DSH Plugins
返回列表
🧩

dsh-prompt-shield

admin-security 更新于 2026.08.15

在终端中运行以下命令:

dsh plugin install a1swg1159-pixel/dsh-prompt-shield

将以下提示词粘贴到 DeepSeek Harness 对话框中:

在 DeepSeek Harness 中执行 dsh plugin install a1swg1159-pixel/dsh-prompt-shield 即可安装,完整源码地址为 https://github.com/a1swg1159-pixel/dsh-prompt-shield

插件介绍

In DeepSeek Harness, text returned by Web, MCP, browser, shell, file, and other tools lands in the model's next context at the tools/post-execute boundary with no gate in between. A single indirect prompt-injection hidden in that payload can steer the model into reading secrets, exfiltrating credentials, or overriding its own instructions—and the operator never sees the raw match. dsh-prompt-shield plugs exactly that gap: it scans every tool result before it is committed, using a set of deterministic rules that require no extra model call, no network service, and never surface the matched text in logs or block feedback.

The detection surface covers attempts to override system, developer, or user instructions; requests to read secrets and environment variables via tools or shells; exfiltration of credentials to external endpoints; forged system or authority markers paired with imperatives; zero-width and bidirectional Unicode obfuscation; instructions split across text blocks; and plausible single-layer Base64-encoded payloads. High-confidence rules ship in both English and Chinese. Each finding exposes only a rule ID, a confidence score, and a SHA-256-derived fingerprint—the matched text itself is never copied into model-facing output.

Three modes let you roll out safely: observe records a safe summary and leaves the result untouched; warn (the default) prepends a warning while preserving the original text, giving you a tuning window to watch false-positive rates; block replaces the tool result with a quarantine error so the raw payload never enters model context or durable storage. Tool-name include and exclude accept wildcards, and the default scans every tool because untrusted instructions can arrive through remote APIs just as easily as through repository files or shell output.

The plugin suits DSH workloads that depend on external tool returns—Web scraping, MCP servers, browser automation, shell pipelines—and want a lightweight, auditable deterministic layer on top of sandboxing, permission policy, and credential redaction. Keep in mind that v0.1.0 is a narrow defense, not a security proof: deterministic rules will miss novel phrasing and can flag documentation that merely quotes an attack. Image OCR, arbitrary cipher decoding, semantic model classification, and a management UI are not yet included. It complements, and does not replace, the isolation and review practices already in place.

使用场景

  • 工具返回文本在写入模型上下文前,检测并拦截间接提示注入
  • 通过 observe、warn、block 三阶段渐进上线,降低误报风险
  • 屏蔽匹配原文,仅在日志与反馈中暴露规则 ID 与 SHA-256 指纹

适合人员

  • 依赖 Web、MCP、浏览器或 Shell 等外部工具返回的 DSH 工作流
  • 需要在沙箱与权限策略之上叠加一层轻量确定性检测的运维团队
  • 对提示注入敏感、要求日志不泄露攻击原文的安全合规场景