Gabrip780/dsh-hidden-paths ↗★ 0

dsh-hidden-paths

Deny an AI agent access to .env files, credential stores, keys and any path you hide — across file tools, shell commands, search selectors and run_code. A DeepSeek Harness (dsh) plugin. 适合需要保护本地密钥、凭据及特定目录不被Agent读取的安全管控场景。

Package
dsh-hidden-paths
Compatibility
Unverified
Version
1.0.1
License
MIT
Last updated
Sep 15, 2026

Install

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:Gabrip780/dsh-hidden-paths

Configuration

- id: dsh-hidden-paths
  config:
    hiddenPaths: []           # ABSOLUTE paths (folders or files) to hide
    guardRoots: []            # legacy alias of hiddenPaths, still accepted
    extraNameRules: []        # extra basename globs, e.g. "*.vault"
    extraDirSegments: []      # extra directory names protected anywhere
    allow: []                 # exceptions; never re-opens a hiddenPath
    maskResults: true         # layer 2: credential redaction
    hidePathsInResults: true  # layer 2: also mask hidden path names
    maskNotice: true          # add a notice line when something was hidden

A config typo cannot silently disarm the guard:

  • a string where an array is expected is read as the single entry you meant (it used to spread into characters and protect nothing);
  • a relative path is resolved against the process cwd and logged as a warning;
  • hiddenPaths: ["/"] really does hide everything, and says so in a warning;
  • if the configuration cannot be read at all, the plugin denies every tool call and logs why, rather than failing open.