DeepSeek Harness 插件

PerryLink/dsh-defend

Star 数 ★ 23 下载量(近 30 天) 4,270 分类 安全与权限 收录于 2026-08-23 npm dsh-defend

在 agent/pre-step、tools/pre-execute、tools/post-execute 三个接缝检测提示词注入、越狱与密钥泄露,按 allow/ask/block 分层拦截,附脱敏 defend/detection 审计事件、defend_report 工具与危险删除命令门禁。

安装

# npm 包(预构建)

dsh plugin --profile web add dsh-defend

# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)

dsh plugin --profile web add github:PerryLink/dsh-defend

装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本——pnpm 默认拦截,所以安装可能停在 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED 或 ERR_PNPM_IGNORED_BUILDS;dsh 会打印出需要添加的确切键名,把它加进该 profile 的 pnpm-workspace.yaml 的 allowBuilds 下,重跑一次即可装上。放行构建本身就是一次信任判断:请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。

README

🛡️ dsh-defend

  • 1024 商店渠道:先 npm i -g dsh1024,再 dsh1024 plugin --profile web add dsh-defend(计入 deepseek1024.com 安装排行)。

DeepSeek Harness 的提示注入、越狱与密钥泄露防护。

规则裁决已知的,拦截裁决其余的——一切都有审计。

dsh-doctor DSH Market

English · 简体中文 · Español · Português · हिन्दी


📖 生态实测知识库(实测数据,不是营销):插件开发指南 · 选型实测数据 · 维护取舍判据。

维护状态:🧊 已冻结

2026-10-05 起冻结,不再新增功能。 本包仍可正常使用,没有退役——但不再投入功能开发,只有真实故障才会修复。

维护者判定该能力面已出现采用度更高、更值得推荐的替代方案,因此把精力移到了别处。

包 周下载量
本包 dsh-defend 937
更值得推荐的替代品 cc-safety-net 13,087

为什么替代品更强。 cc-safety-net 作为编程 Agent 的 CLI hook,拦截破坏性命令与密钥文件访问。

本包仍然独有的能力。 从 prompt-injection / jailbreak / secret-leaker 三个上游资产集移植的 Aho-Corasick 模式引擎;对用户消息、工具参数、工具结果三处做 allow/ask/block 三档拦截;以及经脱敏的 defend/* 会话审计事件。上面的替代品范围更窄(只管破坏性命令与密钥文件),但采用度高出一个数量级。

👉 新工作请优先使用 cc-safety-net(若你只需要破坏性命令闸门);若你要的是更宽的检测面,本包仍是更广的那个,但已冻结不再加功能。 已安装的照常可用,没有任何东西被移除。

完整证据(含宿主版本兼容矩阵)见 dsh-plugin-supersession-review-20261005.md;英文版见 README.md 的 Maintenance status: 🧊 FROZEN 一节。

⭐ 如果它帮到了你

这个插件是 DSH 插件家族的一员(40+ 个,全部 Apache-2.0)。如果你在用,给个 star —— 它不会解锁任何功能,但会让下一个人在搜索里更容易找到它。

English: part of a 40+ plugin family for DeepSeek Harness. If it is useful, a star helps the next person find it — nothing is gated behind it.

兼容性

方面 状态
Harness DeepSeek Harness dsh-v0.2.1-alpha.1(2026-09-24 核验;peer 范围 >=0.1.2-rc.1 <0.2.0 || >=0.1.5-alpha.1 <0.2.0 || >=0.1.6-0 <0.2.0 || >=0.1.7-0 <0.2.0)。该线上 Session.append 的第三参仅对表面事件类型存在且为 SurfaceIntent,因此非表面的 defend/detection 仍无法盖章 ignorable:会话日志审计保持失败关闭式停用,/defend 显式渲染该状态。会话格式 V4 已无 tool-result 内容块——本插件从不生产它,两个内容 walker 只为退役的 V3 包裹块保留只读回退,使升级前写下的会话仍可被扫描。已于 2026-09-24 核验(双 typecheck 尺子 + 全量测试 + build + self-contained/artifacts 门 + pack;宿主类型图仅一份)。
Node ^22.19.0 || >=24.0.0
平台 全部(纯 host;无原生代码、无网络)
模型 任意(检测发生在内容到达模型之前)

