在 agent/pre-step、tools/pre-execute、tools/post-execute 三个接缝检测提示词注入、越狱与密钥泄露,按 allow/ask/block 分层拦截,附脱敏 defend/detection 审计事件、defend_report 工具与危险删除命令门禁。
安装
# npm 包(预构建)
dsh plugin --profile web add dsh-defend
# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)
dsh plugin --profile web add github:PerryLink/dsh-defend
装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本——pnpm 默认拦截,所以安装可能停在 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED 或 ERR_PNPM_IGNORED_BUILDS;dsh 会打印出需要添加的确切键名,把它加进该 profile 的 pnpm-workspace.yaml 的 allowBuilds 下,重跑一次即可装上。放行构建本身就是一次信任判断:请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。
README
🛡️ dsh-defend
- 1024 商店渠道:先
npm i -g dsh1024,再dsh1024 plugin --profile web add dsh-defend(计入 deepseek1024.com 安装排行)。
DeepSeek Harness 的提示注入、越狱与密钥泄露防护。
规则裁决已知的,拦截裁决其余的——一切都有审计。
English · 简体中文 · Español · Português · हिन्दी
📖 生态实测知识库(实测数据,不是营销):插件开发指南 · 选型实测数据 · 维护取舍判据。
维护状态:🧊 已冻结
2026-10-05 起冻结,不再新增功能。 本包仍可正常使用,没有退役——但不再投入功能开发,只有真实故障才会修复。
维护者判定该能力面已出现采用度更高、更值得推荐的替代方案,因此把精力移到了别处。
| 包 | 周下载量 | |
|---|---|---|
| 本包 | dsh-defend |
937 |
| 更值得推荐的替代品 | cc-safety-net |
13,087 |
为什么替代品更强。 cc-safety-net 作为编程 Agent 的 CLI hook,拦截破坏性命令与密钥文件访问。
本包仍然独有的能力。 从 prompt-injection / jailbreak / secret-leaker 三个上游资产集移植的 Aho-Corasick 模式引擎;对用户消息、工具参数、工具结果三处做 allow/ask/block 三档拦截;以及经脱敏的 defend/* 会话审计事件。上面的替代品范围更窄(只管破坏性命令与密钥文件),但采用度高出一个数量级。
👉 新工作请优先使用 cc-safety-net(若你只需要破坏性命令闸门);若你要的是更宽的检测面,本包仍是更广的那个,但已冻结不再加功能。 已安装的照常可用,没有任何东西被移除。
完整证据(含宿主版本兼容矩阵)见 dsh-plugin-supersession-review-20261005.md;英文版见 README.md 的 Maintenance status: 🧊 FROZEN 一节。
⭐ 如果它帮到了你
这个插件是 DSH 插件家族的一员(40+ 个,全部 Apache-2.0)。如果你在用,给个 star —— 它不会解锁任何功能,但会让下一个人在搜索里更容易找到它。
English: part of a 40+ plugin family for DeepSeek Harness. If it is useful, a star helps the next person find it — nothing is gated behind it.
