D
dsh-plugin-credential-guard
v0.1.0 · 4 天前发布
DeepSeek Harness plugin: deny read/read_image/grep/glob calls whose path matches credential-store or secret-file patterns (.credentials.yaml, .env, .ssh, id_* keys, ...).
README
dsh-plugin-credential-guard
DeepSeek Harness 插件:拒绝模型对凭据存储与密钥文件的读取。
背景
harness 的文件读取在所有权限模式下都不受限(fs-sandbox 只拦写)。因此模型可以直接 read $DSH_HOME/.credentials.yaml、项目 .env、~/.ssh 密钥等,把密钥内容带进模型上下文。本插件在工具层关上这扇门。
效果
注册一个 tools.guard:read / read_image / grep / glob 的目标路径若命中敏感模式(.credentials.yaml、.env、.ssh/、id_* 密钥、.npmrc、.netrc、.pgpass),直接拒绝并返回 [credential-guard] ... 原因。
安装
bash
dsh plugin --profile web add dsh-plugin-credential-guard
挂载(profile cordis.patch.yml 或 agent preset):
yaml
id: credential-guard
name: dsh-plugin-credential-guard
config:
tools: [read, read_image, grep, glob]
# patterns 可覆盖默认列表(见 lib/patterns.js 的 DEFAULT_PATTERNS)
边界(诚实声明)
pwsh/bash 里 `版本兼容矩阵
| DSH 版本 | 状态 | 说明 |
|---|---|---|
dsh@0.1.0-rc.6 | ❓ 未知 | metadata 缺失 |
dsh@0.1.0 | ❓ 未知 | — |
dsh@0.2.0 | ⚠️ 待验证 | 待实测(API 可能在变) |
dsh@0.3.0+ | ❓ 未知 | 尚未发布 |
💡 兼容矩阵每周末自动跑实测,欢迎 PR 修正
元数据
- License
- MIT
- npm
- dsh-plugin-credential-guard
- Repo
- —
- Engines
{"node":">=18"}- Weekly DL
- 0
- Monthly DL
- 0
- dsh.bundle
{}