tancheng33/dsh-egress-guard

Runtime security gate on the tool pipeline: denies calls naming hosts outside an egress allowlist, redacts credentials from results at the canonical value rather than only the rendered content, and appends every decision to a JSONL audit log; ships in monitor-only mode.

A runtime security gate for DeepSeek Harness tool calls, sitting in the tool-execution pipeline rather than scanning config files before a run. Three listeners on documented extension points, disposed cleanly on unload: an egress allowlist on tools/pre-execute that denies (or asks about) a call naming a network destination outside your allowlist — curl to a paste site, git push to an unknown remote, a fetch to an exfiltration endpoint; secret redaction on tools/post-execute that rewrites credentials out of a tool result before the model, the durable session log or a Code Mode program can read them; and an audit log across both waterfalls that appends every decision, including ones monitor mode only would have made, to a JSONL file. The README is candid that redaction is pattern-based and can miss unknown credential shapes or rewrite text that merely looks like a secret.

Tools & Capabilities ★ 0 updated 2026-08-15
View on GitHub ↗

Install

dsh plugin --profile <name> add dsh-egress-guard

README Install section quoted verbatim (replace <name>); the README's local-checkout alternative is dsh plugin --profile <name> add /path/to/dsh-egress-guard. Registry-verified live 2026-09-15: dsh-egress-guard latest 0.1.0 (published 2026-08-15); the registry entry carries no repository field, so npm ownership is disclosed but not asserted.

Compatibility

The bundle ships in mode: monitor, so installing it cannot break a working setup — every rule is evaluated and audited but nothing is blocked or rewritten until you turn enforcement on. The README also notes that npm's latest tag for the @deepseek-ai/* packages still points at an old 0.0.1-rc.1 line while current releases are on the next tag.

Details

Recent updates

The README documents the three rules and their extension points rather than a release-by-release changelog; the latest version on the registry when checked on 2026-09-15 was 0.1.0.

FAQ

How do I install it?
The README's command is dsh plugin --profile <name> add dsh-egress-guard; a local-checkout path form is also documented.
Will installing it break my setup?
No — the README says the bundle ships in mode: monitor, so every rule is evaluated and audited but nothing is blocked or rewritten until you enable enforcement.
What are its limits?
The README states redaction is pattern-based, so it misses credential shapes it does not know and can rewrite text that merely looks like a secret; you can add extraPatterns and check the audit log.

Alternatives

1624318455/dsh-plugin-tavily · 6Mikao9/dsh-wsl-workspace · 863683348/dsh-plugin-finance-data

More plugins in Tools & Capabilities

Browse more in Tools & Capabilities

Guides for Tools & Capabilities plugins