Gabrip780/dsh-hidden-paths ↗★ 0
dsh-hidden-paths
Deny an AI agent access to .env files, credential stores, keys and any path you hide — across file tools, shell commands, search selectors and run_code. A DeepSeek Harness (dsh) plugin. 适合需要保护本地密钥、凭据及特定目录不被Agent读取的安全管控场景。
インストール
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:Gabrip780/dsh-hidden-pathsドキュメント
README 全文を読む ↗Configuration
- id: dsh-hidden-paths
config:
hiddenPaths: [] # ABSOLUTE paths (folders or files) to hide
guardRoots: [] # legacy alias of hiddenPaths, still accepted
extraNameRules: [] # extra basename globs, e.g. "*.vault"
extraDirSegments: [] # extra directory names protected anywhere
allow: [] # exceptions; never re-opens a hiddenPath
maskResults: true # layer 2: credential redaction
hidePathsInResults: true # layer 2: also mask hidden path names
maskNotice: true # add a notice line when something was hidden
A config typo cannot silently disarm the guard:
- a string where an array is expected is read as the single entry you meant (it used to spread into characters and protect nothing);
- a relative path is resolved against the process cwd and logged as a warning;
hiddenPaths: ["/"]really does hide everything, and says so in a warning;- if the configuration cannot be read at all, the plugin denies every tool call and logs why, rather than failing open.