兼容性
| 方面 | 状态 |
|---|---|
| Harness | DeepSeek Harness dsh-v0.2.1-alpha.1(2026-09-24 核验;peer 范围 >=0.1.2-rc.1 <0.2.0 || >=0.1.5-alpha.1 <0.2.0 || >=0.1.6-0 <0.2.0 || >=0.1.7-0 <0.2.0)。该线上 Session.append 的第三参仅对表面事件类型存在且为 SurfaceIntent,因此非表面的 defend/detection 仍无法盖章 ignorable:会话日志审计保持失败关闭式停用,/defend 显式渲染该状态。会话格式 V4 已无 tool-result 内容块——本插件从不生产它,两个内容 walker 只为退役的 V3 包裹块保留只读回退,使升级前写下的会话仍可被扫描。已于 2026-09-24 核验(双 typecheck 尺子 + 全量测试 + build + self-contained/artifacts 门 + pack;宿主类型图仅一份)。 |
| Node | ^22.19.0 || >=24.0.0 |
| 平台 | 全部(纯 host;无原生代码、无网络) |
| 模型 | 任意(检测发生在内容到达模型之前) |
你能得到什么
dsh-defend 在 agent 面前放了两层相互独立的防线:
- 危险删除门禁 —— 8·14/8·16 事故教训的可执行形态。在
tools/pre-execute上,递归删除类 shell 命令被拒绝,除非每个目标都是会话工作区内的显式绝对路径且不触碰受保护前缀(家目录配置、.dsh/.claude、系统目录)。dry-run 标记(-WhatIf、--dry-run、git clean -n)放行——它们正是教训要求的删除前核对。 - 检测层 —— 移植自四个上游资产(均为 Apache-2.0,见 THIRD_PARTY_NOTICES.md):25 条 Prompt-Injection-Payloads 规则、25 条 Jailbreak-Detector 模式(纯 TypeScript Aho-Corasick 自动机)、来自 Secret-Key-Leaker-Detect 与各签发方公开文档的 12 条密钥语法、以及原样保留为回归基准的 Prompt-Attack-Dataset。
三个拦截点,同一套决策模型:
| 拦截点 | 扫描内容 | 决策 |
|---|---|---|
agent/pre-step |
进入模型的消息 | allow → next();ask → 审批;block → 拒绝本步 |
tools/pre-execute |
工具参数 | allow → next();ask → 审批;block → deny |
tools/post-execute |
工具结果 | allow → next();ask → 审批;block → 纠正性反馈 |
默认:每个 family 均为 ask,critical 级密钥一律 block(上游「见即中断」语义)。没有审批应答者即失败关闭。每次放行都调用 next()——下游策略插件永不被短路。
入站消息 ── agent/pre-step ── 扫描 ── 干净 → next()/enter
工具参数 ── tools/pre-execute ── 扫描 ── 放行 → next()
工具结果 ── tools/post-execute ── 扫描 ── 拦截 → 反馈
│
└─ defend/detection 审计(规则 id/类别/
严重度/决策——从不含匹配文本)
快速开始
# 1. 把 bundle 装进你的 profile
dsh plugin --profile web add "github:PerryLink/dsh-defend#main"
# 或从 npm 安装(正式发布版)
dsh plugin --profile web add dsh-defend
# 2. 重启并核实行
dsh --profile web --dump-config | grep -A3 'id: dsh-defend'
安装与卸载
- git 通道(最新
main):dsh plugin --profile web add "github:PerryLink/dsh-defend#main"——prepare脚本仅用生产依赖构建。 - npm 通道(正式发布版):
dsh plugin --profile web add dsh-defend。 - tarball 通道:在本仓库执行
pnpm pack,然后dsh plugin --profile web add ./dsh-defend-<version>.tgz。 - 卸载:
dsh plugin --profile web remove dsh-defend(或从 profile patch 中删除该行)。
配置
所有可调项都是 Schemastery Config 字段(可在 cordis.yml 中修改)。按 id 定向覆盖会替换整行——需要重新声明每个键。cordis.patch.yml 内联说明了每个键。
| 键 | 默认值 | 含义 |
|---|---|---|
enabled |
true |
两层防线总开关 |
action |
deny |
危险删除门禁动作(deny / ask) |
toolNames |
['bash','persistent-bash','terminal-bash'] |
门禁评审命令参数的工具注册名 |
detection.enabled |
true |
检测层开关 |
detection.maxScanChars |
10000 |
每次拦截的扫描字符上限(只扫头部) |
detection.normalizeUnicode |
true |
扫描前 NFKC/Unicode 归一化(堵 lookalike-Unicode 绕过) |
detection.secretMinEntropy |
3.0 |
密钥命中后的最小 Shannon 熵(bits/字符),低于阈值视为误报丢弃;0 关闭 |
detection.injectionAction |
ask |
注入类:allow / ask / block |
detection.jailbreakAction |
ask |
越狱类:allow / ask / block |
detection.secretAction |
ask |
密钥类:allow / ask / block |
detection.secretBlockCritical |
true |
critical 密钥无视 secretAction 一律 block |
detection.audit |
true |
写 defend/detection 会话审计事件 |
detection.allowUnmarkedAudit |
