ylwl1997/noatmark-dsh-plugin
NoAtMark text hygiene as a DeepSeek Harness (dsh) plugin — sanitize untrusted text, scan invisible characters,
Brings NoAtMark text hygiene to a dsh agent as four tools backed by the same deterministic engines behind noatmark.com: sanitize_text strips invisible/zero-width characters and flags prompt-injection and hidden-text signals; scan_text reports invisible characters with code points and positions plus injection patterns and hidden text; clean_format cleans LLM formatting artifacts (blank lines, stray fences, trailing spaces) without touching meaning; and sanitize_csv escapes CSV formula injection per OWASP by quoting = + - @ prefixes. The README states all processing is deterministic and local, so no data leaves the machine.
Install
npx @deepseek-ai/dsh web --patch ./cordis.ymlREADME Install section quoted verbatim: the plugin is added through a cordis.yml patch that inserts an id: noatmark / name: noatmark-dsh-plugin row (or points at the source path directly), and the README then starts dsh with npx @deepseek-ai/dsh web --patch ./cordis.yml. Registry check 2026-09-16: noatmark-dsh-plugin resolves at 0.1.0 but its registry entry carries no repository field, so npm ownership is disclosed, not asserted.
Compatibility
README: a DeepSeek Harness (dsh) plugin adding four tools to the agent; the install path shown is a cordis.yml patch, with a source-path variant for a local checkout. All processing is described as deterministic and local.
Details
- Repo: ylwl1997/noatmark-dsh-plugin
- Category: Files & Data
- Stars: 1
- Version: npm noatmark-dsh-plugin 0.1.0 resolves (registry-verified 2026-09-16; repository field absent)
- Last push: 2026-08-17
- First seen: 2026-08-14
Recent updates
The README documents the four tools and the local-only processing guarantee rather than a release-by-release table; the latest version on the registry when checked on 2026-09-16 was 0.1.0.
FAQ
- How do I install it?
- The README adds a cordis.yml patch inserting an id: noatmark / name: noatmark-dsh-plugin row and starts dsh with npx @deepseek-ai/dsh web --patch ./cordis.yml (or points at the source path directly).
- What does it protect against?
- Per the README: invisible/zero-width characters, hidden text and prompt-injection signals, plus CSV formula injection (OWASP) via sanitize_csv.
- Does any text leave my machine?
- No — the README states all processing is deterministic and local.