Introduction

When autonomous agents write code or run scripts, there is a risk that API keys or credentials may be accidentally leaked into Git diffs or that destructive terminal commands (such as rm -rf) may be executed unintentionally. dsh-shadow-auditor acts as a background security firewall within the DSH Agent runtime environment, scanning code diffs for private keys and verifying the safety of terminal commands.

Plugin Overview

This is a plugin for DeepSeek Harness (DSH), focused on background security auditing, key leakage detection, and command safety. It runs as an in-process security interceptor and protects the environment using AST analysis and entropy/regex scanning.

Core Capabilities

Real-Time API Key and Credential Scanning

The plugin performs real-time scanning of code diffs, using entropy analysis and regular expressions to identify API keys, private keys, OAuth bearer tokens, and database credentials. It intercepts tokens before they are transmitted to an LLM or saved to version control, and automatically redacts them in logs.

Destructive Command Firewall

Using AST analysis, the plugin checks shell commands before terminal execution. It establishes boundaries around dangerous operations, including unrestricted rm -rf, disk wiping, recursive permission overrides, and recursive deletions targeting workspace root directories or external paths. It requires explicit user override to execute dangerous scripts.

Security Rule Engine and Dashboard

The plugin provides a configurable security rule engine for managing interception policies. It offers a real-time dashboard and a security audit badge in the UI, making it easier to visualize and review security events in the DSH web interface.

Installation and Enabling

  1. Install the plugin in the DSH configuration file by running the following command:
    dsh plugin --profile web add @goodandready/dsh-shadow-auditor
  1. Enable the features in the DSH configuration file (such as settings.yaml). The following example enables strict key scanning and the destructive command firewall:
    dsh-shadow-auditor:
      strictSecretScanning: true
      blockDangerousCommands: true
      enableAuditBadge: true

Agent Tool Usage

The plugin provides three Agent tools for direct invocation:

  • shadow_auditor_scan_diff(diff)
    • Parameter: diff (string) - Scans a unified diff or code block to find exposed API keys, credentials, and private keys.
  • shadow_auditor_check_command(command)
    • Parameter: command (string) - Evaluates a shell command to check for destructive execution patterns and security policies.
  • shadow_auditor_rules_list
    • Parameters: none
    • Description: Returns the currently active security rules, patterns, and execution modes.

Use Cases and Notes

This plugin is suitable for administrators and developers who need to protect sensitive operations at runtime. It runs with the current process permissions, so explicit user override is required to execute dangerous scripts.

Dependencies: Requires dependencies such as @deepseek-ai/cordis and @deepseek-ai/dsh-host-webserver.
Localization: Supports English, Chinese, and Russian.
Interception Scope: Proactively intercepts .env files and settings files.

Conclusion

dsh-shadow-auditor provides DSH Agent with a set of background security mechanisms. Developers can visit the GitHub repository for more information, or access the SkillHub catalog to install it.