false |
宿主不识别 ignorable 标记(截至目前所有已发布线,含 0.2.x 预发布线)或对未知事件类型 fail-closed(宿主 0.1.2-rc.1 及以后)时是否仍写会话日志审计(接受会话无法恢复的风险) |
detection.maxReportEntries |
200 |
内存环形缓冲条数上限 |
registerCommand |
true |
注册 /defend 命令 |
registerTool |
true |
注册 defend_report 工具 |
工具与界面
| 界面 | 类型 | 说明 |
|---|---|---|
defend_report |
工具 | 汇总(记录/拦截/询问数)、按 family 计数、最近 20 条——从不含匹配文本 |
/defend |
命令 | 同样的汇总文本 |
agent/pre-step |
监听 | 入站消息扫描(enter/reject) |
tools/pre-execute |
监听 | 工具参数扫描(deny/ask)+ 危险删除门禁 |
tools/post-execute |
监听 | 工具结果扫描(block 反馈) |
权限与数据
- 权限:ask 决策走官方审批接缝;绝不重实现或绕过。workshop manifest 声明
session:append与network:none。 - 数据:不落盘任何东西;报告环形缓冲仅在内存且有界。无网络请求、无子进程。
- 会话日志:
defend/detection事件只带规则 id、family、类别、严重度、密钥类型、决策与扫描事实——匹配文本从不入日志,密钥匹配在构造上只留类型。
安全边界
- 检测,而非执法。 门禁与检测层只在官方 seam 上产出 deny/ask/block 决策;沙箱与审批系统仍是执行权威。
- 失败关闭。 审批应答者缺失、会话缺失或服务面缺失时,一律退化为最严格决策——绝不静默放行。
- 内容不出进程。 扫描在本地完成;审计事件已脱敏;密钥绝不入日志、展示或报告。
- 有界工作。 扫描上限、每规则至多一条匹配、环形缓冲上限,恶意输入无法消耗无界资源。
已知限制
- 检测缺口。 规则库覆盖已移植词汇及其容错变体;新式措辞、形近 Unicode 编码(NFKC 归一化列为后续工作)与多步攻击可能绕过。基准把实测下限(上游数据集 27/28)钉进测试,回归可见。
- 无模型级判定。
dsh-defend是确定性的,绝不调用模型,无法判断全新意图。 - 消息拒绝是静默的。
agent/pre-step的 reject 不给模型理由(seam 没有理由字段);审计事件记录规则事实。 - 会话审计与
ignorable标记。 审计追加请求 envelope 的ignorable: true标记,任何 harness 构建都能加载日志。截至目前所有已发布线(0.1.0-rc.1–0.1.0-rc.8、0.1.1-rc.1–0.1.1-rc.2,以及0.2走廊——2026-10-04 对已发布0.2.1-alpha.1复核:其append(type, data, ...opts)只从 options 取sourceEventSeqs/surfaceOp,信封固定为{ type, seq, time, data })都会静默丢弃它——事件未标记落盘,更严格构建上会话将无法恢复;宿主0.1.2-rc.1保留信封字段但仅用于存量日志读取兼容、Session.append仍无法盖章,且读取路径对未标记未知事件类型 fail-closed(defend/detection未注册),写入同样会让会话无法加载。因此 dsh-defend 在第一次追加前即判定(peer 版本预判;版本不可解析时同样 fail closed)并以一次性告警停用会话日志审计;0.2.x预发布线正因如此被提前归入未标记,稳定的0.2.x仍回落到追加探测。设detection.allowUnmarkedAudit: true可重新开启。见 issue #2。
开发
pnpm install # node ^22.19 || >=24
pnpm run typecheck # tsc:src + tests,对照本地 harness checkout
pnpm run typecheck:ci # tsc:对照已发布的 0.1.7-rc.2 类型(无 paths)
pnpm test # vitest:97 个测试、9 个套件(含检测基准)
pnpm run build # tsdown bundle + tsc 声明(lib/)
pnpm run verify:self-contained # 依赖声明全部来自 registry
pnpm run verify:artifacts # 构建产物 ESM 面 + 发布文件齐全
pnpm pack # 发布用 tarball
Benchmark
红队基准(105 个样本的逐类 P/R/F1 + 27/28 fixture 下限)见 benchmark/RESULTS.md;用 node --experimental-strip-types benchmark/run.mjs 复现(零新依赖、无需构建)。
与其他 DSH 插件的互操作
已对照 DSH 0.2.0-rc.2(本 README 面向的运行时)与 2026-10-05 实测的高星插件集验证。
本插件不干扰其他插件,包括广泛安装的高星插件:
- 无工具名冲突。 所有工具都带命名空间,不占用任何已被内置工具或其他插件持有的裸名。
- 无服务键冲突。 不提供任何服务键,因此不存在服务键冲突。
- 无 slot 冲突。 不注册客户端 slot key,因此不参与
shadows-shipped-ui座位争抢。 - 无 HTTP 路由冲突。 不注册任何
webServer前缀。 - 无 patch 层冲突。 组合包 patch 只
insert自己那一行,从不覆写内置行的config。 - 无全局改写。 不改原型、不改写
process.env、不替换全局 fetch dispatcher。
共享事件监听器在构造上就不互相干扰。 它用 ctx.on() 监听顺序敏感事件 agent/pre-step, tools/post-execute, tools/pre-execute —— Cordis 的广播语义:每个监听器都会运行,任何一个都无法饿死其他监听器。此处每个监听器都通过 next() 委托,因此链条绝不会被短路;改写作用在 next() 产出的值上,而不是用它顶替返回:
agent/pre-step— also used bydsh-routing-suite(7000★, 7 listeners),modlens(4122★),dsh-purge(3317★),dsh-agent-teams(1923★),dsh-context(1849★).tools/post-execute— also used bycc-safety-net(1576★).tools/pre-execute— also used bycc-safety-net(1576★).
