DeepSeek Harness plugin

dsh-plugins-kestiny1

Fail-closed canonical tool-output tokenization for DeepSeek Harness

Jump to install

Source facts

Repository
kestiny18/dsh-plugins
Latest update
Aug 21, 2026
Category
Tools & Capabilities
GitHub stars
2
Format
plugin
Package path
dsh-redact
Catalog evidence
Upstream dsh.bundle evidence
Evidence path
dsh-redact/package.json#dsh.bundle
Checked against
0.1.0-rc.8
Upstream check date
2026-08-20

This evidence comes from the upstream catalog. This site has not installed, run, or security-reviewed the plugin.

Install

Start with a prompt that asks an agent to review the GitHub repository and source. Switch to the command if you want to install it yourself.

Copy this prompt into DSH, Codex, or another agent and ask it to review the GitHub repository and source first.

Do not install or run any commands yet. Read this plugin's GitHub repository, README, and relevant source code. Then answer the questions below clearly and directly so I can decide whether it fits my needs:

1. What is this plugin, and what problem does it solve?
2. Who is it for, and what are its typical use cases?
3. How is it used after installation? Include one minimal example.
4. What known limitations or privacy, security, compatibility, or maintenance risks does it have?
5. Give a clear recommendation: recommend, conditionally recommend, or do not recommend, with reasons.

Distinguish statements documented by the repository, inferences from source code, and unknowns. If evidence is insufficient, say so explicitly. Do not guess or simply repeat the README.

GitHub: https://github.com/kestiny18/dsh-plugins/tree/HEAD/dsh-redact
Plugin: dsh-plugins-kestiny1
Author: kestiny18

Check the source files

Read the README and other files from this plugin directory before installing.

File explorer3 files
README.mdSource · read only

dsh-redact

Fail-closed canonical tool-output tokenization for DeepSeek Harness.

dsh-redact replaces common credentials with opaque, Agent-scoped tokens before the final tool result reaches model context or durable Session history. It replaces the successful canonical value through tools/post-execute, so Harness validates the replacement against the tool's declared output schema and renders model content from the accepted value again.

password=FAKE_PASSWORD

→ password=⟦dsh:redact:550e8400-e29b-41d4-a716-446655440000⟧

The token mapping exists only in process memory. Agent disposal clears it, and a restart makes old tokens intentionally unrestorable.

Install

From a Harness environment:

dsh plugin --profile web add dsh-redact
dsh --profile web --dump-config

For local development, run the same command from this directory and replace the package name with ..

The bundle patch registers the plugin as redact; version 1 has no user configuration.

Protected shapes

  • password, passwd, and pwd fields;
  • secret, API-key, app-key, access-key, and signature fields;
  • token and access-token fields;
  • authorization and bearer/basic headers;
  • webhook and robot URL fields;
  • private-key fields and PEM private-key bodies;
  • credentials in URL query parameters;
  • recursively nested arrays, objects, and JSON-encoded strings.

Source references such as environment-variable reads, function calls, type annotations, and declaration placeholders remain visible. JSON-encoded strings are parsed structurally and serialized back as valid JSON. Encoding deeper than 8 string layers is blocked instead of falling back to unsafe pass-through.

Runtime guarantees

  • The prepended tools/post-execute listener wraps later post policies and sanitizes their effective decision.
  • Successful output is returned as a canonical value replacement. Harness output-schema validation remains authoritative.
  • Failed results with sensitive immutable error, meta, or deferred context fields become safe blocked results instead of retaining the original structure.
  • Sanitizer, vault, downstream-policy, and audit-append failures block with constant secret-free feedback.
  • Tokens are stable for the same secret only within one live Agent. Different Agents never share a mapping.
  • redaction/applied is appended only after a replacement and contains exactly a count and sorted category list:
{
  "count": 2,
  "categories": ["password", "token"]
}

No original value, replacement token, tool name, arguments, or error detail enters that event.

Deliberate exclusions

Version 1 does not:

  • inspect or rewrite user messages before they enter the Session inbox;
  • restore tokens into tool arguments or commands;
  • persist or encrypt the token mapping;
  • rewrite assistant messages—the model sees tokens, so canonical assistant output remains tokenized;
  • guarantee sanitization of content a tool-owned finalizeContent callback introduces after tools/post-execute;
  • emit a durable audit event for an Agentless, same-process ToolRuntime.execute() call.

Tools that need an original credential cannot consume a returned token in version 1. Tool definitions and plugins that run after the canonical boundary remain trusted code and must not synthesize secrets into later presentation content.

A successful downstream post policy that replaces only rendered content is superseded by the canonical value replacement, because retaining a raw canonical value would weaken the confidentiality boundary. Downstream security or spill policies should transform canonical values when they must compose with dsh-redact.

Trusted presentation restoration

Restoration is available only as an explicit in-memory primitive; the default plugin does not reveal tokens. A trusted same-process host can retain its own policy instance:

import { RedactionPolicy, installRedactionPolicy } from 'dsh-redact'

const policy = new RedactionPolicy()
installRedactionPolicy(ctx, policy)

// Presentation only. Never append this value to the Session log.
const visible = policy.restore(agent, tokenizedText)

restore() replaces only tokens owned by that Agent's live vault. Unknown token-looking strings stay unchanged.

Development

pnpm install --frozen-lockfile
pnpm --filter dsh-redact run check
pnpm --filter dsh-redact run pack:check

See the repository [security policy](../SECURITY.md) for vulnerability reporting.