DeepSeek Harness (DSH) has a core design philosophy of “everything is a plugin.” When building agents, MCP server configurations and skill files are essentially text. Attackers may embed Prompt injection instructions, homoglyphs, or dangerous Shell commands in these files. dsh-mcpguard is the first security plugin in the DSH ecosystem, designed to scan these files and intercept behaviors that may harm AI agents.

Plugin Positioning

The plugin is maintained by ChenLaoshiYF and is licensed under MIT. It provides two tools as a standard DSH plugin: one for static configuration scanning, and another offering an experimental runtime observation mode. The entire plugin runs fully on the local machine, requiring no daemons, cloud services, or external API keys.

Core Features

  1. Static Scan

    • Scans skill directories and MCP configuration files.
    • Detects Prompt injection (such as “ignore previous instructions”), homoglyphs, invisible Unicode (such as zero-width characters), dangerous Shell commands (such as eval, curl | sh), and credential exposure.
    • Scan results are output in JSON format, including file scores, rule IDs, severity, and the offending excerpt. All sensitive information in the report (API keys, tokens) is redacted.
  2. Runtime Observation (Experimental)

    • The v0.2 release introduces the mcpguard_observe tool.
    • It attaches to the tools/pre-execute hook and monitors tool calls, including MCP tools.
    • By design, it never blocks tool execution. It is used only for logging, tracing, and reporting; the decision remains entirely with the user. Any internal error automatically degrades to allowing execution and logs the issue.

Installation and Enablement

Install via command line:

dsh plugin --profile web add "github:ChenLaoshiYF/dsh-mcpguard"

Or through the UI: after installing from Settings → Plugins, restart dsh --profile web.

Typical Usage

After installation, the plugin provides the following tools:

  • mcpguard_scan: scans the default targets (MCP configuration + skill directories).
  • mcpguard_scan_path: scans any path you specify.
  • mcpguard_observe: provides a runtime observation summary.

Example output (JSON format):

{
  "total": 3,
  "bySeverity": {
    "critical": 1,
    "high": 2
  },
  "recent": [...]
}

Security and Privacy

The plugin includes multiple built-in safeguards to prevent false positives and privacy leaks:

  • Privacy protection: no network requests and no telemetry upload.
  • File scan limits: files larger than 256 KB are skipped; recursive scan depth is limited to 8 levels.
  • Sensitive directory protection: .ssh, .aws, and .gnupg directories are never scanned, even if explicitly targeted.
  • Result redaction: in the report, all keys starting with sk-, tokens starting with ghp_, SSH private key blocks, and JWTs are replaced with ***.

Compatibility and Notes

The plugin has been tested against DeepSeek Harness 0.1.0-rc.5. Because DSH is in developer preview, APIs may change. If you encounter compatibility issues, we recommend submitting an Issue on GitHub.

Summary

dsh-mcpguard focuses on addressing text security pain points in AI agent development. It provides a lightweight, local scanning and observation solution that helps developers identify potential injection risks and configuration issues before code enters the runtime environment.

  • Plugin directory: https://www.skillhub.cn/plugins/ChenLaoshiYF/dsh-mcpguard
  • GitHub repository: https://github.com/ChenLaoshiYF/dsh-mcpguard