静态证据:dsh-plugin-doctor 的 K10–K13 在本仓全部为 pass。
Topics
dsh, dsh-plugin, deepseek-harness, deepseek, cordis, security, prompt-injection, jailbreak, secret-scanning, ai-safety
Contributors
- @PerryLink —— 创建者与维护者:危险删除门禁、四资产检测移植、拦截接线、审计面与五语文档。
- @cuohua —— 关于
defend/detection事件未标记落盘导致会话在更严格构建上无法恢复的精准报告(#2);运行时的宿主能力检测与ignorable标记纪律直接源自该分析。
PerryLink DSH Plugin Family
This project is one of the 44 DeepSeek Harness plugins maintained by PerryLink. If this one helps you, the others likely will too:
| Plugin | One-liner |
|---|---|
| dsh-auto-review | Second-model auto-review on the approval chain, fail-closed by default |
| dsh-autotier | Automatic strong/cheap model-tier routing with deterministic risk guards and a /tier command |
| dsh-background-agents | Durable background child agents with a Web UI sidebar, messaging and interrupt |
| dsh-budget | Cost governance for DeepSeek Harness: budgets, carbon, and latency in one panel. |
| dsh-catalog | DSH Desktop Market standard catalog source for the PerryLink family |
| dsh-cert-mcp | Read-only MCP server exposing the certification registry: grades, snapshots and five-dimension evidence |
| dsh-checkpoint-rewind | Claude Code /rewind-equivalent: snapshots, session forks, one-shot restore |
| dsh-claude-move | Migrate Claude Code sessions, memory, skills and CLAUDE.md into DSH |
| dsh-click | Cross-platform native desktop control for DeepSeek Harness — Windows first. |
| dsh-composer-history | Terminal-style input history for the web composer: arrows, Ctrl+R search |
| dsh-data-quality | Dataset quality checks and citation cross-checks (the optional numeric bridge consumed here) |
| dsh-defend | Prompt-injection, jailbreak, and secret-leak defense for DeepSeek Harness. |
| dsh-doublecheck | Engineering-discipline guard: requirements grill, test gates, adversary review |
| dsh-draw | Unified static-image generation routing for DeepSeek Harness. |
| dsh-fast | Read-only performance diagnostics for DeepSeek Harness. |
| dsh-fund-research | Deterministic research reports for Chinese public mutual funds |
| dsh-github | GitHub PR/issues integration for DSH, every write gated by approval |
| dsh-industry-research | Industry research orchestration that seals its deliverables through this plugin's ctx.researchReport.assemble |
| dsh-laya | Laya typed decisions (noul/choice/score) as a first-class Cordis service and model-visible tools |
| dsh-library | Local document knowledge base for DeepSeek Harness. |
| dsh-local-ai | Local-model (Ollama) integration for DeepSeek Harness. |
| dsh-lsp-actions | LSP diagnostics, formatting, completion, code actions and rename over language servers |
| dsh-mask | PII masking middleware: anonymize at the model boundary, restore at the display layer |
| dsh-mcp-panel | Read-only MCP runtime panel: /mcp command + Settings tab with status, tools and errors |
