okaditya84/dsh-agent-sentinel ↗★ 0
dsh-agent-sentinel
Security guard plugin for DeepSeek Harness: secret redaction, a shell command denylist, indirect prompt-injection scanning, and syntax verification on file writes.
AI 分析
核心用途为 DSH 运行环境提供安全防护。适合对大模型执行代码、命令有高安全要求的用户,可拦截危险命令并防止敏感信息泄露。
インストール
検証済み bundle がないか、互換性チェックに失敗しています。先にリポジトリの説明を読んでください。 README 全文を読む ↗
ドキュメント
README 全文を読む ↗Configuration reference
| Option | Type | Default | Description |
|---|---|---|---|
redactSecrets | boolean | true | Redact secrets/credentials found in tool output content blocks. |
customSecretPatterns | { name, pattern }[] | [] | Additional secret regex patterns. |
blockDangerousCommands | boolean | true | Veto shell calls matching the built-in destructive-command denylist. |
customCommandRules | { id, pattern, reason, severity? }[] | [] | Additional shell command denylist rules. |
detectPromptInjections | boolean | true | Scan file-read/fetch output for prompt-injection patterns. |
verifyCodeSyntax | boolean | true | Verify syntax of file writes/edits (JS, TS, JSON, Python). |
auditLogPath | string | .sentinel-audit.jsonl | Path for the append-only JSONL audit log. |
strictMode | boolean | false | Block (rather than just log) a write that introduces a syntax error. |
maxAuditHistory | number | 500 | In-memory audit ring-buffer size (independent of the on-disk log, which is never truncated by this plugin). |