The core design philosophy of DeepSeek Harness (dsh) is “everything is a plugin,” enabling users to meet specific business needs through extensions. In agent development and operations scenarios, exporting session records is commonly used for auditing or compliance archiving. However, raw exported text often contains sensitive information, such as API keys, JWT tokens, environment variables, or absolute paths. dsh-session-export aims to solve this problem. It acts as a dependency, converting any current or historical session into a verifiable, redacted archive and providing the corresponding management tools.

This is a session export, redaction, and compliance archiving bundle for DeepSeek Harness (dsh). The plugin is maintained by JohnXu22786 and uses the MIT license. It does not depend on a model itself; instead, it performs redaction through a rules-based engine, supports multiple output formats, and provides full archive management capabilities.

Core Features

The plugin provides the following core capabilities:

  1. Default deterministic redaction
    Redaction mode is enabled by default, removing sensitive data through rules. Supported sensitive items include API keys, JWT tokens, high-entropy tokens, .env-style configuration lines, URL credentials, and absolute paths. Redacted values carry a salted SHA-256 fingerprint (12 hexadecimal characters), ensuring archive files remain correlatable across different machines without exposing the original secret. The fingerprint is determined by the secret value itself and is independent of the rule that matched it.

  2. Multiple output formats
    Export results can be saved as Markdown (human-readable), JSONL (machine-readable), PDF (print-ready), or all formats.

  3. Archive management
    Exported files are organized by session and date and stored in the default directory $DSH_HOME/exports (i.e., ~/.dsh/exports). Archives support searching, listing, and deletion, with path traversal protection implemented in deletion operations to ensure only files inside the archive root directory can be accessed.

  4. Compliance metadata
    Each exported file includes an embedded metadata header recording the session id, model used, redaction level, event count, and an optional SHA-256 content hash. In addition, the plugin provides the /export-audit slash command to view export trends aggregated by day, format, session, or redaction level.

  5. No model dependency
    The redaction process is rules-based and does not rely on large language models. If more advanced redaction is needed, optional LLM-assisted masking can be enabled through configuration.

Installation and Enablement

Installing this plugin requires a DeepSeek Harness environment and Node.js 20+ (Node 24+ is recommended to run source-code tests).

The installation command is as follows:

dsh plugin --profile demo add github:JohnXu22786/session-export

After installation, the plugin automatically injects configuration, with the default output directory set to $DSH_HOME/exports. You can override this setting in the configuration file.

Typical Usage

The plugin provides both tool calls and slash commands.

Tool Commands

In the DSH context, you can directly invoke the following tools:

  • session_export { format?, sessionId?, redact? }
    Export a session. If format is not specified, the default format is used. The redact parameter controls whether redaction is enabled and defaults to enabled.
  • session_export_list { query?, sessionId?, format?, before?, after?, limit? }
    List or search archives. Results can be filtered by session id, date range, or format.
  • export_delete { target }
    Delete an archive by archive id or file name.

Slash Commands

Users can enter the following commands directly in the conversation:

  • /session-export: Trigger a session export.
  • /session-export-list: View the export list.
  • /export-delete: Delete a specified archive.
  • /sanitize-config: View or modify redaction configuration.
  • /export-audit: View compliance audit trends.

Use Cases and Considerations

This plugin is suitable for DSH users who need to meet compliance requirements and have high requirements for data security.

  • Environment requirements: A DeepSeek Harness profile containing the base bundle must be configured, and the profile must provide base services such as sessions, sessionPersistence, tools, and commands.
  • Runtime permissions: The plugin runs with the permissions of the current DSH process, so you should review the source code and license before installation.
  • Data security: Redaction fingerprints are generated using salted SHA-256 to preserve correlatability. Index writes are serialized within the process to prevent data loss caused by concurrent calls.

Summary

dsh-session-export provides a complete session export and compliance archiving solution for DeepSeek Harness. It addresses sensitive information leakage through default deterministic redaction and meets operations and compliance needs with archive management and audit views. All features are available through command-line and slash commands, requiring no additional development for integration.

Plugin directory page | GitHub repository