perrylink/dsh-defend

Injection/jailbreak/key leakage detection + dangerous deletion access control: Aho-Corasick engine intercepts user messages, tool parameters, and tool results by allow/ask/block (desensitization defend/detection audit events, defend_report tool, /defend command), and rejects recursive deletion commands outside the workspace

Defence for DeepSeek Harness in two independent layers. The destructive-delete guard hooks tools/pre-execute and refuses recursively deleting shell commands unless every target is an explicit absolute path inside the session workspace — the executable form of the 8·14/8·16 postmortem lesson. On top of that it detects prompt injection, jailbreak attempts and secret leaks, applying rules for what is known and interception for everything else, with everything audited. Detection happens before content reaches the model, so a text-only or vision model is protected identically.

Messaging & Communication ★ 0 updated 2026-08-18 — untested
View on GitHub ↗

Install

dsh plugin --profile web add dsh-defend

README install: the npm channel (dsh plugin --profile web add dsh-defend). Two other channels are documented — git, which tracks the latest main (dsh plugin --profile web add "github:PerryLink/dsh-defend#main", where a prepare script builds with production dependencies only) and a tarball channel (pnpm pack, then dsh plugin --profile web add ./dsh-defend-<version>.tgz). Uninstall with dsh plugin --profile web remove dsh-defend.

Compatibility

Node ^22.19.0 || >=24.0.0, Apache-2.0. Verified against the DeepSeek Harness dsh-v0.1.5-rc.1 checkout on 2026-09-10 (full gate chain plus profile install smoke); peer ranges >=0.1.2-rc.1 <0.2.0 || >=0.1.5-alpha.1 <0.2.0. Pure host plugin — no native code, no network — and model-agnostic, because detection runs before content reaches the model.

Details

Recent updates

README documents the compatibility verification (dsh-v0.1.5-rc.1, adapted 2026-09-10, peer ranges bounded below 0.2.0) and the two-layer design stance: rules decide the known, interception decides the rest, and every action is audited.

FAQ

How do I install dsh-defend?
Run: dsh plugin --profile web add dsh-defend. The git channel is dsh plugin --profile web add "github:PerryLink/dsh-defend#main" and a tarball channel is documented for local packs.
What does the destructive-delete guard block?
On tools/pre-execute, recursively deleting shell commands are refused unless every target is an explicit absolute path inside the session workspace.
Which DSH versions are supported?
Verified against dsh-v0.1.5-rc.1 (2026-09-10); peer ranges are >=0.1.2-rc.1 <0.2.0 or >=0.1.5-alpha.1 <0.2.0. Node ^22.19.0 or >=24.0.0.

More plugins in Messaging & Communication

Browse more in Messaging & Communication

Guides for Messaging & Communication plugins