perrylink/dsh-mask

PII desensitization middleware: replace name/phone/email/ID card/bank card/key/address with placeholders before the model boundary, restore the display layer, and never enter the plain text into the session log; /mask command + mask_test tool; npm dsh-mask 0.1.4 has been released

dsh-mask is PII masking middleware for DeepSeek Harness: phones, emails, ID cards, bank cards, keys and addresses become placeholders at the model boundary — before a message reaches the model — while a restore table maps placeholders back to the originals at the display layer, so plaintext never enters the session log. It is a pure host-side implementation with zero runtime dependencies, requires no extra model capability, and ships a 1024-store channel note (dsh1024 install ranking) alongside the standard dsh plugin installs.

Coding & Development ★ 5 updated 2026-09-03 — untested
View on GitHub ↗

Install

dsh plugin --profile web add "github:PerryLink/dsh-mask#main"

GitHub install per README (EN primary, editions in 简体中文/Español/Português/हिन्दी); npm dsh-mask 0.2.2 verified 2026-09-03 with repository field → github.com/PerryLink/dsh-mask. Install: dsh plugin --profile web add "github:PerryLink/dsh-mask#main" or dsh plugin --profile web add dsh-mask (npm).

Compatibility

DeepSeek Harness 0.1.2-alpha.5 (adapted 2026-09-02 per README); Node ^22.19.0 || >=24; pure host, zero-dependency regex, no browser half; text models only.

Details

Recent updates

0.2.2 current on npm; README compatibility table dated 2026-09-02 for harness 0.1.2-alpha.5.

FAQ

When does masking happen?
At the model boundary: personal data is replaced with placeholders before a message reaches the model, and restored only at the display layer — the plaintext never enters the session log.
Which data types are masked?
Phones, emails, ID-card numbers, bank cards, keys and addresses, via pure host-side regex patterns — no extra model capability or browser half required.
Can the model still use the data?
The model sees placeholders; a restore table maps them back to originals for display, so masking does not break the visible conversation.

Alternatives

JohnXu22786/secret-guard · ChenLaoshiYF/dsh-mcpguard

More plugins in Coding & Development

Browse more in Coding & Development

Guides for Coding & Development plugins