Introduction¶
DeepSeek Harness (DSH) not only forwards prompts but also rewrites prompts at runtime, sets approval gates, adjusts sandbox policies, and migrates sessions. If you only ask whether the model answered, host-layer interception is often mistaken for model refusal. The dsh-purge plugin separates these two layers, performs controlled evaluation and cleaning on the official Harness already installed on the user’s machine, and helps investigate whether default policies are too strict.
Core Positioning¶
dsh-purge is a cybersecurity red team tool plugin for DeepSeek Harness. It focuses on controlled evaluation and cleaning of the local official Harness and includes a built-in drill environment. The plugin supports switching prompts for different models, with the default prompt designed for the Chinese model “Xiao Ma Jiang.” The project is maintained by YuJunZhiXue and is released under the MIT license.
Key Features¶
The plugin provides the following core capabilities:
-
dsh-purge dock
Click the button next to the session title to open the right-hand Dock, which contains the Clean and Drill pages. -
Prompt editor
Supports switching prompts for different models and adjusting rule sets through the editor. -
Local file handling
Supports reading local files under paths such as$DSH_HOMEand.dshfor configuration and prompt injection. -
Built-in drill environment
After authorization, it can access assets, skills, and the local environment for simulation drills. -
Host policy modification
Provides modification of default copies, permission policies, and tool restrictions. It does not alter official capabilities or forge identities. -
Automatic checks
Automatically checks and reapplies configurations at startup to prevent invalidation caused by manually modifying files.
Installation and Activation¶
The plugin does not provide a command-line installation script. Obtain it through one of the following channels:
- Directory page: https://deepseek.stream/plugins/dsh-purge
- GitHub repository: https://github.com/YuJunZhiXue/dsh-purge
Typical Usage¶
When using dsh-purge for injection and configuration, follow these steps:
- On the Clean page of dsh-purge, click Apply. Apply only writes prompts and patches to disk; at this point, in-process injection has not taken effect.
- After the Apply operation completes, you must click Restart. Only after restarting the host does the injection enter a new session. If Apply is executed alone, it appears that nothing changes.
- Use the prompt editor to adjust rule sets and customize security policies for specific models.
Use Cases and Cautions¶
This plugin is limited to the local official Harness and does not attack the public internet. The target version is DSH 0.1.7-rc.2. Before use, review the source code and license.
Strict legal and compliance disclaimer
Disclaimer: This is a non-profit open-source project. It follows applicable laws and the rules of the platforms it uses, and is intended only for learning and research. Do not use it for any illegal or non-compliant purpose; the user bears any resulting consequences.
Zero-tolerance statement: This project opposes and forbids any illegal activity. The authors do not support, encourage, or assist unauthorized network attacks, exploit use, data theft, unlawful intrusion into computer information systems, or generation of illegal or prohibited content. Anyone who uses this project for crime is solely responsible under the law. The authors have no liability.
- This repository contains no illegal material. The published code, docs, patches, and default prompt are not malware, backdoors, unauthorized pentest kits, ransomware, credential-stuffing scripts, or attack payloads aimed at the public internet or third-party systems.
- Local official Harness only. Security-eval patches and prompt injection run only on the official DeepSeek Harness already installed on the user’s machine.
- Eval patches do not attack the public internet. Apply, inject, revert, and uninstall stay in local files and local processes. They do not scan, probe, intrude, or send attack traffic to any public host.
- Lawful, controlled scope. Testing must stay on the authorized local official Harness, offline local synthetic fixtures, authorized cybersecurity ranges, and compliant lab environments.
- Forbidden uses. Users must not use this project to violate applicable laws (Criminal Law, Cybersecurity Law, Data Security Law, etc.) or engage in unauthorized intrusion, sabotage, credential stuffing, or spreading malicious payloads.
Conclusion¶
dsh-purge provides a visualized red team evaluation environment for the local official Harness, enabling separation of host-layer and model-layer refusal behaviors. Through the Clean and Drill pages, developers can more precisely control the test scope and permission policies. The project code is open-sourced on GitHub, and the directory page provides a documentation index.