npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

dsh-redact

v0.1.0

Published

Fail-closed canonical tool-output tokenization for DeepSeek Harness

Readme

dsh-redact

Fail-closed canonical tool-output tokenization for DeepSeek Harness.

dsh-redact replaces common credentials with opaque, Agent-scoped tokens before the final tool result reaches model context or durable Session history. It replaces the successful canonical value through tools/post-execute, so Harness validates the replacement against the tool's declared output schema and renders model content from the accepted value again.

password=FAKE_PASSWORD

→ password=⟦dsh:redact:550e8400-e29b-41d4-a716-446655440000⟧

The token mapping exists only in process memory. Agent disposal clears it, and a restart makes old tokens intentionally unrestorable.

Install

From a Harness environment:

dsh plugin --profile web add dsh-redact
dsh --profile web --dump-config

For local development, run the same command from this directory and replace the package name with ..

The bundle patch registers the plugin as redact; version 1 has no user configuration.

Protected shapes

  • password, passwd, and pwd fields;
  • secret, API-key, app-key, access-key, and signature fields;
  • token and access-token fields;
  • authorization and bearer/basic headers;
  • webhook and robot URL fields;
  • private-key fields and PEM private-key bodies;
  • credentials in URL query parameters;
  • recursively nested arrays, objects, and JSON-encoded strings.

Source references such as environment-variable reads, function calls, type annotations, and declaration placeholders remain visible. JSON-encoded strings are parsed structurally and serialized back as valid JSON. Encoding deeper than 8 string layers is blocked instead of falling back to unsafe pass-through.

Runtime guarantees

  • The prepended tools/post-execute listener wraps later post policies and sanitizes their effective decision.
  • Successful output is returned as a canonical value replacement. Harness output-schema validation remains authoritative.
  • Failed results with sensitive immutable error, meta, or deferred context fields become safe blocked results instead of retaining the original structure.
  • Sanitizer, vault, downstream-policy, and audit-append failures block with constant secret-free feedback.
  • Tokens are stable for the same secret only within one live Agent. Different Agents never share a mapping.
  • redaction/applied is appended only after a replacement and contains exactly a count and sorted category list:
{
  "count": 2,
  "categories": ["password", "token"]
}

No original value, replacement token, tool name, arguments, or error detail enters that event.

Deliberate exclusions

Version 1 does not:

  • inspect or rewrite user messages before they enter the Session inbox;
  • restore tokens into tool arguments or commands;
  • persist or encrypt the token mapping;
  • rewrite assistant messages—the model sees tokens, so canonical assistant output remains tokenized;
  • guarantee sanitization of content a tool-owned finalizeContent callback introduces after tools/post-execute;
  • emit a durable audit event for an Agentless, same-process ToolRuntime.execute() call.

Tools that need an original credential cannot consume a returned token in version 1. Tool definitions and plugins that run after the canonical boundary remain trusted code and must not synthesize secrets into later presentation content.

A successful downstream post policy that replaces only rendered content is superseded by the canonical value replacement, because retaining a raw canonical value would weaken the confidentiality boundary. Downstream security or spill policies should transform canonical values when they must compose with dsh-redact.

Trusted presentation restoration

Restoration is available only as an explicit in-memory primitive; the default plugin does not reveal tokens. A trusted same-process host can retain its own policy instance:

import { RedactionPolicy, installRedactionPolicy } from 'dsh-redact'

const policy = new RedactionPolicy()
installRedactionPolicy(ctx, policy)

// Presentation only. Never append this value to the Session log.
const visible = policy.restore(agent, tokenizedText)

restore() replaces only tokens owned by that Agent's live vault. Unknown token-looking strings stay unchanged.

Development

pnpm install --frozen-lockfile
pnpm --filter dsh-redact run check
pnpm --filter dsh-redact run pack:check

See the repository security policy for vulnerability reporting.