| dsh-memento | Approval-gated cross-session memory: ctx.memory seam + SQLite + memory tool |
| dsh-observe | OpenTelemetry and Langfuse observability exporter for DeepSeek Harness. |
| dsh-output-styles | Claude Code outputStyles-equivalent runtime style switching |
| dsh-permission-rules | Claude Code-style declarative allow/deny/ask permission rules with audit |
| dsh-plugin-certification | Community certification registry with repro-checkable grades and badges |
| dsh-plugin-doctor | Zero-dependency static + sandbox smoke detector for DSH plugins |
| dsh-plugin-guide | Plugin-development knowledge base as an on-demand agent skill |
| dsh-plugin-kit | Shared zero-runtime-dependency toolkit for the PerryLink DSH plugins |
| dsh-plugin-upgrade | One-package, one-corridor-index plugin upgrade skill: routes a repository to the matching closed corridor card |
| dsh-reach | Multi-channel approval/question bridge: WeChat/Telegram/Feishu, session console |
| dsh-research-report | Verifiable research-report engine: content-addressed evidence ledger and sealed versions |
| dsh-score | Multi-dimensional quality scoring for DeepSeek Harness plugins. |
| dsh-session-pin | Pin sessions in the Web sidebar with durable ordering |
| dsh-session-sync | Cross-device session sync for DeepSeek Harness — a dedicated git mirror of your session store. |
| dsh-skill-pack-security | Security-audit skill pack: secret scan, dependency and supply-chain review |
| dsh-talk | Voice-first session loop for DeepSeek Harness: talk to it, hear it answer. |
| dsh-team-rooms | Cross-session team rooms: shared message bus, task board and timeline |
| dsh-test-drive | Isolated install-and-smoke test drives for DeepSeek Harness plugins. |
| dsh-ticktick | TickTick/Dida365 task bridge: session-header panel + 11 tools |
| dsh-translate | Vendor parameter translation and deterministic JSON repair for DeepSeek Harness. |
License
Apache License 2.0 © 2026 dsh-defend contributors
从 DSH Desktop 市场安装
所有 PerryLink 插件均可在 DSH Desktop 内置市场中浏览:市场 → 来源 → 添加来源 → 粘贴 https://perrylink-dsh-catalog.perrylink.workers.dev/catalog-source.json → 选中。安装仍需通过市场的 npm 身份校验与你的确认。
链接
同类插件
toby-bridges/api-relay-audit★ 868
从 DeepSeek Harness 对 AI API 中转站和 LLM 代理运行本地安全审计,生成 Markdown 报告,覆盖提示词注入、模型替换信号、工具调用改写、错误泄漏、流完整性和按 profile 启用的 Web3 风险。
SeaOf0/dsh-redteam-model★ 666
面向授权安全研究的 DSH 合集:九个工作模式(redteam 总控、渗透测试、代码审计、二进制分析、攻防评估、免杀对抗、应急溯源、云安全攻防、CTF 解题)与十五个运行时插件,设置页管理台支持一键部署、安装、更新与卸载。
howmp/dsh-pentest★ 595
面向 DeepSeek Harness 的授权渗透模式:以探索链路记录目标、线索、资产与漏洞,并在 Web 中可视化展示。
PerryLink/dsh-auto-review★ 233
审批链上的第二模型自动审查:只读审查子代理返回带理由的 allow/deny 结构化裁决,默认 fail-closed。
NanmiCoder/dsh-auto-mode★ 164
在 Workspace Write 与 Full access 之间增加 Auto 权限档:日常操作留在官方 workspace-write 沙箱内,由当前会话模型复核升权与破坏性调用,精确的越界访问按次放行一次,意图不明时询问,命中关键路径则拒绝。
PerryLink/dsh-permission-rules★ 119
Claude Code 风格的声明式权限规则:按序 allow/deny/ask 的 YAML 规则,在 tools/pre-execute 瀑布上匹配工具名、参数、工作区路径与 agent 身份,带完整会话日志审计、干跑模式与热重载。
社区评论
评论公开保存在 GitHub Discussions。加载评论会连接 GitHub 和 Giscus;发表内容需要 GitHub 账号。