← 返回列表
D

dsh-plugin-credential-guard

v0.1.0 · 4 天前发布

DeepSeek Harness plugin: deny read/read_image/grep/glob calls whose path matches credential-store or secret-file patterns (.credentials.yaml, .env, .ssh, id_* keys, ...).

dshdsh-plugindeepseek-harnesssecuritycredentialssecrets

README

dsh-plugin-credential-guard

DeepSeek Harness 插件:拒绝模型对凭据存储与密钥文件的读取。

背景

harness 的文件读取在所有权限模式下都不受限(fs-sandbox 只拦写)。因此模型可以直接 read $DSH_HOME/.credentials.yaml、项目 .env~/.ssh 密钥等,把密钥内容带进模型上下文。本插件在工具层关上这扇门。

效果

注册一个 tools.guardread / read_image / grep / glob 的目标路径若命中敏感模式(.credentials.yaml.env.ssh/id_* 密钥、.npmrc.netrc.pgpass),直接拒绝并返回 [credential-guard] ... 原因。

安装

bash
dsh plugin --profile web add dsh-plugin-credential-guard

挂载(profile cordis.patch.yml 或 agent preset):

yaml
  • id: credential-guard

  • name: dsh-plugin-credential-guard
    config:
    tools: [read, read_image, grep, glob]
    # patterns 可覆盖默认列表(见 lib/patterns.js 的 DEFAULT_PATTERNS)

    边界(诚实声明)

  • 只拦工具调用(read/read_image/grep/glob 的路径参数)。pwsh/bash 里 `
  • 版本兼容矩阵

    DSH 版本状态说明
    dsh@0.1.0-rc.6 ❓ 未知 metadata 缺失
    dsh@0.1.0 ❓ 未知
    dsh@0.2.0 ⚠️ 待验证 待实测(API 可能在变)
    dsh@0.3.0+ ❓ 未知 尚未发布

    💡 兼容矩阵每周末自动跑实测,欢迎 PR 修正

    元数据

    License
    MIT
    npm
    dsh-plugin-credential-guard
    Repo
    Engines
    {"node":">=18"}
    Weekly DL
    0
    Monthly DL
    0
    dsh.bundle
    {}