dsh-plugin-credential-guard
v0.1.0
Published
DeepSeek Harness plugin: deny read/read_image/grep/glob calls whose path matches credential-store or secret-file patterns (.credentials.yaml, .env, .ssh, id_* keys, ...).
Maintainers
Readme
dsh-plugin-credential-guard
DeepSeek Harness 插件:拒绝模型对凭据存储与密钥文件的读取。
背景
harness 的文件读取在所有权限模式下都不受限(fs-sandbox 只拦写)。因此模型可以直接 read $DSH_HOME/.credentials.yaml、项目 .env、~/.ssh 密钥等,把密钥内容带进模型上下文。本插件在工具层关上这扇门。
效果
注册一个 tools.guard:read / read_image / grep / glob 的目标路径若命中敏感模式(.credentials.yaml、.env、.ssh/、id_* 密钥、.npmrc、.netrc、.pgpass),直接拒绝并返回 [credential-guard] ... 原因。
安装
dsh plugin --profile web add dsh-plugin-credential-guard挂载(profile cordis.patch.yml 或 agent preset):
- id: credential-guard
name: dsh-plugin-credential-guard
config:
tools: [read, read_image, grep, glob]
# patterns 可覆盖默认列表(见 lib/patterns.js 的 DEFAULT_PATTERNS)边界(诚实声明)
- 只拦工具调用(read/read_image/grep/glob 的路径参数)。
pwsh/bash里cat ~/.dsh/.credentials.yaml仍然可读——那需要宿主侧修复(启动后 scrub 进程环境、或在 fs-sandbox 层拦截读)。本插件是外部插件能做的最大范围。 - 匹配是路径级(basename / 目录段),不做内容嗅探。
开发
npm test