DeepSeek Harness Plugin

ylwl1997/noatmark-dsh-plugin

Stars ★ 1 Category Security & Permissions Added 2026-08-14

Text hygiene as a dsh plugin: sanitize untrusted text, scan invisible characters, clean LLM formatting, and escape CSV formula injection.

Install

# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)

dsh plugin --profile web add github:ylwl1997/noatmark-dsh-plugin

Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).

README

NoAtMark text hygiene as a DeepSeek Harness (dsh) plugin.

Everything-is-a-plugin: this plugin gives your dsh agent four text-hygiene tools, backed by the same deterministic engines behind noatmark.com.

Tools

Tool What it does
sanitize_text Strip invisible/zero-width characters and flag prompt-injection + hidden-text signals.
scan_text Report invisible characters (with code points + positions), injection patterns, and hidden text.
clean_format Clean LLM formatting artifacts (blank lines, stray fences, trailing spaces) — meaning untouched.
sanitize_csv Escape CSV formula injection (OWASP): = + - @ prefixes get a leading quote.

All processing is deterministic and local — no data leaves your machine.

Install

Add this plugin to your dsh Web UI. If you're running from a source checkout, use a cordis.yml patch:

- insert:
    - id: noatmark
      name: noatmark-dsh-plugin

or point at the source directly (absolute path):

- insert:
    - id: noatmark
      name: '/path/to/noatmark-dsh-plugin/src/index.ts'

Start dsh with the patch:

npx @deepseek-ai/dsh web --patch ./cordis.yml

Usage

In a dsh session, ask the agent to use a tool, e.g.:

Sanitize this pasted text before you summarize it.

Scan this file for invisible characters.

Clean the formatting of this AI output.

Escape this CSV before saving it.

Development

pnpm install
pnpm build   # tsc -> dist/

Resources

MIT

Content from the project README on GitHub ↗

Links

More in this category

View the whole category →

Community comments

Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.