dshbase

插件目录 / Developer / dsh-egress-guard

dsh-egress-guard

已验证 · 实测可装 LKRCharon

✓ 持续维护 基于 2 个官方 DSH 包

查看 GitHub ↗ ← 返回插件目录

0Stars
0Forks
0未关闭 issue
JavaScript语言
2026-08-15最近推送
跨平台平台

功能简介

DSH本地无网密钥预检,失败即关闭。

✅
我们的评价
可用 — 实测通过,早期项目

DSH本地无网密钥预检,失败即关闭。 实测能干净安装、正常启动。早期项目,但功能可用。

「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。

README

dsh-egress-guard

Local, zero-network, deterministic secret preflight for DeepSeek Harness model requests. dsh-egress-guard inspects the fully assembled request at the official llm/stream boundary. It first validates and freezes the exact plain-data request graph that downstream code will consume. If it finds a likely credential, it stops before calling the downstream model adapter. Matches never appear in the error, finding report, or plugin log. The default policy is fail-closed: - known secret patterns block the request; - images and unknown content blocks block because this version cannot inspect their bytes safely; - requests larger than the configured scan limit block; - cyclic, proxy/accessor-backed, non-plain, sparse, oversized, non-enumerable, unknown-field, or otherwise unfreezable request graphs block even in audit mode; - invalid configuration prevents the plugin from loading. It does not rewrite request values and never sends request content to another service.

Install

From npm after the package is published: ``sh npx --yes @deepseek-ai/[email protected] plugin --profile web add dsh-egress-guard npx --yes @deepseek-ai/[email protected] --profile web --dump-config ` From the public GitHub repository now: `sh npx --yes @deepseek-ai/[email protected] plugin --profile web add git+https://github.com/LKRCharon/dsh-egress-guard.git npx --yes @deepseek-ai/[email protected] --profile web --dump-config ` From a local checkout, use a file: specifier so pnpm installs a package copy instead of a symlink: `sh npx --yes @deepseek-ai/[email protected] plugin --profile web add file:/absolute/path/to/dsh-egress-guard npx --yes @deepseek-ai/[email protected] --profile web --dump-config ` For a release-equivalent local smoke test, run npm pack in the checkout and add the resulting .tgz by absolute path. Do not add a bare checkout path: rc.6 treats it as a symlink, which can bypass the profile's host-module fallback at real startup. The preview CLI delegates plugin installation to pnpm, so ensure it is on PATH first. With Corepack, run corepack enable pnpm; alternatively install pnpm 11 directly. A global dsh install may replace the pinned npx prefix above. The dump should contain an egress-guard row before you start the profile. DSH rc.6 profiles disable automatic peer installation. The add command can therefore warn about the @deepseek-ai/cordis and @deepseek-ai/dsh-llm peers even though the host supplies them at runtime. They intentionally remain peer dependencies so the plugin shares the host runtime and LlmError identity.

Default coverage

Built-in rules cover: - PEM private keys; - GitHub, AWS, Google, Slack, Stripe, npm, PyPI, Hugging Face, GitLab, and common
sk-* provider keys; - bearer and basic-auth credentials; - credentialed PostgreSQL, MySQL, MongoDB, and Redis URLs; - high-confidence password=, api_key=, access_token=, and related assignments. Common placeholders such as process.env.API_KEY, changeme, and your_api_key are ignored. Pattern matching is intentionally conservative; it is a safety layer, not a complete secret scanner.

