← 返回列表
D

dsh-airlock

v0.1.0 · 1 天前发布

Provenance-gated tool use for DeepSeek Harness (dsh) — labels every input, propagates the labels, and denies capabilities over labels instead of argument strings

deepseek-harnessdshdsh-pluginsecurityprompt-injectioninformation-flowprovenancetaintexfiltrationguard

README

dsh-airlock

Provenance-gated tool use for DeepSeek Harness (dsh).

Status: 0.1.0.

The plugin labels context by origin and enforces rules over those labels at five seams.

The seam claims are verified against dsh 0.1.0-rc.6, which warns of compatibility-breaking changes.

The behaviour is verified end to end against dsh 0.1.0-rc.6. See Verified end to end.

Expect breaking changes while the harness is a release candidate.

>
Read the shell hole before you rely on secret-no-egress.

A secret read through bash is not labelled, so egress stays open.

A live run reproduced a one-line shell command that read a credential file and

posted it, with the plugin mounted, and the
查看完整 README →

版本兼容矩阵

DSH 版本状态说明
dsh@0.1.0-rc.6 ❓ 未知 metadata 缺失
dsh@0.1.0 ❓ 未知
dsh@0.2.0 ⚠️ 待验证 待实测(API 可能在变)
dsh@0.3.0+ ❓ 未知 尚未发布

💡 兼容矩阵每周末自动跑实测,欢迎 PR 修正

元数据

License
MIT
npm
dsh-airlock
Repo
git+https://github.com/krimvp/dsh-airlock.git
Engines
{"node":">=20.6.0"}
Weekly DL
0
Monthly DL
0
dsh.bundle
{}