dsh-tui-secret-guard
在终端中运行以下命令:
dsh plugin install icyaaaww/dsh-tui-secret-guard
将以下提示词粘贴到 DeepSeek Harness 对话框中:
在 DeepSeek Harness 中运行 dsh plugin install icyaaaww/dsh-tui-secret-guard 即可安装该凭据拦截插件,源码仓库为 https://github.com/icyaaaww/dsh-tui-secret-guard
插件介绍
Pasting a snippet of .env, a deployment command carrying a live token, or a debug dump into an agent is the most common way an active credential ends up on the wire. dsh-TUI Secret Guard is a lightweight, local interception layer built for exactly that scenario: it checks outgoing prompts before they ever reach the model.
The plugin recognises known provider tokens, private-key headers, and credential-style assignments such as API_KEY or ACCESS_TOKEN. Everything runs locally. No prompt content is stored, no network, filesystem, or command permission is requested, and the only outward signal is a category-level report of what was blocked. Placeholder values like ${ENV_NAME}, YOUR_API_KEY, redacted, or masked are deliberately passed through, and a blocked prompt must be edited and resubmitted rather than silently rewritten, preventing the model from acting on altered input.
If your dsh-TUI workflow regularly involves pasting code, logs, or configuration text into an agent, especially when production tokens and private keys are in play, Secret Guard adds a zero-side-effect pre-flight check that keeps high-confidence credentials out of the session while leaving your input exactly as you wrote it.
使用场景
- 粘贴 .env 或部署命令到提示词前拦截活跃令牌
- 调试日志包含密钥赋值时阻止发送到模型
- 团队 agent 工作流中统一预检凭据类别
适合人员
- 频繁向 agent 粘贴代码、日志或配置文本的开发者
- 使用 dsh-TUI 工作流且需管理多环境密钥的工程师
- 关注提示词安全与零存储的运维或安全团队