030611/dsh-telemetry-redactor
Fail-closed export-copy redaction for DeepSeek Harness session telemetry
Redacts supported credential patterns from outbound telemetry copies before configured backends receive them — without rewriting canonical session logs. Redacts values under high-risk key names (authorization, cookie, credential, password, secret, token, apiKey, access_token, clientSecret, privateKey), Bearer/Basic authorization values embedded in strings, and common credential forms (sk-..., GitHub/Slack tokens, JWT-like triples, token=/api_key: assignments). Keys are tokenized before matching so telemetry counters (inputTokens, tokenUsage…) and fields like tokenizer stay intact. The listener is prepended so it normally wraps deployment rules mounted before or after it. Fail-closed means the coordinator withholds one failing export copy and continues the agent loop.
Install
dsh plugin --profile web add dsh-telemetry-redactornpm package dsh-telemetry-redactor 0.1.0 (registry-verified 2026-08-26). dsh plugin --profile web add dsh-telemetry-redactor then dsh --profile web --dump-config — the dump must contain the inserted telemetry-redactor row. Minimal Profile Bundle; community-maintained (not official DeepSeek).
Compatibility
DeepSeek Harness profile bundle — mounts on the official session-telemetry/record waterfall and calls next() so other deployment rules still compose.
Details
- Repo: 030611/dsh-telemetry-redactor
- Category: Agent Capabilities
- Stars: 3
- Version: npm dsh-telemetry-redactor 0.1.0 (registry-verified 2026-08-26)
- Last push: 2026-08-14
- First seen: 2026-08-13
Recent updates
v0.1.0: credential-pattern redaction on outbound copies; tokenized key matching; prepended waterfall listener; canonical log untouched.
FAQ
- Does it edit the canonical session log?
- No — the official telemetry coordinator deep-copies events before the waterfall; this plugin redacts only the outbound copy.
- Will token counters be redacted?
- No — keys are tokenized before matching, so inputTokens/output_tokens/tokenUsage/tokenCount/contextTokenCount and fields like tokenizer remain intact.
- What does fail-closed mean here?
- The coordinator withholds one failing export copy and continues the agent loop — it is not a claim that every telemetry path or listener order is impossible to bypass.
Alternatives
030611/dsh-verification-receipt · omdsh-dev/dsh-security-audit · jkrandom-sudo/dsh-plugin-audit