Bundle
dsh-model-redactor
Model-visible redaction plugin for DeepSeek Harness: redacts secrets from model input and output streams
- Source
- zerodegress
- stars
- 1 stars
- License
- MIT
- Updated
- Updated yesterday
Readme
# dsh-model-redactor
Model-visible redaction plugin for DeepSeek Harness (dsh). It redacts
sensitive material (API keys, tokens, credentials) from what the model sees:
- **Input** (`agent/pre-step`): user messages are rewritten to redacted copies
before they enter the session log and the model request. Already-logged tool
results are redacted through session surface replacement, preserving the
original append-origin events in the durable log.
- **Output** (`llm/stream`): text, reasoning, and tool-call argument deltas are
redacted before the agent loop logs them, so the log and future model context
stay consistent. `block-end` payloads are also redacted so the assembled
assistant message cannot reintroduce a secret.
## Install / compose
Add the row to a Cordis patch:
```yaml
- insert:
- id: dsh-model-redactor
name: dsh-model-redactor
config:
enabled: true
```
The package ships `cordis.patch.yml` and declares `dsh.bundle.patch` for bundle
profiles.
## Configuration
| Field | Type | Default | Description |
| --- | --- | --- | --- |
| `enabled` | `boolean` | `true` | Master switch. |
| `replacement` | `string` | `[REDACTED]` | Replacement text (1..128 chars). Must not itself match a built-in secret pattern. |
| `customRegexes` | `Array<{ pattern, flags?, replacement? }>` | `[]` | Extra regex rules. |
| `customWords` | `Array<string \| { word, replacement? }>` | `[]` | Exact-word rules. |
Built-in rules are fixed and cannot be disabled. They cover OpenAI-style `sk-`,
`Bearer`, `Basic`, GitHub tokens, Slack tokens, JWTs, assignment patterns,
PEM private-key blocks, and AWS `AKIA` access key IDs.
## Build and test
```sh
pnpm build
pnpm test
```
`tsc` emits `lib/`. Unit and integration tests use Vitest.
Install
dsh plugin --profile web add github:zerodegress/dsh-model-redactor
Profile: web
With the hub plugin installed, ask your agent to install it by name — it resolves the same plan shown here.
dsh plugin --profile web add github:stvlynn/dsh.fish#path:packages/dsh-plugin-hub
install dsh-model-redactor from the hub
- This package builds from source on install. pnpm will ask you to allow its build script — that is permission to run the package’s code on your machine, outside the agent sandbox. Only allow sources you trust.
- This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.