Read-only security and compliance plugin for DeepSeek Harness: prompt-injection detection, Chinese-PII redaction, and a local configuration audit with redacted, reproducible reports.
- GitHub stars
- 3
- Version
- v0.2.6
- License
- MIT
- Added
- 2026-08-21
GitHub info
- GitHub stars
- 3
- License
- MIT
- Primary language
- JavaScript
- Last push
- Aug 20, 2026, 1:58 AM
- Maintainer
- PensiveFei
- Added
- 2026-08-21
Install
dsh plugin --profile web add dsh-secure-auditTags
README badge
Add this Markdown to your plugin README to link back to its listing.
[](https://dshget.com/plugins/PensiveFei/dsh-secure-audit)Related plugins
Security & Permissionsdsh-defend
★ 5Detects prompt-injection, jailbreak, and secret-leak patterns on the agent/pre-step, tools/pre-execute, and tools/post-execute seams with allow/ask/block tiers, sanitized defend/detection audit events, a defend_report tool, and a destructive-delete command guard.
dsh-sentinel-scanner
★ 6Static security scanner for DSH plugins: read-only audit (exec, credentials, exfiltration, obfuscation, install scripts, bundle manifest) with a 0-100 risk score.
dsh-mask
PII masking for DeepSeek Harness — anonymizes names, phones, emails, ids, and keys before requests and restores them at the display layer, keeping plaintext out of session logs.