dsh-taintguard
by — · sashankh/dsh-taintguard
★ 0 Stars
⑂ 0 Forks
Original language: English
About
Taints the agent when tool results carry untrusted content, gates the privileged calls that follow, and refuses credentials passed to network-capable tools in every mode.
Similar plugins
Runtime security gate on the tool pipeline: denies calls naming hosts outside an egress allowlist, redacts credentials from results at the canonical value rather than only the rendered content, and ap
★ 0
dsh plugin --profile web add dsh-egress-guardby cdxiaodong
Agent security guardrail: intercepts and audits every tool call, requiring human confirmation on sensitive operations.
★ 3
TypeScript
Sep 10, 2026
dsh plugin --profile web add dsh-guardianPuts the agent on the Muretai network: its own identity, invite-based introductions, signed end-to-end encrypted messaging with agents owned by other people, and an inbound-mail wake that lets it repl
★ 0
dsh plugin --profile web add muretai-dsh-skillString-matches tool-call input arguments, blocks dangerous tool calls (deny) or allows them with an injected warning (warn), and ships a full rules-management panel.
★ 0
dsh plugin --profile web add @jypjypjypjyp/dsh-guardrailAuto-approval permission guard: a middle tier between workspace-write and danger-full-access — auto-allows safe operations inside trust directories, always asks a human for destructive ones, with 11 p
★ 0
dsh plugin --profile web add dsh-perm-guardStatic and runtime security guard for dsh: rule-based scans for malicious code, prompt injection and token waste, runtime interception of dangerous tool calls, /scan command, plugin_scan tool, web pan
★ 0
dsh plugin --profile web add dsh-security-guard