Skip to content
dsh.fish
Bundle

dsh-model-redactor

Model-visible redaction plugin for DeepSeek Harness: redacts secrets from model input and output streams

Source
zerodegress
stars
1 stars
License
MIT
Updated
Updated yesterday

Readme

# dsh-model-redactor

Model-visible redaction plugin for DeepSeek Harness (dsh). It redacts
sensitive material (API keys, tokens, credentials) from what the model sees:

- **Input** (`agent/pre-step`): user messages are rewritten to redacted copies
  before they enter the session log and the model request. Already-logged tool
  results are redacted through session surface replacement, preserving the
  original append-origin events in the durable log.
- **Output** (`llm/stream`): text, reasoning, and tool-call argument deltas are
  redacted before the agent loop logs them, so the log and future model context
  stay consistent. `block-end` payloads are also redacted so the assembled
  assistant message cannot reintroduce a secret.

## Install / compose

Add the row to a Cordis patch:

```yaml
- insert:
    - id: dsh-model-redactor
      name: dsh-model-redactor
      config:
        enabled: true
```

The package ships `cordis.patch.yml` and declares `dsh.bundle.patch` for bundle
profiles.

## Configuration

| Field | Type | Default | Description |
| --- | --- | --- | --- |
| `enabled` | `boolean` | `true` | Master switch. |
| `replacement` | `string` | `[REDACTED]` | Replacement text (1..128 chars). Must not itself match a built-in secret pattern. |
| `customRegexes` | `Array<{ pattern, flags?, replacement? }>` | `[]` | Extra regex rules. |
| `customWords` | `Array<string \| { word, replacement? }>` | `[]` | Exact-word rules. |

Built-in rules are fixed and cannot be disabled. They cover OpenAI-style `sk-`,
`Bearer`, `Basic`, GitHub tokens, Slack tokens, JWTs, assignment patterns,
PEM private-key blocks, and AWS `AKIA` access key IDs.

## Build and test

```sh
pnpm build
pnpm test
```

`tsc` emits `lib/`. Unit and integration tests use Vitest.

Install

dsh plugin --profile web add github:zerodegress/dsh-model-redactor

Profile: web

  • This package builds from source on install. pnpm will ask you to allow its build script — that is permission to run the package’s code on your machine, outside the agent sandbox. Only allow sources you trust.
  • This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.
Source