines behavioral policies to block it (e.g.,
SHIELD-INJECT-002). - Multi-level policies: Supports four policy levels:
permissive(loose),balanced(balanced, default),strict(strict), andenterprise(enterprise). - Trust manifest generation: Generates a JSON file containing package name, source, commit, risk score, and capabilities for trust repository management.
Installation and Enablement¶
Before use, ensure Node.js 20+ and pnpm are installed.
1. Install the Pre-check Scanner (CLI)¶
Before installing any Harness plugin, first install and build the dsh-shield CLI:
git clone https://github.com/245678000000/dsh-shield.git
cd dsh-shield
pnpm install
pnpm build
pnpm link --global
Verify the installation:
dsh-shield --help
dsh-shield doctor
2. Install the Runtime Guardrails (Plugin)¶
Install it into the local directory of DeepSeek Harness (Note: do not install source code directly via git unless it has been scanned and locked to a SHA):
dsh plugin --profile web add /你的路径/dsh-shield
After installation, restart dsh web (or the corresponding profile). The default policy is balanced. The custom policy file is located at:
~/.dsh-shield/policy.yaml
Typical Usage¶
After installation, you can use the following commands before installing plugins or during runtime.
Pre-check Scanning¶
Scan a synthetic plugin that would spawn a process (it will not be executed):
dsh-shield scan ./fixtures/plugins/process
The scan result shows a risk level (e.g., HIGH / REVIEW BEFORE INSTALLING). Scanning a clean plugin shows no high-risk findings:
dsh-shield scan ./fixtures/plugins/clean
Trust and Policy Management¶
Generate a trust manifest to record package metadata and risks:
dsh-shield manifest ./fixtures/plugins/process
Check policy matching for a specific target:
dsh-shield policy check <target>
Compare scan results from different versions:
dsh-shield diff old.json new.json
Use Cases and Notes¶
- Use cases: Developers who need to manage a large number of third-party plugins or MCP Servers in DSH; teams sensitive to data egress; security operations teams that need to audit Agent behavior.
- Key notes:
- dsh-shield does not run
npm installorrequire()on the target; it only performs AST analysis. - It does not claim 100% security, nor can it prove that any plugin is absolutely harmless.
- If the policy configuration is corrupted, the system adopts a “fail closed” (deny) policy and does not silently allow operations.
- This plugin does not rely on forking the AgentLoop or modifying Harness source code; instead, it integrates through officially provided hooks.
- dsh-shield does not run
Short Conclusion¶
dsh-shield provides DeepSeek Harness with a practical layer of security guardrails through a closed loop of “scan-classify-intercept-audit.” It does not guarantee perfect defense, but it can identify risks before installation, control sensitive operations at runtime, and is a necessary component for building a trustworthy Agent toolchain.
More details and source code:
* GitHub: https://github.com/245678000000/dsh-shield
* Plugin directory: https://www.skillhub.cn/plugins/245678000000/dsh-shield