ChenLaoshiYF/dsh-mcpguard
?? for DeepSeek Harness: first security plugin for dsh
dsh-mcpguard (明棱) — described as the first security plugin for DeepSeek Harness. Scans skills and MCP configs for prompt injection, homoglyph smuggling, invisible Unicode, dangerous shell patterns, and leaked credentials. Tools: mcpguard_scan (MCP configs + skill directories), mcpguard_scan_path (any path), mcpguard_observe (v0.2 experimental — runtime observation summary over the tools/pre-execute seam, watch only, never blocks). Scan tools return a JSON report: per-file score, findings with rule IDs, severity, and offending excerpts — redacted so API keys and tokens never leak into the report. By design observation never denies, delays, or rewrites a tool call.
Install
dsh plugin --profile web add "github:ChenLaoshiYF/dsh-mcpguard"GitHub install per README (English): dsh plugin --profile web add "github:ChenLaoshiYF/dsh-mcpguard", then restart dsh --profile web. Or install from Settings → Plugins. Ships as a normal DSH plugin — two tools, no daemon, no cloud.
Compatibility
DeepSeek Harness web profile.
Details
- Repo: ChenLaoshiYF/dsh-mcpguard
- Category: Infrastructure & Deployment
- Stars: 2
- Version: GitHub source (v0.2 experimental runtime observation; no npm package)
- Last push: 2026-08-30
- First seen: 2026-08-14
Recent updates
prompt-injection / homoglyph / invisible-Unicode / shell / credential scanning; 2 scan tools + experimental observe tool; redacted JSON reports; watch-only runtime mode.
FAQ
- What does it scan for?
- Prompt injection, homoglyph smuggling, invisible Unicode, dangerous shell patterns, and leaked credentials in skills and MCP configs.
- Does it block anything?
- No — scans report; the experimental observe mode is watch-only and never denies, delays, or rewrites a tool call.
- Are secrets exposed in reports?
- No — offending excerpts are redacted so API keys and tokens never leak into the report itself.
Alternatives
PerryLink/dsh-doublecheck · jinguanghai/deepseek-harness-forge-plugins · 030611/dsh-telemetry-redactor