JohnXu22786/secret-guard
Blocks agents from reading or writing sensitive files (.env, credentials, key material), masks leaked secret-shaped values in tool results, keeps an audit journal, and exposes safe sg_* inspection tools that never print raw values.
secret-guard blocks secrets from leaking into the conversation context: it intercepts reads and writes of sensitive files (.env, credentials, key material) by the agent's file tools before they execute, and applies a content-masking fallback on tool results so content that slips past interception still gets scrubbed. Companion sg_* safety-inspection tools return only key names, line numbers, shapes, booleans and HMAC fingerprints — never raw values. An audit journal is append-only JSONL rotated by size, rule files hot-reload (automatic polling + manual sg_reload), and the default rule table is policy-driven with path normalization and glob compilation.
Install
dsh plugin --profile demo add github:JohnXu22786/secret-guardREADME EN body verified 2026-09-02 (repo JohnXu22786/secret-guard; zh edition link present). Install per README: dsh plugin --profile demo add github:JohnXu22786/secret-guard (docs use a demo profile — install into the profile you want guarded); checkout installs dsh plugin --profile web add . / headless are also documented. Remove: dsh plugin --profile demo remove dsh-secret-guard. Zero build — loads as pure TypeScript source (Node native type-stripping; must not use strip-unsupported syntax — the repo ships an npm run smoke:strip check); runtime deps only @deepseek-ai/dsh-tools and schemastery.
Compatibility
DSH profiles with file tools; intercepts via tools/pre-execute and tools/post-execute waterfall events; zero-build pure-TS source.
Details
- Repo: JohnXu22786/secret-guard
- Category: Tools & Capabilities
- Stars: 1
- Version: git github:JohnXu22786/secret-guard
- Last push: 2026-08-17
- First seen: 2026-08-16
Recent updates
pre-execute interception of sensitive-file reads/writes; post-execute content-masking fallback; sg_* inspection tools (never raw values); JSONL audit journal + hot-reload rules; zero-build TS.
FAQ
- When does interception happen?
- At the tools/pre-execute waterfall event — before the tool body runs — so sensitive-file access is short-circuited before any content reaches the model.
- Can inspection tools read my secrets?
- No — sg_* tools return only key names, line numbers, shapes, booleans and HMAC fingerprints; raw values never leave the guard.
- What about content that slips through?
- A tools/post-execute fallback masks recognized secret-shaped content in tool results even after the fact.
Alternatives
ChenLaoshiYF/dsh-mcpguard · Starfie1d1272/dsh-builtin-toggles