插件目录 / Developer / dsh-egress-guard
dsh-egress-guard
已验证 · 实测可装 LKRCharon
✓ 持续维护 基于 2 个官方 DSH 包
0Stars
0Forks
0未关闭 issue
JavaScript语言
2026-08-15最近推送
跨平台平台
功能简介
DSH本地无网密钥预检,失败即关闭。
我们的评价
可用 — 实测通过,早期项目
可用 — 实测通过,早期项目
DSH本地无网密钥预检,失败即关闭。 实测能干净安装、正常启动。早期项目,但功能可用。
「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。
README
dsh-egress-guard
Local, zero-network, deterministic secret preflight for DeepSeek Harness model requests.dsh-egress-guard inspects the fully assembled request at the official llm/stream boundary. It first validates and freezes the exact plain-data request graph that downstream code will consume. If it finds a likely credential, it stops before calling the downstream model adapter. Matches never appear in the error, finding report, or plugin log.
The default policy is fail-closed:
- known secret patterns block the request;
- images and unknown content blocks block because this version cannot inspect their bytes safely;
- requests larger than the configured scan limit block;
- cyclic, proxy/accessor-backed, non-plain, sparse, oversized, non-enumerable, unknown-field, or otherwise unfreezable request graphs block even in audit mode;
- invalid configuration prevents the plugin from loading.
It does not rewrite request values and never sends request content to another service.
Install
From npm after the package is published: ``sh
npx --yes @deepseek-ai/[email protected] plugin --profile web add dsh-egress-guard
npx --yes @deepseek-ai/[email protected] --profile web --dump-config
`
From the public GitHub repository now:
`sh
npx --yes @deepseek-ai/[email protected] plugin --profile web add git+https://github.com/LKRCharon/dsh-egress-guard.git
npx --yes @deepseek-ai/[email protected] --profile web --dump-config
`
From a local checkout, use a file: specifier so pnpm installs a package copy instead of a symlink:
`sh
npx --yes @deepseek-ai/[email protected] plugin --profile web add file:/absolute/path/to/dsh-egress-guard
npx --yes @deepseek-ai/[email protected] --profile web --dump-config
`
For a release-equivalent local smoke test, run npm pack in the checkout and add the resulting .tgz by absolute path. Do not add a bare checkout path: rc.6 treats it as a symlink, which can bypass the profile's host-module fallback at real startup.
The preview CLI delegates plugin installation to pnpm, so ensure it is on PATH first. With Corepack, run corepack enable pnpm; alternatively install pnpm 11 directly. A global dsh install may replace the pinned npx prefix above. The dump should contain an egress-guard row before you start the profile.
DSH rc.6 profiles disable automatic peer installation. The add command can therefore warn about the @deepseek-ai/cordis and @deepseek-ai/dsh-llm peers even though the host supplies them at runtime. They intentionally remain peer dependencies so the plugin shares the host runtime and LlmError identity.
Default coverage
Built-in rules cover:
- PEM private keys;
- GitHub, AWS, Google, Slack, Stripe, npm, PyPI, Hugging Face, GitLab, and common sk-* provider keys;
- bearer and basic-auth credentials;
- credentialed PostgreSQL, MySQL, MongoDB, and Redis URLs;
- high-confidence password=, api_key=, access_token=, and related assignments.
Common placeholders such as process.env.API_KEY, changeme, and your_api_key are ignored. Pattern matching is intentionally conservative; it is a safety layer, not a complete secret scanner.
