DSH Hub

PerryLink/dsh-defend

dsh-defend

BundleWorkflow19 GitHub stars· updated 2026-09-25

Prompt-injection, jailbreak, and secret-leak defense for DeepSeek Harness: Aho-Corasick detection with allow/ask/block interception and sanitized audit events

Install

npx @deepseek-ai/dsh plugin --profile web add "github:PerryLink/dsh-defend#main"

Restart `dsh web` after install. Bundle APIs can change during the developer preview.

README badge

dsh-defend DSH Hub badge
[![DSH Hub](https://dshhub.dev/badge/dsh-defend.svg)](https://dshhub.dev/plugins/dsh-defend)

Paste this into your README. The star count updates with every catalog sync.

From the README

Excerpt from PerryLink/dsh-defend, cleaned of badges and images.

🛡️ dsh-defend

  • 1024 store channel: npm i -g dsh1024 once, then dsh1024 plugin --profile web add dsh-defend (counts toward the deepseek1024.com install ranking).

Prompt-injection, jailbreak, and secret-leak defense for DeepSeek Harness.

Rules decide the known. Interception decides the rest — and everything is audited.

English · 简体中文 · Español · Português · हिन्दी


⭐ 如果它帮到了你

这个插件是 DSH 插件家族的一员(40+ 个,全部 Apache-2.0)。如果你在用,给个 star —— 它不会解锁任何功能,但会让下一个人在搜索里更容易找到它。

English: part of a 40+ plugin family for DeepSeek Harness. If it is useful, a star helps the next person find it — nothing is gated behind it.

Compatibility

SurfaceStatus
HarnessDeepSeek Harness dsh-v0.1.7-rc.2 (verified 2026-09-25; peer ranges >=0.1.2-rc.1 <0.2.0 || >=0.1.5-alpha.1 <0.2.0 || >=0.1.6-0 <0.2.0 || >=0.1.7-0 <0.2.0). On this line Session.append's third argument exists only for surface-eligible event types and is a SurfaceIntent, so the non-surface defend/detection type still cannot stamp the ignorable marker: session-log audit stays fail-closed-disabled and /defend renders that state explicitly. Session format V4 has no tool-result content block — this plugin never produced one, and its two content walkers keep a read-only fallback for the retired V3 wrapper so sessions written before the upgrade still scan. Verified 2026-09-25 (dual typecheck rulers + full test suite + build + self-contained/artifacts gates + pack; exactly one copy of the host type graph).
Node^22.19.0 || >=24.0.0
PlatformsAll (pure host; no native code, no network)
ModelAny (detection runs before content reaches the model)

What you get

dsh-defend puts two independent layers in front of the agent:

  1. Destructive-delete guard — the executable form of the 8·14/8·16 postmortem lesson. On tools/pre-execute, recursively deleting shell commands are refused unless every target is an explicit absolute path inside the session workspace and outside the protected prefixes (home config, .dsh/.claude, system directories). Dry-run markers (-WhatIf, --dry-run, git clean -n) pass, because they are exactly the check the lesson demands.
  2. Detection layer — ported from four upstream assets (all Apache-2.0, see THIRD_PARTY_NOTICES.md): 25 Prompt-Injection-Payloads rules, 25 Jailbreak-Detector patterns through a pure-TypeScript Aho-Corasick automaton, 12 secret grammars from Secret-Key-Leaker-Detect plus the issuers' public references, and the Prompt-Attack-Dataset kept verbatim as the regression benchmark.

Three interception points, one decision model each:

PointScannedDecision
agent/pre-stepinbound user messagesallow → next(); ask → approval; block → reject the step
tools/pre-executetool argumentsallow → next(); ask → approval; block → deny
tools/post-executetool resultsallow → next(); ask → approval; block → corrective feedback

Defaults: ask for every family, block for critical secrets (the upstream interrupt-on-sight semantics). No approval answerer = fail closed. Every pass-through calls next() — downstream policy plugins are never short-circuited.

…

Related plugins