The core design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” When building DSH-based agents, the LLM may generate instructions that execute dangerous system commands or unintentionally leak sensitive credentials. The dsh-safeguard plugin is mounted in the tools/pre-execute pipeline and performs a short-circuit rejection before tool execution, ensuring that the side effects of blocked operations never occur.
dsh-safeguard is a security plugin for DeepSeek Harness that blocks dangerous commands and secret leakage. It is maintained by ZhijiangTang and matches content using regex-based heuristic rules.
Core Features¶
The plugin provides two types of interception capabilities:
- Dangerous Command Interception: It applies regex matching to
bashtool commands and rejects them on match. Default rules includerm -rf,git push --force,git reset --hard,git clean -fd,chmod -R 777,mkfs,dddisk writes, redirection to block devices,curl \| shpipe execution, and SQLDROP/DELETE/TRUNCATEstatements. - Secret Leakage Interception: It scans
JSON.stringify-serialized arguments from all tools for common secret patterns. Default rules include AWS Access Key (AKIA...), API keys starting withsk-, GitHub PAT (ghp_,github_pat_), PEM private keys, and Slack tokens (xox-). Note: long JWTs starting witheyJare not blocked because overly broad patterns produce a high false-positive rate.
Installation and Enablement¶
Install it from the command line:
dsh plugin --profile <profile> add dsh-safeguard
After installation, override the configuration items in the profile’s cordis.patch.yml (or bundle configuration) to enable the features:
- insert:
- id: guard
name: dsh-safeguard
config:
enableDanger: true # 危险命令拦截开关
enableSecrets: true # 密钥泄漏拦截开关
extraPatterns: # 额外危险命令正则
- 'curl.*\\|.*bash'
allowList: # 精确豁免名单
- 'rm -rf /tmp/safe-dir'
Debugging and Helper Tools¶
The plugin provides two helper tools for debugging:
- guard_list: Lists the currently enabled rule categories and item counts.
- guard_check: A check-only tool that does not block. It accepts a
textparameter and returns the matched rule name, category, or whether the input is exempted. For example,guard_check("rm -rf /")returns categorydangerand rulerm -rf. The model can perform programmatic self-checks viaawait tools.guard_check({ text: "..." }).
Use Cases and Notes¶
This plugin only blocks clearly high-risk actions using regex-based heuristic matching. It does not verify signatures, determine whether secrets are real, or provide sandbox isolation. It cannot replace secret scanners (such as gitleaks), signature verification, or OS-level sandboxes (such as dsh-bash-sandbox). In production environments, it should still be used together with other security measures.