JohnXu22786/secret-guard

Blocks agents from reading or writing sensitive files (.env, credentials, key material), masks leaked secret-shaped values in tool results, keeps an audit journal, and exposes safe sg_* inspection tools that never print raw values.

secret-guard blocks secrets from leaking into the conversation context: it intercepts reads and writes of sensitive files (.env, credentials, key material) by the agent's file tools before they execute, and applies a content-masking fallback on tool results so content that slips past interception still gets scrubbed. Companion sg_* safety-inspection tools return only key names, line numbers, shapes, booleans and HMAC fingerprints — never raw values. An audit journal is append-only JSONL rotated by size, rule files hot-reload (automatic polling + manual sg_reload), and the default rule table is policy-driven with path normalization and glob compilation.

Tools & Capabilities ★ 1 updated 2026-08-17
View on GitHub ↗

Install

dsh plugin --profile demo add github:JohnXu22786/secret-guard

README EN body verified 2026-09-02 (repo JohnXu22786/secret-guard; zh edition link present). Install per README: dsh plugin --profile demo add github:JohnXu22786/secret-guard (docs use a demo profile — install into the profile you want guarded); checkout installs dsh plugin --profile web add . / headless are also documented. Remove: dsh plugin --profile demo remove dsh-secret-guard. Zero build — loads as pure TypeScript source (Node native type-stripping; must not use strip-unsupported syntax — the repo ships an npm run smoke:strip check); runtime deps only @deepseek-ai/dsh-tools and schemastery.

Compatibility

DSH profiles with file tools; intercepts via tools/pre-execute and tools/post-execute waterfall events; zero-build pure-TS source.

Details

Recent updates

pre-execute interception of sensitive-file reads/writes; post-execute content-masking fallback; sg_* inspection tools (never raw values); JSONL audit journal + hot-reload rules; zero-build TS.

FAQ

When does interception happen?
At the tools/pre-execute waterfall event — before the tool body runs — so sensitive-file access is short-circuited before any content reaches the model.
Can inspection tools read my secrets?
No — sg_* tools return only key names, line numbers, shapes, booleans and HMAC fingerprints; raw values never leave the guard.
What about content that slips through?
A tools/post-execute fallback masks recognized secret-shaped content in tool results even after the fact.

Alternatives

ChenLaoshiYF/dsh-mcpguard · Starfie1d1272/dsh-builtin-toggles

More plugins in Tools & Capabilities

Browse more in Tools & Capabilities

Guides for Tools & Capabilities plugins