okaditya84/dsh-agent-sentinel0

dsh-agent-sentinel

Security guard plugin for DeepSeek Harness: secret redaction, a shell command denylist, indirect prompt-injection scanning, and syntax verification on file writes.

AI Analysis

核心用途为 DSH 运行环境提供安全防护。适合对大模型执行代码、命令有高安全要求的用户,可拦截危险命令并防止敏感信息泄露。

Package
dsh-agent-sentinel
Version
0.1.0
License
MIT
Last updated
Aug 18, 2026

Install

This plugin has no verified bundle, or compatibility checks failed. Read the repository notes first. Read the full README ↗

Configuration reference

OptionTypeDefaultDescription
redactSecretsbooleantrueRedact secrets/credentials found in tool output content blocks.
customSecretPatterns{ name, pattern }[][]Additional secret regex patterns.
blockDangerousCommandsbooleantrueVeto shell calls matching the built-in destructive-command denylist.
customCommandRules{ id, pattern, reason, severity? }[][]Additional shell command denylist rules.
detectPromptInjectionsbooleantrueScan file-read/fetch output for prompt-injection patterns.
verifyCodeSyntaxbooleantrueVerify syntax of file writes/edits (JS, TS, JSON, Python).
auditLogPathstring.sentinel-audit.jsonlPath for the append-only JSONL audit log.
strictModebooleanfalseBlock (rather than just log) a write that introduces a syntax error.
maxAuditHistorynumber500In-memory audit ring-buffer size (independent of the on-disk log, which is never truncated by this plugin).