DeepSeek Harness 插件

dsh-model-redactor

Model-visible redaction plugin for DeepSeek Harness: redacts secrets from model input and output streams(英文原文)

跳到安装方式

来源信息

GitHub 仓库
zerodegress/dsh-model-redactor
最近更新
2026年8月16日
分类
工具与能力
GitHub stars
1
载体类型
plugin
目录证据
上游声明已找到 dsh.bundle
证据路径
package.json#dsh.bundle
核对版本
0.1.0-rc.8
上游核对日期
2026-08-20

该证据由上游目录提供。本站没有安装、运行或安全审核这个插件。

安装

默认先复制一段 Prompt,让 Agent 读 GitHub 仓库和源码;需要自己装时再切到命令。

复制这段 Prompt,发给 DSH、Codex 或其他 Agent,让它先读 GitHub 仓库和源码。

请先不要安装或执行任何命令。阅读这个插件的 GitHub 仓库、README 和关键源码,然后用清楚、直接的方式回答以下问题,帮助我判断它是否适合我的需求:

1. 这个插件是什么,解决什么问题;
2. 适合哪些用户和典型使用场景;
3. 安装后如何使用,并给出一个最小使用示例;
4. 有哪些已知限制,以及隐私、安全、兼容性或维护风险;
5. 给出“推荐 / 有条件推荐 / 不推荐”的明确建议和理由。

请区分仓库明确说明、根据源码推断和未知信息。证据不足时请明确说明,不要猜测或照抄 README。

GitHub:https://github.com/zerodegress/dsh-model-redactor
插件名:dsh-model-redactor
作者:zerodegress

检查来源文件

安装前先看这个插件目录里的 README 和其他文件。

文件资源管理器3 个文件
README.md来源说明 · 只读预览

dsh-model-redactor

Model-visible redaction plugin for DeepSeek Harness (dsh). It redacts sensitive material (API keys, tokens, credentials) from what the model sees:

  • Input (agent/pre-step): user messages are rewritten to redacted copies

before they enter the session log and the model request. Already-logged tool results are redacted through session surface replacement, preserving the original append-origin events in the durable log.

  • Output (llm/stream): text, reasoning, and tool-call argument deltas are

redacted before the agent loop logs them, so the log and future model context stay consistent. block-end payloads are also redacted so the assembled assistant message cannot reintroduce a secret.

Install / compose

Add the row to a Cordis patch:

- insert:
    - id: dsh-model-redactor
      name: dsh-model-redactor
      config:
        enabled: true

The package ships cordis.patch.yml and declares dsh.bundle.patch for bundle profiles.

Configuration

| Field | Type | Default | Description | | --- | --- | --- | --- | | enabled | boolean | true | Master switch. | | replacement | string | [REDACTED] | Replacement text (1..128 chars). Must not itself match a built-in secret pattern. | | customRegexes | Array<{ pattern, flags?, replacement? }> | [] | Extra regex rules. | | customWords | Array<string \| { word, replacement? }> | [] | Exact-word rules. |

Built-in rules are fixed and cannot be disabled. They cover OpenAI-style sk-, Bearer, Basic, GitHub tokens, Slack tokens, JWTs, assignment patterns, PEM private-key blocks, and AWS AKIA access key IDs.

Build and test

pnpm build
pnpm test

tsc emits lib/. Unit and integration tests use Vitest.