Overview

DeepSeek Harness (DSH) may accidentally leak sensitive information (such as API keys and environment variables) when performing file operations. As a DSH plugin, secret-guard prevents keys from entering the conversation context by intercepting reads and writes to sensitive files before tool execution and applying content masking at the result layer.

Plugin Overview

Name: secret-guard
Maintainer: JohnXu22786
Category: admin-security
License: MIT
Core Purpose: Intercept reads and writes of sensitive files (such as .env files and credentials) and mask leaked keys.

This is a zero-build plugin that loads pure TypeScript source code and depends only on @deepseek-ai/dsh-tools and schemastery at runtime.

Core Capabilities

  1. Sensitive file interception: Intercept reads and writes of sensitive files (such as .env files and credentials) before tool execution to prevent leakage.
  2. Content masking: Apply content masking to tool results as a fallback to prevent already leaked content from entering the context.
  3. Security inspection tools: Provide sg_* tools that return only metadata (such as key names, line numbers, and fingerprints) and never return raw values.
  4. Audit logs: Record audit logs in JSONL format.
  5. Rule hot reloading: Support automatic hot reloading of rule files.

Installation and Configuration

Use the official installation command to add the plugin to the specified profile:

dsh plugin --profile demo add github:JohnXu22786/secret-guard

Remove the plugin:

dsh plugin --profile demo remove dsh-secret-guard

Check plugin status:

dsh --profile web --dump-config | grep -A 6 secret-guard

Environment Requirements

  • dsh ≥ 0.1.0-rc.6
  • Node.js ≥ 22.19 or ≥ 24
  • Runtime dependencies: @deepseek-ai/dsh-tools and schemastery

Local Development

During local development, you need to use an absolute path to override the plugin source code:

# dev-overlay.yml
- insert:
    - id: secret-guard-dev
      name: 'file:///D:/path/to/secret-guard/src/index.ts'
      config:
        maskResults: true

Run command:

dsh --profile headless --patch D:/path/to/secret-guard/dev-overlay.yml "list the current directory"

Notes

  1. Source restrictions: Source code must use strip-only type stripping for supported syntax (e.g., parameter properties are not allowed).
  2. Path resolution: Relative paths (such as sealKey.path and audit.dir) are resolved from dsh’s startup working directory.
  3. Matching rules: Matching is case-insensitive.

Summary

secret-guard provides a complete defense chain from interception to masking, making it suitable for development scenarios requiring strict confidentiality. For detailed information, see GitHub.