你能得到什么

dsh-defend 在 agent 面前放了两层相互独立的防线:

  1. 危险删除门禁 —— 8·14/8·16 事故教训的可执行形态。在 tools/pre-execute 上,递归删除类 shell 命令被拒绝,除非每个目标都是会话工作区内的显式绝对路径且不触碰受保护前缀(家目录配置、.dsh/.claude、系统目录)。dry-run 标记(-WhatIf、--dry-run、git clean -n)放行——它们正是教训要求的删除前核对。
  2. 检测层 —— 移植自四个上游资产(均为 Apache-2.0,见 THIRD_PARTY_NOTICES.md):25 条 Prompt-Injection-Payloads 规则、25 条 Jailbreak-Detector 模式(纯 TypeScript Aho-Corasick 自动机)、来自 Secret-Key-Leaker-Detect 与各签发方公开文档的 12 条密钥语法、以及原样保留为回归基准的 Prompt-Attack-Dataset。

三个拦截点,同一套决策模型:

拦截点 扫描内容 决策
agent/pre-step 进入模型的消息 allow → next();ask → 审批;block → 拒绝本步
tools/pre-execute 工具参数 allow → next();ask → 审批;block → deny
tools/post-execute 工具结果 allow → next();ask → 审批;block → 纠正性反馈

默认:每个 family 均为 ask,critical 级密钥一律 block(上游「见即中断」语义)。没有审批应答者即失败关闭。每次放行都调用 next()——下游策略插件永不被短路。

入站消息 ── agent/pre-step ── 扫描 ── 干净 → next()/enter
工具参数 ── tools/pre-execute ── 扫描 ── 放行 → next()
工具结果 ── tools/post-execute ── 扫描 ── 拦截 → 反馈
                              │
                              └─ defend/detection 审计(规则 id/类别/
                                 严重度/决策——从不含匹配文本)

快速开始

# 1. 把 bundle 装进你的 profile
dsh plugin --profile web add "github:PerryLink/dsh-defend#main"

# 或从 npm 安装(正式发布版)
dsh plugin --profile web add dsh-defend

# 2. 重启并核实行
dsh --profile web --dump-config | grep -A3 'id: dsh-defend'

安装与卸载

  • git 通道(最新 main):dsh plugin --profile web add "github:PerryLink/dsh-defend#main" —— prepare 脚本仅用生产依赖构建。
  • npm 通道(正式发布版):dsh plugin --profile web add dsh-defend。
  • tarball 通道:在本仓库执行 pnpm pack,然后 dsh plugin --profile web add ./dsh-defend-<version>.tgz。
  • 卸载:dsh plugin --profile web remove dsh-defend(或从 profile patch 中删除该行)。

配置

所有可调项都是 Schemastery Config 字段(可在 cordis.yml 中修改)。按 id 定向覆盖会替换整行——需要重新声明每个键。cordis.patch.yml 内联说明了每个键。

