PerryLink/dsh-defend
dsh-defend
Prompt-injection, jailbreak, and secret-leak defense for DeepSeek Harness: Aho-Corasick detection with allow/ask/block interception and sanitized audit events
Install
npx @deepseek-ai/dsh plugin --profile web add "github:PerryLink/dsh-defend#main"Restart `dsh web` after install. Bundle APIs can change during the developer preview.
README badge
[](https://dshhub.dev/plugins/dsh-defend)Paste this into your README. The star count updates with every catalog sync.
From the README
Excerpt from PerryLink/dsh-defend, cleaned of badges and images.
🛡️ dsh-defend
- 1024 store channel:
npm i -g dsh1024once, thendsh1024 plugin --profile web add dsh-defend(counts toward the deepseek1024.com install ranking).
Prompt-injection, jailbreak, and secret-leak defense for DeepSeek Harness.
Rules decide the known. Interception decides the rest — and everything is audited.
English · 简体中文 · Español · Português · हिन्दी
⭐ 如果它帮到了你
这个插件是 DSH 插件家族的一员(40+ 个,全部 Apache-2.0)。如果你在用,给个 star —— 它不会解锁任何功能,但会让下一个人在搜索里更容易找到它。
English: part of a 40+ plugin family for DeepSeek Harness. If it is useful, a star helps the next person find it — nothing is gated behind it.
Compatibility
| Surface | Status |
|---|---|
| Harness | DeepSeek Harness dsh-v0.1.7-rc.2 (verified 2026-09-25; peer ranges >=0.1.2-rc.1 <0.2.0 || >=0.1.5-alpha.1 <0.2.0 || >=0.1.6-0 <0.2.0 || >=0.1.7-0 <0.2.0). On this line Session.append's third argument exists only for surface-eligible event types and is a SurfaceIntent, so the non-surface defend/detection type still cannot stamp the ignorable marker: session-log audit stays fail-closed-disabled and /defend renders that state explicitly. Session format V4 has no tool-result content block — this plugin never produced one, and its two content walkers keep a read-only fallback for the retired V3 wrapper so sessions written before the upgrade still scan. Verified 2026-09-25 (dual typecheck rulers + full test suite + build + self-contained/artifacts gates + pack; exactly one copy of the host type graph). |
| Node | ^22.19.0 || >=24.0.0 |
| Platforms | All (pure host; no native code, no network) |
| Model | Any (detection runs before content reaches the model) |
What you get
dsh-defend puts two independent layers in front of the agent:
- Destructive-delete guard — the executable form of the 8·14/8·16 postmortem lesson. On
tools/pre-execute, recursively deleting shell commands are refused unless every target is an explicit absolute path inside the session workspace and outside the protected prefixes (home config,.dsh/.claude, system directories). Dry-run markers (-WhatIf,--dry-run,git clean -n) pass, because they are exactly the check the lesson demands. - Detection layer — ported from four upstream assets (all Apache-2.0, see THIRD_PARTY_NOTICES.md): 25 Prompt-Injection-Payloads rules, 25 Jailbreak-Detector patterns through a pure-TypeScript Aho-Corasick automaton, 12 secret grammars from Secret-Key-Leaker-Detect plus the issuers' public references, and the Prompt-Attack-Dataset kept verbatim as the regression benchmark.
Three interception points, one decision model each:
| Point | Scanned | Decision |
|---|---|---|
agent/pre-step | inbound user messages | allow → next(); ask → approval; block → reject the step |
tools/pre-execute | tool arguments | allow → next(); ask → approval; block → deny |
tools/post-execute | tool results | allow → next(); ask → approval; block → corrective feedback |
Defaults: ask for every family, block for critical secrets (the upstream interrupt-on-sight semantics). No approval answerer = fail closed. Every pass-through calls next() — downstream policy plugins are never short-circuited.
…
