dsh-agent-sentinel
DiscoveredSecurity guard plugin for DeepSeek Harness: secret redaction, a shell command denylist, prompt-injection scanning, and syntax verification.
dsh-agent-sentinel
English | 中文
dsh-agent-sentinel is a dsh-plugin for DeepSeek Harness that adds four independent, best-effort safety layers to an agent loop: secret redaction on tool output, a pattern-based denylist for destructive shell commands, indirect prompt-injection scanning on file reads and web fetches, and syntax verification on file writes. Every finding is written to an append-only JSONL audit log.
It hooks into the real Cordis extension points ctx.tools.guard() and the tools/post-execute waterfall, the same points the official @deepseek-ai/dsh-repeat-tool-reminder guard plugin uses.
What this is, honestly
Each layer below is a heuristic, not a guarantee. Read this section before enabling strictMode or relying on this plugin as your only safety net.
- Secret redaction — regex + Shannon-entropy scanning. Catches known secret shapes (OpenAI/DeepSeek/GitHub/AWS/Stripe/Anthropic keys, private key blocks, JWTs, DB connection strings) and generic high-entropy
KEY=...-style assignments. It cannot catch a secret format it has no pattern for, and it only inspectscontent(text) blocks — aPostToolDecisionthat carries a barevalueinstead ofcontentis logged (value_result_not_scanned) but not scanned, since safely rewritingvaluerequires framework-level revalidation this plugin doesn't perform. - Command guard — a fixed regex denylist for known-destructive shapes (
rm -rf /,find / -delete, disk wipes,curl | bash,chmod -R 777 /, ...). This is defense-in-depth, not a sandbox. It does not parse shell grammar, so variable indirection (T=/; rm -rf $T), command substitution, or a tool this rule set doesn't yet name can bypass it. Pair it with real containment (@deepseek-ai/dsh-sandbox-*,@deepseek-ai/dsh-user-approval) for actual guarantees. - Prompt-injection scanner — regex matching for common override/jailbreak phrasing and zero-width Unicode. Each pattern carries a hand-assigned severity weight, not a calibrated probability from any measured detection rate.
- Syntax verifier — a real parse for JS/TS (via the TypeScript compiler's
transpileModule, which correctly understands ES moduleimport/exportsyntax) and JSON (JSON.parse); for Python it shells out to a realpython3/pythoninterpreter when one is onPATH, falling back to a string/comment-aware bracket-balance heuristic otherwise.
Quickstart
pnpm add dsh-agent-sentinel
Mount via a Cordis composition file (cordis.yml)
- id: sentinel
name: 'dsh-agent-sentinel'
config:
redactSecrets: true
blockDangerousCommands: true
detectPromptInjections: true
verifyCodeSyntax: true
auditLogPath: '.sentinel-audit.jsonl'
strictMode: false
Programmatic mount
import { Context } from '@deepseek-ai/cordis'
import * as sentinel from 'dsh-agent-sentinel'
const ctx = new Context()
ctx.plugin(sentinel, {
redactSecrets: true,
blockDangerousCommands: true,
auditLogPath: '.sentinel-audit.jsonl',
})
const summary = ctx.sentinel.getThreatSummary()
console.log(`Total security events: ${summary.totalEvents}`)
Configuration reference
| Option | Type | Default | Description |
|---|---|---|---|
redactSecrets | boolean | true | Redact secrets/credentials found in tool output content blocks. |
customSecretPatterns | { name, pattern }[] | [] | Additional secret regex patterns. |
blockDangerousCommands | boolean | true | Veto shell calls matching the built-in destructive-command denylist. |
customCommandRules | { id, pattern, reason, severity? }[] | [] | Additional shell command denylist rules. |
detectPromptInjections | boolean | true | Scan file-read/fetch output for prompt-injection patterns. |
verifyCodeSyntax | boolean | true | Verify syntax of file writes/edits (JS, TS, JSON, Python). |
auditLogPath | string | .sentinel-audit.jsonl | Path for the append-only JSONL audit log. |
strictMode | boolean | false | Block (rather than just log) a write that introduces a syntax error. |
maxAuditHistory | number | 500 | In-memory audit ring-buffer size (independent of the on-disk log, which is never truncated by this plugin). |
A note on this package's dependency setup
As of this writing, @deepseek-ai/dsh-tools (and every sibling @deepseek-ai/dsh-* package checked) depends transitively on @deepseek-ai/dsh-type-meta, which 404s on the public npm registry — the whole @deepseek-ai/dsh-* family is not independently installable outside the deepseek-harness monorepo's own workspace right now. That includes even declaring it as an optional peer dependency: pnpm's peer-resolution walk still tries to resolve dsh-tools's own manifest and fails the same way, breaking pnpm install for every consumer. So dsh-tools is deliberately not listed in package.json at all — this plugin relies on it purely at runtime (it is always present in a real harness process; nothing else provides ctx.tools) and mirrors the small slice of its published type surface it needs locally in src/vendor/dsh-tools-types.ts, with each type's exact source (package, version, file) documented in that file's header. If @deepseek-ai/dsh-type-meta becomes installable, that file can be replaced with real imports without changing any call site — every mirrored name matches the real export name.
Running tests
pnpm test # vitest run
pnpm test:coverage # vitest run --coverage
pnpm typecheck # tsc --noEmit, against the real installed @deepseek-ai/cordis types
License
MIT © Aditya Jethani
Comments
Loading…
Similar plugins
by ZhijiangTang
DSH plugin: block dangerous shell commands and secret leakage before execution (tools/pre-execute veto)
★ 0
↓ 58/wk
MIT
JavaScript
Aug 16, 2026
dsh plugin --profile web add dsh-safeguardby Yazzyk
DeepSeek Harness (dsh) 插件:在 Web GUI 里手动点选文件或目录,屏蔽 agent 对它们的读取、搜索、写入与编辑。A dsh plugin that denies an agent read/search/write/edit access to chosen files and directories, picked from the plugin's own We
★ 0
MIT
JavaScript
Sep 19, 2026
dsh plugin --profile web add dsh-file-shieldby jkrandom-sudo
Security audit for DeepSeek Harness plugins: static permission profile with file/line evidence + a runtime sentinel gating credential access and unknown-host egress · DSH 插件安全审计:静态权限画像(附文件/行号证据)+ 运行时哨
★ 4
↓ 154/wk
MIT
TypeScript
Sep 11, 2026
dsh plugin --profile web add dsh-plugin-auditby PensiveFei
Read-only security & compliance plugin for DeepSeek Harness: prompt-injection detection, Chinese-PII redaction, and local configuration audit with redacted, reproducible reports.
★ 85
MIT
JavaScript
Sep 30, 2026
dsh plugin --profile agent add dsh-secure-auditby lonelymoon87
Adds dangerous-operation policy checks, output redaction, and a security-review workflow.
★ 1
↓ 46/wk
MIT
TypeScript
Aug 21, 2026
dsh plugin --profile web add dsh-guardianby Pasumao
DeepSeek Harness (dsh) Windows 环境防坑插件:防坑 skill + 三层主动防护(乱码检测提示 / 危险写拦截 / 编码诊断修复工具)。Windows guard plugin for DeepSeek Harness (dsh).
★ 0
MIT
JavaScript
Aug 29, 2026
dsh plugin --profile web add dsh-plugin-windows-guard