ylwl1997/noatmark-dsh-plugin

NoAtMark text hygiene as a DeepSeek Harness (dsh) plugin — sanitize untrusted text, scan invisible characters,

Brings NoAtMark text hygiene to a dsh agent as four tools backed by the same deterministic engines behind noatmark.com: sanitize_text strips invisible/zero-width characters and flags prompt-injection and hidden-text signals; scan_text reports invisible characters with code points and positions plus injection patterns and hidden text; clean_format cleans LLM formatting artifacts (blank lines, stray fences, trailing spaces) without touching meaning; and sanitize_csv escapes CSV formula injection per OWASP by quoting = + - @ prefixes. The README states all processing is deterministic and local, so no data leaves the machine.

Files & Data ★ 1 updated 2026-08-17 ✅ runtime-tested
View on GitHub ↗

Install

npx @deepseek-ai/dsh web --patch ./cordis.yml

README Install section quoted verbatim: the plugin is added through a cordis.yml patch that inserts an id: noatmark / name: noatmark-dsh-plugin row (or points at the source path directly), and the README then starts dsh with npx @deepseek-ai/dsh web --patch ./cordis.yml. Registry check 2026-09-16: noatmark-dsh-plugin resolves at 0.1.0 but its registry entry carries no repository field, so npm ownership is disclosed, not asserted.

Compatibility

README: a DeepSeek Harness (dsh) plugin adding four tools to the agent; the install path shown is a cordis.yml patch, with a source-path variant for a local checkout. All processing is described as deterministic and local.

Details

Recent updates

The README documents the four tools and the local-only processing guarantee rather than a release-by-release table; the latest version on the registry when checked on 2026-09-16 was 0.1.0.

FAQ

How do I install it?
The README adds a cordis.yml patch inserting an id: noatmark / name: noatmark-dsh-plugin row and starts dsh with npx @deepseek-ai/dsh web --patch ./cordis.yml (or points at the source path directly).
What does it protect against?
Per the README: invisible/zero-width characters, hidden text and prompt-injection signals, plus CSV formula injection (OWASP) via sanitize_csv.
Does any text leave my machine?
No — the README states all processing is deterministic and local.

More plugins in Files & Data

Browse more in Files & Data

Guides for Files & Data plugins