The core design philosophy of DeepSeek Harness (dsh) is “everything is a plugin,” enabling users to meet specific business needs through extensions. In agent development and operations scenarios, exporting session records is commonly used for auditing or compliance archiving. However, raw exported text often contains sensitive information, such as API keys, JWT tokens, environment variables, or absolute paths. dsh-session-export aims to solve this problem. It acts as a dependency, converting any current or historical session into a verifiable, redacted archive and providing the corresponding management tools.
This is a session export, redaction, and compliance archiving bundle for DeepSeek Harness (dsh). The plugin is maintained by JohnXu22786 and uses the MIT license. It does not depend on a model itself; instead, it performs redaction through a rules-based engine, supports multiple output formats, and provides full archive management capabilities.
Core Features¶
The plugin provides the following core capabilities:
-
Default deterministic redaction
Redaction mode is enabled by default, removing sensitive data through rules. Supported sensitive items include API keys, JWT tokens, high-entropy tokens,.env-style configuration lines, URL credentials, and absolute paths. Redacted values carry a salted SHA-256 fingerprint (12 hexadecimal characters), ensuring archive files remain correlatable across different machines without exposing the original secret. The fingerprint is determined by the secret value itself and is independent of the rule that matched it. -
Multiple output formats
Export results can be saved as Markdown (human-readable), JSONL (machine-readable), PDF (print-ready), or all formats. -
Archive management
Exported files are organized by session and date and stored in the default directory$DSH_HOME/exports(i.e.,~/.dsh/exports). Archives support searching, listing, and deletion, with path traversal protection implemented in deletion operations to ensure only files inside the archive root directory can be accessed. -
Compliance metadata
Each exported file includes an embedded metadata header recording the session id, model used, redaction level, event count, and an optional SHA-256 content hash. In addition, the plugin provides the/export-auditslash command to view export trends aggregated by day, format, session, or redaction level. -
No model dependency
The redaction process is rules-based and does not rely on large language models. If more advanced redaction is needed, optional LLM-assisted masking can be enabled through configuration.
Installation and Enablement¶
Installing this plugin requires a DeepSeek Harness environment and Node.js 20+ (Node 24+ is recommended to run source-code tests).
The installation command is as follows:
dsh plugin --profile demo add github:JohnXu22786/session-export
After installation, the plugin automatically injects configuration, with the default output directory set to $DSH_HOME/exports. You can override this setting in the configuration file.
Typical Usage¶
The plugin provides both tool calls and slash commands.
Tool Commands¶
In the DSH context, you can directly invoke the following tools:
session_export { format?, sessionId?, redact? }
Export a session. Ifformatis not specified, the default format is used. Theredactparameter controls whether redaction is enabled and defaults to enabled.session_export_list { query?, sessionId?, format?, before?, after?, limit? }
List or search archives. Results can be filtered by session id, date range, or format.export_delete { target }
Delete an archive by archive id or file name.
Slash Commands¶
Users can enter the following commands directly in the conversation:
/session-export: Trigger a session export./session-export-list: View the export list./export-delete: Delete a specified archive./sanitize-config: View or modify redaction configuration./export-audit: View compliance audit trends.
Use Cases and Considerations¶
This plugin is suitable for DSH users who need to meet compliance requirements and have high requirements for data security.
- Environment requirements: A DeepSeek Harness profile containing the base bundle must be configured, and the profile must provide base services such as
sessions,sessionPersistence,tools, andcommands. - Runtime permissions: The plugin runs with the permissions of the current DSH process, so you should review the source code and license before installation.
- Data security: Redaction fingerprints are generated using salted SHA-256 to preserve correlatability. Index writes are serialized within the process to prevent data loss caused by concurrent calls.
Summary¶
dsh-session-export provides a complete session export and compliance archiving solution for DeepSeek Harness. It addresses sensitive information leakage through default deterministic redaction and meets operations and compliance needs with archive management and audit views. All features are available through command-line and slash commands, requiring no additional development for integration.