键 默认值 含义
enabled true 两层防线总开关
action deny 危险删除门禁动作(deny / ask)
toolNames ['bash','persistent-bash','terminal-bash'] 门禁评审命令参数的工具注册名
detection.enabled true 检测层开关
detection.maxScanChars 10000 每次拦截的扫描字符上限(只扫头部)
detection.normalizeUnicode true 扫描前 NFKC/Unicode 归一化(堵 lookalike-Unicode 绕过)
detection.secretMinEntropy 3.0 密钥命中后的最小 Shannon 熵(bits/字符),低于阈值视为误报丢弃;0 关闭
detection.injectionAction ask 注入类:allow / ask / block
detection.jailbreakAction ask 越狱类:allow / ask / block
detection.secretAction ask 密钥类:allow / ask / block
detection.secretBlockCritical true critical 密钥无视 secretAction 一律 block
detection.audit true 写 defend/detection 会话审计事件
detection.allowUnmarkedAudit false 宿主不识别 ignorable 标记(截至目前所有已发布线,含 0.2.x 预发布线)或对未知事件类型 fail-closed(宿主 0.1.2-rc.1 及以后)时是否仍写会话日志审计(接受会话无法恢复的风险)
detection.maxReportEntries 200 内存环形缓冲条数上限
registerCommand true 注册 /defend 命令
registerTool true 注册 defend_report 工具

工具与界面

界面 类型 说明
defend_report 工具 汇总(记录/拦截/询问数)、按 family 计数、最近 20 条——从不含匹配文本
/defend 命令 同样的汇总文本
agent/pre-step 监听 入站消息扫描(enter/reject)
tools/pre-execute 监听 工具参数扫描(deny/ask)+ 危险删除门禁
tools/post-execute 监听 工具结果扫描(block 反馈)

权限与数据

  • 权限:ask 决策走官方审批接缝;绝不重实现或绕过。workshop manifest 声明 session:append 与 network:none。
  • 数据:不落盘任何东西;报告环形缓冲仅在内存且有界。无网络请求、无子进程。
  • 会话日志:defend/detection 事件只带规则 id、family、类别、严重度、密钥类型、决策与扫描事实——匹配文本从不入日志,密钥匹配在构造上只留类型。

安全边界

  • 检测,而非执法。 门禁与检测层只在官方 seam 上产出 deny/ask/block 决策;沙箱与审批系统仍是执行权威。
  • 失败关闭。 审批应答者缺失、会话缺失或服务面缺失时,一律退化为最严格决策——绝不静默放行。
  • 内容不出进程。 扫描在本地完成;审计事件已脱敏;密钥绝不入日志、展示或报告。
  • 有界工作。 扫描上限、每规则至多一条匹配、环形缓冲上限,恶意输入无法消耗无界资源。

已知限制

  • 检测缺口。 规则库覆盖已移植词汇及其容错变体;新式措辞、形近 Unicode 编码(NFKC 归一化列为后续工作)与多步攻击可能绕过。基准把实测下限(上游数据集 27/28)钉进测试,回归可见。
  • 无模型级判定。 dsh-defend 是确定性的,绝不调用模型,无法判断全新意图。
  • 消息拒绝是静默的。 agent/pre-step 的 reject 不给模型理由(seam 没有理由字段);审计事件记录规则事实。
  • 会话审计与 ignorable 标记。 审计追加请求 envelope 的 ignorable: true 标记,任何 harness 构建都能加载日志。截至目前所有已发布线(0.1.0-rc.1–0.1.0-rc.8、0.1.1-rc.1–0.1.1-rc.2,以及 0.2 走廊——2026-10-04 对已发布 0.2.1-alpha.1 复核:其 append(type, data, ...opts) 只从 options 取 sourceEventSeqs/surfaceOp,信封固定为 { type, seq, time, data })都会静默丢弃它——事件未标记落盘,更严格构建上会话将无法恢复;宿主 0.1.2-rc.1 保留信封字段但仅用于存量日志读取兼容、Session.append 仍无法盖章,且读取路径对未标记未知事件类型 fail-closed(defend/detection 未注册),写入同样会让会话无法加载。因此 dsh-defend 在第一次追加前即判定(peer 版本预判;版本不可解析时同样 fail closed)并以一次性告警停用会话日志审计;0.2.x 预发布线正因如此被提前归入未标记,稳定的 0.2.x 仍回落到追加探测。设 detection.allowUnmarkedAudit: true 可重新开启。见 issue #2。

