Taints the agent when tool results carry untrusted content, gates the privileged calls that follow, and refuses credentials passed to network-capable tools in every mode.
- License
- MIT
- Added
- 2026-08-18
GitHub info
- License
- MIT
- Primary language
- TypeScript
- Last push
- Aug 16, 2026, 3:34 PM
- Maintainer
- sashankh
- Added
- 2026-08-18
Install
Install command
dsh plugin --profile web add github:sashankh/dsh-taintguardREADME badge
Add this Markdown to your plugin README to link back to its listing.
Listed onDSH Get
[](https://dshget.com/plugins/sashankh/dsh-taintguard)Related plugins
Security & Permissionsapi-relay-audit
★ 819Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.
Security & Permissionstoby-bridges
dsh-pentest
★ 324Authorized pentest mode for DeepSeek Harness — exploration chain, assets and findings with a Web view.
Security & Permissionshowmp
dsh-auto-review
★ 120Second-model auto-review on the approval answerer chain: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default.
Security & PermissionsPerryLink