Introduction

The plugin mechanism of DeepSeek Harness (DSH) allows developers to extend system behavior. In real development, downstream model adapters usually run within a trust boundary and directly handle complete user request graphs. If a request contains sensitive information such as API keys or database connection strings, that data may be exposed directly to the model for inference.

The dsh-egress-guard plugin operates at the llm/stream boundary and inspects requests before they are passed to downstream adapters. It blocks requests containing known secret patterns locally by freezing the request graph and scanning text content. The entire process does not use the network, does not rewrite request values, and does not send content to external services.

Plugin Scope

The plugin is maintained by LKRCharon and is an MIT-licensed DSH security plugin. It focuses on “local, zero-network, deterministic secret precheck.” When it receives a model request, the plugin first validates and freezes the request graph. If suspected credentials are found, it stops invoking the downstream model adapter and returns a fixed redacted error. Matching results do not appear in error messages, reports, or plugin logs.

Core Features

The core capabilities of the plugin are concentrated in the following areas:

  1. Request scanning scope: Scans fields such as system prompts, tool schemas, JSON parameters, message content, and tool descriptions.
  2. Secret detection: Built-in rules support detecting multiple credential formats, including PEM private keys, API keys for platforms such as GitHub/AWS/Google, Bearer authentication, database connection URLs, and common assignment statements such as password= and api_key=.
  3. Default policy (Fail-Closed): By default, the plugin blocks requests containing known secret patterns, images (OCR scanning is not supported), and unknown content.
  4. Audit mode: Supports switching to audit mode, which only records findings (rule ID, structural location, etc.) without blocking the request.
  5. Graph structure handling: Handles cyclic, sparse, or unfreezable request graphs and blocks requests when structural anomalies occur.

Installation and Enablement

Before installation, make sure the environment meets the dependency requirements: Node.js version 22.19.x or 24, and DeepSeek Harness version 0.1.0-rc.6 or a compatible version.

Run the following command to install the plugin:

npx --yes @deepseek-ai/dsh@0.1.0-rc.6 plugin --profile web add dsh-egress-guard

After successful installation, the dsh command output should contain an egress-guard configuration line. Note that DSH rc.6’s configuration profile mode disables automatic peer installation, so the command may report missing dependencies such as @deepseek-ai/cordis. This does not affect runtime, because the host environment provides these dependencies.

Configuration and Usage

Configuration is done by modifying the cordis.patch.yml file. Later patch layers can override configuration with the same ID.

Basic Configuration

Add the following content to the configuration file:

- id: egress-guard
  name: dsh-egress-guard
  config:
    mode: block
    scanToolSchemas: true
    blockUnscannable: true
    maxScanBytes: 4194304
    maxFindings: 64
    skipProviders: []
    skipPurposes: []
    customRules: []

Configuration Options

  • mode: Set to block to block requests; set to audit to only log findings.
  • scanToolSchemas: Whether to scan tool descriptions and JSON Schemas sent to model tools.
  • blockUnscannable: Defaults to true. Used to block images, malformed fields, or unknown content types that cannot be safely scanned.
  • maxScanBytes: Limits the maximum number of text bytes to scan (default 4MB, range 1 KiB - 16 MiB). Requests exceeding the limit are blocked.
  • maxFindings: Maximum number of retained finding records.
  • skipProviders / skipPurposes: Bypass checks by configuring specific routes or conversation purposes.

Custom Rules

The plugin supports adding custom rules to match specific secret prefixes. Custom rules do not use regular expressions; instead, they use deterministic prefix + alphabet + length matching.

customRules:
  - id: acme-production-key
    prefix: 'ACME-PROD-'
    alphabet: 'ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789'
    length: 24

The rule defines a prefix, a restricted character set, and a fixed length. The plugin looks for the prefix and then selects the specified number of characters from the restricted character set as the suffix.

Notes

  1. Log residue: The plugin blocks outbound model requests, but the text may already have been written to local DSH session logs and will not be automatically cleaned.
  2. Binary content: The plugin does not support OCR scanning of images and blocks binary content by default.
  3. Boundary limitations: It is a plugin that runs inside the DSH process and only intercepts model requests. It is not a machine-level network firewall and cannot prevent malicious plugins from stealing data through abnormal paths.
  4. Graph structure freezing: Before scanning, the plugin freezes the request graph to prevent the direct caller from modifying it during asynchronous parsing. However, modifications to runtime global variables are not affected.