The core design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” When building DSH-based agents, the LLM may generate instructions that execute dangerous system commands or unintentionally leak sensitive credentials. The dsh-safeguard plugin is mounted in the tools/pre-execute pipeline and performs a short-circuit rejection before tool execution, ensuring that the side effects of blocked operations never occur.

dsh-safeguard is a security plugin for DeepSeek Harness that blocks dangerous commands and secret leakage. It is maintained by ZhijiangTang and matches content using regex-based heuristic rules.

Core Features

The plugin provides two types of interception capabilities:

  1. Dangerous Command Interception: It applies regex matching to bash tool commands and rejects them on match. Default rules include rm -rf, git push --force, git reset --hard, git clean -fd, chmod -R 777, mkfs, dd disk writes, redirection to block devices, curl \| sh pipe execution, and SQL DROP/DELETE/TRUNCATE statements.
  2. Secret Leakage Interception: It scans JSON.stringify-serialized arguments from all tools for common secret patterns. Default rules include AWS Access Key (AKIA...), API keys starting with sk-, GitHub PAT (ghp_, github_pat_), PEM private keys, and Slack tokens (xox-). Note: long JWTs starting with eyJ are not blocked because overly broad patterns produce a high false-positive rate.

Installation and Enablement

Install it from the command line:

dsh plugin --profile <profile> add dsh-safeguard

After installation, override the configuration items in the profile’s cordis.patch.yml (or bundle configuration) to enable the features:

- insert:
    - id: guard
      name: dsh-safeguard
      config:
        enableDanger: true      # 危险命令拦截开关
        enableSecrets: true     # 密钥泄漏拦截开关
        extraPatterns:          # 额外危险命令正则
          - 'curl.*\\|.*bash'
        allowList:              # 精确豁免名单
          - 'rm -rf /tmp/safe-dir'

Debugging and Helper Tools

The plugin provides two helper tools for debugging:

  1. guard_list: Lists the currently enabled rule categories and item counts.
  2. guard_check: A check-only tool that does not block. It accepts a text parameter and returns the matched rule name, category, or whether the input is exempted. For example, guard_check("rm -rf /") returns category danger and rule rm -rf. The model can perform programmatic self-checks via await tools.guard_check({ text: "..." }).

Use Cases and Notes

This plugin only blocks clearly high-risk actions using regex-based heuristic matching. It does not verify signatures, determine whether secrets are real, or provide sandbox isolation. It cannot replace secret scanners (such as gitleaks), signature verification, or OS-level sandboxes (such as dsh-bash-sandbox). In production environments, it should still be used together with other security measures.

dsh-safeguard

Catalog
GitHub