Introduction

The built-in permission vocabulary of DeepSeek Harness (DSH) usually restricts only write operations, while read operations are often left unrestricted. This leaves AI agents uncontrolled when they perform operations such as running cat .env or opening ~/.ssh/id_rsa. As a policy guard plugin, gabrip780/dsh-hidden-paths aims to intercept files and paths that should not be read at the plugin layer, preventing AI agents from accidentally or maliciously reading sensitive information.

Core Features

The plugin primarily provides the following capabilities:

  • Multichannel Interception: Prevents AI agents from accessing hidden files and folders through file tools (such as read, edit), Shell commands (such as cat, ls), search selectors, and code execution via run_code.
  • Automatic Redaction: Automatically identifies and redacts credential formats (such as OpenAI/Anthropic keys, JWTs, GitHub/GitLab tokens, etc.), marking them as [redacted:kind] in results.
  • Default Protection: Protects sensitive files and directories such as .env, .ssh, and .aws by default.
  • Result Masking: In results returned by tools, consistently displays the names of hidden paths as [hidden].
  • Dual-Layer Mechanism: Uses Layer 1 path rejection and Layer 2 result filtering. Layer 1 rejects paths before tool execution; Layer 2 filters results after execution and handles redaction and path-name masking.

Installation and Activation

Install the plugin via the official command and activate the profile layer:

dsh plugin --profile web add dsh-hidden-paths

After installation, restart the dsh server to load the new module.

The plugin is automatically inserted into the configuration by the bundle layer. Do not manually add an insert block in the configuration. To adjust the configuration, use an id-targeted override to override the default settings.

Typical Usage

Add the paths that need to be hidden in the configuration file:

- id: dsh-hidden-paths
  config:
    hiddenPaths:
      - /home/you/private          # 隐藏文件夹及其子目录
      - /etc/app/master.key        # 隐藏单个文件

Activate the plugin via a configuration override (do not use an insert block):

- id: dsh-hidden-paths
  config:
    hiddenPaths: []
    maskResults: true
    hidePathsInResults: true

Use Cases and Considerations

This plugin is suitable for developers who need to restrict AI agent access to sensitive directories and files in their projects. However, note the following limitations when using it:

  • Policy Guard, Not a Sandbox: This is an application-layer policy guard, not a kernel sandbox. It cannot prevent protection bypasses by executing arbitrary code via run_code, using hard links, reading the /proc directory, or constructing paths from environment variables.
  • Configuration Behavior: Strings in the configuration are treated as single entries, and relative paths are resolved against the current working directory. If the configuration cannot be read, the plugin rejects all tool calls.
  • Redaction Scope: Redaction rules target explicit token formats only and do not alter ordinary source code content (such as const api_key = ...).

Conclusion

gabrip780/dsh-hidden-paths is an important tool in the DeepSeek Harness ecosystem for strengthening security. By configuring path blocklists and default rules, it can effectively reduce the risk of AI agents leaking sensitive information. For more details, refer to the SkillHub plugin directory or the GitHub repository.