Introduction¶
The core design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” When building agentic applications, session logs and requests sent to the model often contain sensitive information (such as API keys, private keys, and tokens). dsh-secret-scrub is an irreversible secret-scrubbing plugin designed for this scenario. Before text is persisted to logs or sent to the model, it replaces matches with placeholders using regex matching to prevent the leakage of sensitive information.
What It Is¶
dsh-secret-scrub is a standalone plugin extracted from the kaya-ai-terminal project. It provides secret-scrubbing capability to DSH by regex-matching secret-like shapes and replacing them with [REDACTED:<category>] placeholders. The plugin is maintained by jkt-check and released under the MIT License.
Core Features¶
- Irreversible replacement: Matched secrets are permanently replaced, and the original text cannot be recovered.
- Multi-level scrubbing:
- minimal: Runs only Tier 0 (core secret rules).
- balanced (default): Runs Tier 0 + Tier 1 (environment variables, cloud provider keys).
- aggressive: Runs Tier 0 + Tier 1 + Tier 2 (PII information, high-entropy text such as SHA-256).
- Listener mounting: The plugin mounts three pre-stage waterfall listeners, respectively intercepting:
- User messages (
agent/pre-step). - Tool execution result content (
tools/post-execute). - Persisted logs from tool code dispatch (
tools/ptc-dispatch-log).
- User messages (
- Custom rules: Supports adding custom regex rules through configuration files.
- Engine export: Provides a standalone
scrubTextscrubbing engine that can be used separately in Node.js without depending on DSH.
Installation and Activation¶
Use the official npm package installation command to activate the plugin. The plugin defaults to the balanced level and requires no extra credentials.
dsh plugin --profile headless add dsh-secret-scrub
If you need to test local modifications, you can install from a tarball path:
dsh plugin --profile headless add /path/to/dsh-secret-scrub-0.1.1.tgz
Typical Usage¶
After installation and restarting the corresponding profile, execute a command containing secrets; the text is scrubbed before it reaches the logs and the model.
dsh --profile headless "echo AWS AKIAIOSFODNN7EXAMPLE"
If you need to adjust the scrubbing level or add custom rules, override the default cordis.patch.yml:
- id: secret-scrub
config:
level: aggressive
extra:
- category: internal-token
pattern: 'internal-[0-9]{4}'
If you are not using DSH, it can be used directly as a Cordis plugin:
import { Context } from '@deepseek-ai/cordis'
import * as SecretScrub from 'dsh-secret-scrub'
const ctx = new Context()
await ctx.plugin(SecretScrub, {
level: 'aggressive',
disabled: ['env-var-secret'],
extra: [
{ category: 'internal-token', pattern: 'internal-[0-9]{4}' },
],
})
Notes¶
- Irreversibility: The scrubbing process is irreversible, and replaced secrets cannot be recovered.
- Regex limitations: Unprefixed secrets, secrets spanning multiple text blocks, and encoded forms (Base64, URL encoding) may not be matched due to conservative rule shapes.
- False positives and false negatives: Tier-2 rules match “shapes” rather than “verified secrets,” so false positives can occur (for example, an email address in instructions may be scrubbed). High-entropy text (such as git SHAs) is scrubbed in aggressive mode.
- Security reliance: Do not rely solely on this plugin as the sole control for preventing leakage.
Summary¶
This plugin provides DSH users with basic sensitive-information protection through tiered configuration and custom rules to fit different scenarios. Refer to the links below for more details and source code.