dsh-secret-scrub
by — · jkt-check/dsh-secret-scrub
★ 0 Stars
⑂ 0 Forks
Original language: English
About
Irreversible secret-scrubbing guard: rewrites access keys, bearer tokens, and private key blocks into [REDACTED:<category>] placeholders before they reach the session log and the model.
Compatibility
Versions
| Latest version | Published | Size |
|---|---|---|
| 0.1.0 | — | — |
| 0.1.1 | — | — |
Similar plugins
Runtime security gate on the tool pipeline: denies calls naming hosts outside an egress allowlist, redacts credentials from results at the canonical value rather than only the rendered content, and ap
★ 0
dsh plugin --profile web add dsh-egress-guardStatic and runtime security guard for dsh: rule-based scans for malicious code, prompt injection and token waste, runtime interception of dangerous tool calls, /scan command, plugin_scan tool, web pan
★ 0
dsh plugin --profile web add dsh-security-guardTaints the agent when tool results carry untrusted content, gates the privileged calls that follow, and refuses credentials passed to network-capable tools in every mode.
★ 0
dsh plugin --profile web add dsh-taintguardAuto-approval permission guard: a middle tier between workspace-write and danger-full-access — auto-allows safe operations inside trust directories, always asks a human for destructive ones, with 11 p
★ 0
dsh plugin --profile web add dsh-perm-guardSource-aware prompt injection guard for DSH: tracks untrusted turn context, detects injection signals, scores sensitive sinks, and blocks high-risk tool calls with explainable audit logs.
★ 0
↓ 79/wk
dsh plugin --profile web add dsh-injection-guardby JUANWANG-BUAA
Auditable, token-gated DeepSeek Harness remote gateway: mobile QR access, per-device sessions, Host/Origin rewrite, settings/credentials/directory support.
★ 40
MIT
TypeScript
Sep 12, 2026
dsh plugin --profile web add dsh-full-remote