dsh-defend
Detects prompt-injection, jailbreak, and secret-leak patterns on the agent/pre-step, tools/pre-execute, and tools/post-execute seams with allow/ask/block tiers, sanitized defend/detection audit events, a defend_report tool, and a destructive-delete command guard.
在 agent/pre-step、tools/pre-execute、tools/post-execute 三个接缝检测提示词注入、越狱与密钥泄露,按 allow/ask/block 分层拦截,附脱敏 defend/detection 审计事件、defend_report 工具与危险删除命令门禁。
How to install
dsh plugin add dsh-defend About
🛡️ dsh-defend **Prompt-injection, jailbreak, and secret-leak defense for DeepSeek Harness.** *Rules decide the known. Interception decides the rest — and everything is audited.* English · 简体中文 · Español · Português · हिन्दी --- Compatibility | Surface | Status | |---|---| | Harness | DeepSeek Harness 0.1.0-rc.6 (compat declared for 0.1.0-rc.5–0.1.0-rc.6) | | Node | ^22.19.0 \|\| >=24.0.0 | | Platforms | All (pure host; no native code, no network) | | Model | Any (detection runs before content reaches the model) | What you get dsh-defend puts two independent layers in front of the agent: 1. **…
Recommendation signals
Meta
- License
- Apache-2.0
- Language
- TypeScript
- GitHub stars
- 16
- mo. downloads
- 0
- Last push
- 2026-09-24
- Created
- 2026-08-16
Basic safety check
- Findings
- None
- Sources
- curated:awesome-dsh-plugin.com, curated:awesome-dsh-plugin/awesome-dsh-plugin, curated:0xsline/awesome-deepseek-harness
- Topics
- cordis, deepseek, deepseek-harness, dsh, dsh-plugin, jailbreak, llm-security, prompt-injection, secret-scanning, security
Related plugins
dsh-auto-mode
NanmiCoder/dsh-auto-mode
Adds an Auto permission preset between Workspace Write and Full access: routine work stays in the official workspace-write sandbox while the current session model reviews escalation and destructive calls, granting one exact wider access once, asking when the intent is ambiguous, and denying critical paths.
dsh-passwords
slywalker2006/dsh-passwords
Turns DeepSeek Harness into a server-grade multi-tenant platform: remote access + auto HTTPS, subuser permissions & token/daily quotas, sandbox enforcement, encrypted auth & audit log.
sofagent
KongFangXun/sofagent/tree/main/engine/dsh-plugins/cordis-plugin-sofagent-audit
Commit-time audit harness for AI coding agents: 24 git-diff rules (secrets, out-of-scope edits, prompt injection), HMAC-signed audit trail, snapshot rollback, and an MCP server with 84 tools. Installable via dsh plugin add.
dsh-vault
Ox0400/dsh-vault
Encrypted local credentials vault for the Harness: a web settings page and vault_* tools to store, search and copy passwords, API keys, TOTP secrets and card data, with health audits, expiry rotation, imports/exports and read-only/ask access modes.