lukethecat/dsh-plugin-warroom-garak
Adds one model-facing tool, garak_scan: an authorized garak baseline red-team sweep against a target LLM endpoint, with a built-in authorization gate (it refuses to run unless authorization.authorized === true with a non-empty scope), a budget cap on attempts per probe (maxGenerations), and an auto-written one-page Markdown evidence report containing the target, scope, tool and time, a per-probe hit-rate table, the overall hit rate and a pointer to the raw garak report. The run stays in the dsh session log (auditable / replayable) and the result returns a summary plus report path and metrics. It is positioned as the orchestrator in a "war-room" approach — garak owns the probes, this plugin runs them against an authorized target and produces a compliance-ready artefact.
Install
⚠️ Install command not yet confirmed — check the README on GitHub for the exact command.
Compatibility
v0 / developer preview. The README warns two seams are version-sensitive and may need a small fix on first build in your environment — the defineTool parameter/output schema DSL (src/index.ts) and the garak report JSONL field names / hit detection (src/garak.ts). It is modelled on the official dsh-tool-web plugin and pins dsh-* deps to your installed dsh version.
Details
- Repo: lukethecat/dsh-plugin-warroom-garak
- Category: Other
- Stars: 0
- Version: v0 developer preview, built against @deepseek-ai/dsh-* 0.1.0-rc.x; no npm release
- Last push: 2026-08-14
- First seen: 2026-08-14
Recent updates
The README documents the v0/developer-preview status and the two version-sensitive seams rather than a release-by-release changelog; there is no published release history. Verify the source against your DSH version before building.
FAQ
- How do I install dsh-plugin-warroom-garak?
- Build the checkout (npm install && npm run build) and add the documented - name: 'dsh-plugin-warroom-garak' entry with its config to your dsh profile / cordis composition, then restart dsh — the README publishes no one-line install and no npm release.
- What do I need first?
- A working DeepSeek Harness install and garak on PATH (pipx install garak or pip install garak, verified with garak --version).
- Will it scan any endpoint?
- No — the README says the tool refuses to run unless authorization.authorized === true with a non-empty scope, caps attempts with maxGenerations, and writes an evidence report of the authorized sweep.
Alternatives
Zenquiem/dsh-security-suite · bigclawd/dsh-security-guard · perrylink/dsh-defend