开发

pnpm install        # node ^22.19 || >=24
pnpm run typecheck  # tsc:src + tests,对照本地 harness checkout
pnpm run typecheck:ci  # tsc:对照已发布的 0.1.7-rc.2 类型(无 paths)
pnpm test           # vitest:97 个测试、9 个套件(含检测基准)
pnpm run build      # tsdown bundle + tsc 声明(lib/)
pnpm run verify:self-contained  # 依赖声明全部来自 registry
pnpm run verify:artifacts       # 构建产物 ESM 面 + 发布文件齐全
pnpm pack           # 发布用 tarball

Benchmark

红队基准(105 个样本的逐类 P/R/F1 + 27/28 fixture 下限)见 benchmark/RESULTS.md;用 node --experimental-strip-types benchmark/run.mjs 复现(零新依赖、无需构建)。

与其他 DSH 插件的互操作

已对照 DSH 0.2.0-rc.2(本 README 面向的运行时)与 2026-10-05 实测的高星插件集验证。

本插件不干扰其他插件,包括广泛安装的高星插件:

  • 无工具名冲突。 所有工具都带命名空间,不占用任何已被内置工具或其他插件持有的裸名。
  • 无服务键冲突。 不提供任何服务键,因此不存在服务键冲突。
  • 无 slot 冲突。 不注册客户端 slot key,因此不参与 shadows-shipped-ui 座位争抢。
  • 无 HTTP 路由冲突。 不注册任何 webServer 前缀。
  • 无 patch 层冲突。 组合包 patch 只 insert 自己那一行,从不覆写内置行的 config。
  • 无全局改写。 不改原型、不改写 process.env、不替换全局 fetch dispatcher。

共享事件监听器在构造上就不互相干扰。 它用 ctx.on() 监听顺序敏感事件 agent/pre-step, tools/post-execute, tools/pre-execute —— Cordis 的广播语义:每个监听器都会运行,任何一个都无法饿死其他监听器。此处每个监听器都通过 next() 委托,因此链条绝不会被短路;改写作用在 next() 产出的值上,而不是用它顶替返回:

  • agent/pre-step — also used by dsh-routing-suite (7000★, 7 listeners), modlens (4122★), dsh-purge (3317★), dsh-agent-teams (1923★), dsh-context (1849★).
  • tools/post-execute — also used by cc-safety-net (1576★).
  • tools/pre-execute — also used by cc-safety-net (1576★).

静态证据:dsh-plugin-doctor 的 K10–K13 在本仓全部为 pass。

Topics

dsh, dsh-plugin, deepseek-harness, deepseek, cordis, security, prompt-injection, jailbreak, secret-scanning, ai-safety

Contributors

  • @PerryLink —— 创建者与维护者:危险删除门禁、四资产检测移植、拦截接线、审计面与五语文档。
  • @cuohua —— 关于 defend/detection 事件未标记落盘导致会话在更严格构建上无法恢复的精准报告(#2);运行时的宿主能力检测与 ignorable 标记纪律直接源自该分析。

PerryLink DSH Plugin Family

This project is one of the 44 DeepSeek Harness plugins maintained by PerryLink. If this one helps you, the others likely will too:

