dshbase

Plugin directory / Developer / dsh-model-redactor

dsh-model-redactor

Unverified zerodegress

✓ Actively maintained Builds on 5 official DSH packages

View on GitHub ↗ ← Back to plugin directory

1Stars
0Forks
0Open issues
Language
2026-08-16Last push
Cross-platformPlatform

What it does

A plugin in the Developer category for DeepSeek Harness.

Our take
Unverified — not yet verified

A plugin in the Developer category for DeepSeek Harness. Not yet verified — install and test it yourself.

“Unverified” means our automated CI has not yet installed this plugin. Feature descriptions and version compatibility are the author’s claims. This is not a security audit and not an endorsement of third-party code.

Plugin author? Get the “Verified” label — submit your own evidence (screenshots, logs, or a short demo) and we'll review and flip the badge.

Submit verification evidence ↗

README

dsh-model-redactor

Model-visible redaction plugin for DeepSeek Harness (dsh). It redacts
sensitive material (API keys, tokens, credentials) from what the model sees:

  • Input (agent/pre-step): user messages are rewritten to redacted copies
    before they enter the session log and the model request. Already-logged tool
    results are redacted through session surface replacement, preserving the
    original append-origin events in the durable log.
  • Output (llm/stream): text, reasoning, and tool-call argument deltas are
    redacted before the agent loop logs them, so the log and future model context
    stay consistent. block-end payloads are also redacted so the assembled
    assistant message cannot reintroduce a secret.

Install / compose

Add the row to a Cordis patch:

- insert:
    - id: dsh-model-redactor
      name: dsh-model-redactor
      config:
        enabled: true

The package ships cordis.patch.yml and declares dsh.bundle.patch for bundle
profiles.

Configuration

Field Type Default Description
enabled boolean true Master switch.
replacement string [REDACTED] Replacement text (1..128 chars). Must not itself match a built-in secret pattern.
customRegexes Array<{ pattern, flags?, replacement? }> [] Extra regex rules.
customWords Array<string | { word, replacement? }> [] Exact-word rules.

Built-in rules are fixed and cannot be disabled. They cover OpenAI-style sk-,
Bearer, Basic, GitHub tokens, Slack tokens, JWTs, assignment patterns,
PEM private-key blocks, and AWS AKIA access key IDs.

Build and test

pnpm build
pnpm test

tsc emits lib/. Unit and integration tests use Vitest.

Install

🧩 Let your agent install it (recommended)

Install the catalog once, then DeepSeek Harness can find and install any plugin from this site automatically:

dsh plugin add dshbase-catalog

Then say "install dsh-model-redactor for me" — your agent finds it in the directory and installs it. Docs: dshbase-catalog · verified packs.

This plugin is GitHub source (not published to npm) — install it straight from the repo:

Web profile:

dsh plugin --profile web add github:zerodegress/dsh-model-redactor

Headless (CLI) profile:

dsh plugin --profile headless add github:zerodegress/dsh-model-redactor

Test report

Not yet L3-verified — see failure note below if we already ran it.

Status: pending · last test 2026-08-27
Note: 验证: runtime-fail Browse all pending failures →
Security: not yet scanned — our daily static scan will cover it shortly.

Share this badge

More in Developer

Browse all 7795 plugins →