tancheng33/dsh-egress-guard

Runtime security gate on the tool pipeline: denies calls naming hosts outside an egress allowlist, redacts credentials from results at the canonical value rather than only the rendered content, and appends every decision to a JSONL audit log; ships in monitor-only mode.

Tools & Capabilities ★ 0 updated —
View on GitHub ↗

Install

dsh plugin --profile web add github:tancheng33/dsh-egress-guard

Details