Configure

Later DSH patch layers override a row by id. Add this to the profile's
cordis.patch.yml and restate the row name: `yaml - id: egress-guard name: dsh-egress-guard config: mode: block scanToolSchemas: true blockUnscannable: true maxScanBytes: 4194304 maxFindings: 64 skipProviders: [] skipPurposes: [] customRules: [] ` Available settings: | Setting | Default | Meaning | |---|---:|---| | mode | block | block stops dispatch; audit logs redacted metadata and continues. | | scanToolSchemas | true | Scan tool descriptions and JSON schemas sent to the model. | | blockUnscannable | true | Block images, malformed model fields, and unknown future content types. Unsafe request graph structures always block. | | maxScanBytes | 4194304 | Maximum UTF-8 request text scanned; exceeding it blocks. Range: 1 KiB–16 MiB. | | maxFindings | 64 | Maximum distinct rule/location records retained. Counts still fail closed. | | skipProviders | [] | Provider routes that bypass the guard. | | skipPurposes | [] | Any of conversation, compaction, or session-title to bypass explicitly. | | customRules | [] | Up to 32 deterministic literal-prefix + fixed-alphabet suffix rules. | Custom rule example: `yaml customRules: - id: acme-production-key prefix: 'ACME-PROD-' alphabet: 'ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789' length: 24 ` Custom rules do not execute regular expressions. The matcher finds a literal prefix, then requires exactly length characters from alphabet and a suffix boundary. Prefixes must be 4–64 printable ASCII characters and end in a delimiter outside the alphabet; alphabets contain 2–128 unique printable ASCII characters; suffix length is 1–256. This deliberately narrow format keeps custom scanning deterministic and avoids regular-expression backtracking.

What is scanned

- the system prompt; - provider/model routing ids, reasoning effort, and session id metadata; - each message's provider-facing text and reasoning channels; - message source/provenance fields, including adapter replay metadata; - raw JSON tool-call arguments; - nested tool-result content, including text reconstructed across nested result layers; - tool descriptions and parameter schemas; - stop sequences; - ordinary conversation, compaction, and session-title requests. Text is joined only inside the same message and channel, matching the provider serializer. It is never joined across messages.

Safety boundary

This plugin prevents a matching request from reaching the downstream DSH model adapter. It is not a machine-wide network firewall. Important limits: - Text already entered into DSH may remain in the local session log even when outbound dispatch is blocked. - Binary image contents are not OCR-scanned; they block by default. - The guard freezes the same request object graph before scanning so a direct caller cannot mutate it during asynchronous adapter resolution; the live
AbortSignal remains unfrozen. - Encoded, fragmented, novel, or low-entropy secrets may evade regular-expression detection. - A malicious plugin that exfiltrates data outside the normal downstream adapter path is outside this plugin's boundary. - Same-process code that mutates shared JavaScript prototypes or other globals after preflight is also outside the boundary; the guard freezes the request's own plain-data graph, not the whole runtime. - audit mode records only rule ids, structural locations, counts, a one-way provider fingerprint, and request purpose, but it does not prevent egress.

Development

Requires Node.js 22.19.x or 24 and newer, plus DeepSeek Harness
0.1.0-rc.6 or a compatible 0.1.x preview. `sh npm install npm run check npm run pack:check ` The package ships plain ESM and leaves @deepseek-ai/dsh-llm external so the host's LlmError identity remains intact.

中文说明

这是一个纯本地的 DSH 模型请求出站检查插件。它在
llm/stream` 边界扫描完整请求;发现疑似密钥时不调用下游模型适配器,并返回固定的脱敏错误。默认不联网、不改写请求、扫描不了的图片或未知内容直接阻断。注意:它只阻止模型请求外发,不会自动清理已经写入本地 session 日志的原文。

License

MIT

安装

🧩 让 Agent 自动装(推荐)

装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:

dsh plugin add dshbase-catalog

然后对 agent 说「帮我装 dsh-egress-guard」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。

该插件是 GitHub 源码(未发 npm)——直接从仓库装:

Web profile:

dsh plugin --profile web add github:LKRCharon/dsh-egress-guard

Headless(CLI)profile:

dsh plugin --profile headless add github:LKRCharon/dsh-egress-guard

实测报告

验证通过:从 GitHub 源码完成 L1 安装 + L2 加载 + L3 运行(dsh 0.1.0-rc.6)。

使用场景

扩展 agent 的编码能力面——给它一个新工具、工作流或集成,让它接手以前做不了的开发任务。

适合谁

想让 dsh 在真实代码库上像队友一样干活的开发者——能改、能跑、能验证,而不只是回答问题。

二次开发建议

工具/命令面就是缝:暴露更多 SDK 能力、加更聪明的上下文接线,或收紧改代码与验证之间的循环。

安全:尚未扫描——我们的每日静态扫描将很快覆盖它。

分享徽章

Developer 里更多

浏览全部 7797 个插件 →