Configure
Later DSH patch layers override a row by id. Add this to the profile's cordis.patch.yml and restate the row name:
`yaml
- id: egress-guard
name: dsh-egress-guard
config:
mode: block
scanToolSchemas: true
blockUnscannable: true
maxScanBytes: 4194304
maxFindings: 64
skipProviders: []
skipPurposes: []
customRules: []
`
Available settings:
| Setting | Default | Meaning |
|---|---:|---|
| mode | block | block stops dispatch; audit logs redacted metadata and continues. |
| scanToolSchemas | true | Scan tool descriptions and JSON schemas sent to the model. |
| blockUnscannable | true | Block images, malformed model fields, and unknown future content types. Unsafe request graph structures always block. |
| maxScanBytes | 4194304 | Maximum UTF-8 request text scanned; exceeding it blocks. Range: 1 KiB–16 MiB. |
| maxFindings | 64 | Maximum distinct rule/location records retained. Counts still fail closed. |
| skipProviders | [] | Provider routes that bypass the guard. |
| skipPurposes | [] | Any of conversation, compaction, or session-title to bypass explicitly. |
| customRules | [] | Up to 32 deterministic literal-prefix + fixed-alphabet suffix rules. |
Custom rule example:
`yaml
customRules:
- id: acme-production-key
prefix: 'ACME-PROD-'
alphabet: 'ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789'
length: 24
`
Custom rules do not execute regular expressions. The matcher finds a literal prefix, then requires exactly length characters from alphabet and a suffix boundary. Prefixes must be 4–64 printable ASCII characters and end in a delimiter outside the alphabet; alphabets contain 2–128 unique printable ASCII characters; suffix length is 1–256. This deliberately narrow format keeps custom scanning deterministic and avoids regular-expression backtracking.
What is scanned
- the system prompt;
- provider/model routing ids, reasoning effort, and session id metadata;
- each message's provider-facing text and reasoning channels;
- message source/provenance fields, including adapter replay metadata;
- raw JSON tool-call arguments;
- nested tool-result content, including text reconstructed across nested result layers;
- tool descriptions and parameter schemas;
- stop sequences;
- ordinary conversation, compaction, and session-title requests.
Text is joined only inside the same message and channel, matching the provider serializer. It is never joined across messages.
Safety boundary
This plugin prevents a matching request from reaching the downstream DSH model adapter. It is not a machine-wide network firewall.
Important limits:
- Text already entered into DSH may remain in the local session log even when outbound dispatch is blocked.
- Binary image contents are not OCR-scanned; they block by default.
- The guard freezes the same request object graph before scanning so a direct caller cannot mutate it during asynchronous adapter resolution; the live AbortSignal remains unfrozen.
- Encoded, fragmented, novel, or low-entropy secrets may evade regular-expression detection.
- A malicious plugin that exfiltrates data outside the normal downstream adapter path is outside this plugin's boundary.
- Same-process code that mutates shared JavaScript prototypes or other globals after preflight is also outside the boundary; the guard freezes the request's own plain-data graph, not the whole runtime.
- audit mode records only rule ids, structural locations, counts, a one-way provider fingerprint, and request purpose, but it does not prevent egress.
Development
Requires Node.js 22.19.x or 24 and newer, plus DeepSeek Harness 0.1.0-rc.6 or a compatible 0.1.x preview.
`sh
npm install
npm run check
npm run pack:check
`
The package ships plain ESM and leaves @deepseek-ai/dsh-llm external so the host's LlmError identity remains intact.
中文说明
这是一个纯本地的 DSH 模型请求出站检查插件。它在 llm/stream` 边界扫描完整请求;发现疑似密钥时不调用下游模型适配器,并返回固定的脱敏错误。默认不联网、不改写请求、扫描不了的图片或未知内容直接阻断。注意:它只阻止模型请求外发,不会自动清理已经写入本地 session 日志的原文。
License
MIT安装
🧩 让 Agent 自动装(推荐)
装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:
dsh plugin add dshbase-catalog 然后对 agent 说「帮我装 dsh-egress-guard」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。
该插件是 GitHub 源码(未发 npm)——直接从仓库装:
Web profile:
dsh plugin --profile web add github:LKRCharon/dsh-egress-guard Headless(CLI)profile:
dsh plugin --profile headless add github:LKRCharon/dsh-egress-guard 实测报告
验证通过:从 GitHub 源码完成 L1 安装 + L2 加载 + L3 运行(dsh 0.1.0-rc.6)。
使用场景
扩展 agent 的编码能力面——给它一个新工具、工作流或集成,让它接手以前做不了的开发任务。
适合谁
想让 dsh 在真实代码库上像队友一样干活的开发者——能改、能跑、能验证,而不只是回答问题。
二次开发建议
工具/命令面就是缝:暴露更多 SDK 能力、加更聪明的上下文接线,或收紧改代码与验证之间的循环。