dshbase

Plugin directory / Developer / noatmark-dsh-plugin

noatmark-dsh-plugin

Verified · install-tested on dsh ylwl1997

✓ Actively maintained 2 contributors Builds on 2 official DSH packages Pure TypeScript

View on GitHub ↗ ← Back to plugin directory

1Stars
0Forks
0Open issues
TypeScriptLanguage
2026-08-14Last push
Cross-platformPlatform

What it does

Text hygiene as a dsh plugin: sanitize untrusted text, scan invisible characters, clean LLM formatting, and escape CSV formula injection.

✅
Our take
Works — verified, early-stage project

Text hygiene as a dsh plugin: sanitize untrusted text, scan invisible characters, clean LLM formatting, and escape CSV formula injection. It installs cleanly and boots without issues in our testing. It's early-stage but functional.

“Verified” means our automated CI actually ran dsh plugin add in a clean profile and it booted — nothing more. Feature descriptions and version compatibility are the author’s claims. This is not a security audit and not an endorsement of third-party code.

README

noatmark-dsh-plugin

awesome · DSH plugin

NoAtMark text hygiene as a DeepSeek Harness (dsh) plugin.

Everything-is-a-plugin: this plugin gives your dsh agent four text-hygiene tools, backed by the same deterministic engines behind noatmark.com.

Tools

Tool What it does
sanitize_text Strip invisible/zero-width characters and flag prompt-injection + hidden-text signals.
scan_text Report invisible characters (with code points + positions), injection patterns, and hidden text.
clean_format Clean LLM formatting artifacts (blank lines, stray fences, trailing spaces) — meaning untouched.
sanitize_csv Escape CSV formula injection (OWASP): = + - @ prefixes get a leading quote.

All processing is deterministic and local — no data leaves your machine.

Install

Add this plugin to your dsh Web UI. If you're running from a source checkout, use a cordis.yml patch:

- insert:
    - id: noatmark
      name: noatmark-dsh-plugin

or point at the source directly (absolute path):

- insert:
    - id: noatmark
      name: '/path/to/noatmark-dsh-plugin/src/index.ts'

Start dsh with the patch:

npx @deepseek-ai/dsh web --patch ./cordis.yml

Usage

In a dsh session, ask the agent to use a tool, e.g.:

Sanitize this pasted text before you summarize it.

Scan this file for invisible characters.

Clean the formatting of this AI output.

Escape this CSV before saving it.

Development

pnpm install
pnpm build   # tsc -> dist/

Resources

MIT

Install

🧩 Let your agent install it (recommended)

Install the catalog once, then DeepSeek Harness can find and install any plugin from this site automatically:

dsh plugin add dshbase-catalog

Then say "install noatmark-dsh-plugin for me" — your agent finds it in the directory and installs it. Docs: dshbase-catalog · verified packs.

Web profile:

dsh plugin --profile web add noatmark-dsh-plugin

Headless (CLI) profile:

dsh plugin --profile headless add noatmark-dsh-plugin

Package

npm: noatmark-dsh-plugin · version 0.1.0 · tested on dsh 0.1.0-rc.6

Test report

Verified end-to-end: L1 install + L2 load + L3 runtime Q&A on dsh 0.1.0-rc.6.

When to use it

Sanitize untrusted text, scan for invisible characters, clean LLM formatting, and escape CSV — hygiene before content touches the model.

Who it's for

Users who paste text from the web or untrusted sources and want zero-width/invisible-character attacks caught first.

For developers — extending it

Add hygiene rules and detectors — new invisible-character ranges, formatting normalizers, and sanitizer presets.

Security: not yet scanned — our daily static scan will cover it shortly.

Share this badge

More in Developer

Browse all 7797 plugins →