dsh-model-redactor
Model-visible redaction plugin for DeepSeek Harness (dsh). It redacts sensitive material (API keys, tokens, credentials) from what the model sees:
- Input (
agent/pre-step): user messages are rewritten to redacted copies
before they enter the session log and the model request. Already-logged tool results are redacted through session surface replacement, preserving the original append-origin events in the durable log.
- Output (
llm/stream): text, reasoning, and tool-call argument deltas are
redacted before the agent loop logs them, so the log and future model context stay consistent. block-end payloads are also redacted so the assembled assistant message cannot reintroduce a secret.
Install / compose
Add the row to a Cordis patch:
- insert:
- id: dsh-model-redactor
name: dsh-model-redactor
config:
enabled: trueThe package ships cordis.patch.yml and declares dsh.bundle.patch for bundle profiles.
Configuration
| Field | Type | Default | Description | | --- | --- | --- | --- | | enabled | boolean | true | Master switch. | | replacement | string | [REDACTED] | Replacement text (1..128 chars). Must not itself match a built-in secret pattern. | | customRegexes | Array<{ pattern, flags?, replacement? }> | [] | Extra regex rules. | | customWords | Array<string \| { word, replacement? }> | [] | Exact-word rules. |
Built-in rules are fixed and cannot be disabled. They cover OpenAI-style sk-, Bearer, Basic, GitHub tokens, Slack tokens, JWTs, assignment patterns, PEM private-key blocks, and AWS AKIA access key IDs.
Build and test
pnpm build
pnpm testtsc emits lib/. Unit and integration tests use Vitest.