DSH Plugins
返回列表
🧩

dsh-tui-secret-guard

admin-security 更新于 2026.08.26

在终端中运行以下命令:

dsh plugin install icyaaaww/dsh-tui-secret-guard

将以下提示词粘贴到 DeepSeek Harness 对话框中:

在 DeepSeek Harness 中运行 dsh plugin install icyaaaww/dsh-tui-secret-guard 即可安装该凭据拦截插件,源码仓库为 https://github.com/icyaaaww/dsh-tui-secret-guard

插件介绍

Pasting a snippet of .env, a deployment command carrying a live token, or a debug dump into an agent is the most common way an active credential ends up on the wire. dsh-TUI Secret Guard is a lightweight, local interception layer built for exactly that scenario: it checks outgoing prompts before they ever reach the model.

The plugin recognises known provider tokens, private-key headers, and credential-style assignments such as API_KEY or ACCESS_TOKEN. Everything runs locally. No prompt content is stored, no network, filesystem, or command permission is requested, and the only outward signal is a category-level report of what was blocked. Placeholder values like ${ENV_NAME}, YOUR_API_KEY, redacted, or masked are deliberately passed through, and a blocked prompt must be edited and resubmitted rather than silently rewritten, preventing the model from acting on altered input.

If your dsh-TUI workflow regularly involves pasting code, logs, or configuration text into an agent, especially when production tokens and private keys are in play, Secret Guard adds a zero-side-effect pre-flight check that keeps high-confidence credentials out of the session while leaving your input exactly as you wrote it.

使用场景

  • 粘贴 .env 或部署命令到提示词前拦截活跃令牌
  • 调试日志包含密钥赋值时阻止发送到模型
  • 团队 agent 工作流中统一预检凭据类别

适合人员

  • 频繁向 agent 粘贴代码、日志或配置文本的开发者
  • 使用 dsh-TUI 工作流且需管理多环境密钥的工程师
  • 关注提示词安全与零存储的运维或安全团队