Plugin One-liner
dsh-auto-review Second-model auto-review on the approval chain, fail-closed by default
dsh-autotier Automatic strong/cheap model-tier routing with deterministic risk guards and a /tier command
dsh-background-agents Durable background child agents with a Web UI sidebar, messaging and interrupt
dsh-budget Cost governance for DeepSeek Harness: budgets, carbon, and latency in one panel.
dsh-catalog DSH Desktop Market standard catalog source for the PerryLink family
dsh-cert-mcp Read-only MCP server exposing the certification registry: grades, snapshots and five-dimension evidence
dsh-checkpoint-rewind Claude Code /rewind-equivalent: snapshots, session forks, one-shot restore
dsh-claude-move Migrate Claude Code sessions, memory, skills and CLAUDE.md into DSH
dsh-click Cross-platform native desktop control for DeepSeek Harness — Windows first.
dsh-composer-history Terminal-style input history for the web composer: arrows, Ctrl+R search
dsh-data-quality Dataset quality checks and citation cross-checks (the optional numeric bridge consumed here)
dsh-defend Prompt-injection, jailbreak, and secret-leak defense for DeepSeek Harness.
dsh-doublecheck Engineering-discipline guard: requirements grill, test gates, adversary review
dsh-draw Unified static-image generation routing for DeepSeek Harness.
dsh-fast Read-only performance diagnostics for DeepSeek Harness.
dsh-fund-research Deterministic research reports for Chinese public mutual funds
dsh-github GitHub PR/issues integration for DSH, every write gated by approval
dsh-industry-research Industry research orchestration that seals its deliverables through this plugin's ctx.researchReport.assemble
dsh-laya Laya typed decisions (noul/choice/score) as a first-class Cordis service and model-visible tools
dsh-library Local document knowledge base for DeepSeek Harness.
dsh-local-ai Local-model (Ollama) integration for DeepSeek Harness.
dsh-lsp-actions LSP diagnostics, formatting, completion, code actions and rename over language servers
dsh-mask PII masking middleware: anonymize at the model boundary, restore at the display layer
dsh-mcp-panel Read-only MCP runtime panel: /mcp command + Settings tab with status, tools and errors
dsh-memento Approval-gated cross-session memory: ctx.memory seam + SQLite + memory tool
dsh-observe OpenTelemetry and Langfuse observability exporter for DeepSeek Harness.
dsh-output-styles Claude Code outputStyles-equivalent runtime style switching
dsh-permission-rules Claude Code-style declarative allow/deny/ask permission rules with audit
dsh-plugin-certification Community certification registry with repro-checkable grades and badges
dsh-plugin-doctor Zero-dependency static + sandbox smoke detector for DSH plugins
dsh-plugin-guide Plugin-development knowledge base as an on-demand agent skill
dsh-plugin-kit Shared zero-runtime-dependency toolkit for the PerryLink DSH plugins
dsh-plugin-upgrade One-package, one-corridor-index plugin upgrade skill: routes a repository to the matching closed corridor card
dsh-reach Multi-channel approval/question bridge: WeChat/Telegram/Feishu, session console
dsh-research-report Verifiable research-report engine: content-addressed evidence ledger and sealed versions
dsh-score Multi-dimensional quality scoring for DeepSeek Harness plugins.
dsh-session-pin Pin sessions in the Web sidebar with durable ordering
dsh-session-sync Cross-device session sync for DeepSeek Harness — a dedicated git mirror of your session store.
dsh-skill-pack-security Security-audit skill pack: secret scan, dependency and supply-chain review
dsh-talk Voice-first session loop for DeepSeek Harness: talk to it, hear it answer.
dsh-team-rooms Cross-session team rooms: shared message bus, task board and timeline
dsh-test-drive Isolated install-and-smoke test drives for DeepSeek Harness plugins.
dsh-ticktick TickTick/Dida365 task bridge: session-header panel + 11 tools
dsh-translate Vendor parameter translation and deterministic JSON repair for DeepSeek Harness.

License

Apache License 2.0 © 2026 dsh-defend contributors

从 DSH Desktop 市场安装

所有 PerryLink 插件均可在 DSH Desktop 内置市场中浏览:市场 → 来源 → 添加来源 → 粘贴 https://perrylink-dsh-catalog.perrylink.workers.dev/catalog-source.json → 选中。安装仍需通过市场的 npm 身份校验与你的确认。

内容来自项目 README(GitHub)↗

链接

同类插件

查看整个分类 →

评论公开保存在 GitHub Discussions。加载评论会连接 GitHub 和 Giscus;发表内容需要 GitHub 账号。