JohnXu22786/secret-guard
Blocks agents from reading or writing sensitive files (.env, credentials, key material), masks leaked secret-shaped values in tool results, keeps an audit journal, and exposes safe sg_* inspection tools that never print raw values.
About this plugin
A security plugin for the DeepSeek Harness (dsh): it intercepts reads and writes of sensitive files (.env, credentials, key material, etc.) by the agent's file tools before they execute, preventing API keys and other secrets from leaking into the conversation context; it also applies a content-masking fallback on tool results so that even content that slips past the interception gets scrubbed.
$ dsh plugin --profile web add dsh-secret-guard$ dsh plugin --profile web add github:johnxu22786/secret-guardHealth breakdown
66 / 100Score reflects license, community signals, documentation and distribution. It is not a code audit — review the source before installing.
Security
Key metrics
Related
Related plugins
[!WARNING] 📌 Announcement (v2.1.7) v2.1.7: Hardens remote/local capability boundaries, long-lived browser and persistent-cache resource ownership, DSH 0.1.5 connection/catalog compatibility, property-based fuzzing, and release provenance without raising the rc.8 Host floor. What’s new →
Local-first code knowledge graph for coding agents: 10 MCP tools for layered context compression, DAG planning, incremental AST indexing, a cross-session skill flywheel, diagnostics, and graph artifact import/export.
Free, keyless web search for DSH: 7 engines (DuckDuckGo/Bing/SearXNG free + Exa/Perplexity/DeepSeek paid), auto-failover, settings-page UI with API key inputs and official links, web_fetch, and an engine test tool.
MCP Connector for DeepSeek Harness: an MCP manager with one panel to connect servers, configure authorization, search tools across connections, and troubleshoot failures. Browse a continuously updated catalog of over one hundred connectors; filter by connection/server/status, inspect readable parameters and the last successful cache time, and rediscover tools. Supports OAuth 2.0 PKCE, API keys, stdio/HTTP, and mcpServers JSON import. Maintained by Qichacha/QCC.
Framework upgrade safety & plugin version gating for DeepSeek Harness (DSH): one-click framework upgrade with auto-rollback on failure → one-click rollback to the previous version after an upgrade → plugins the new framework cannot load are auto-disabled → the plugin upgrade gate refuses a version the host can't take. A built-in multi-source plugin market & index (500+ plugins / 300+ skills, zero GitHub API calls) rides on top as the discovery layer — and every source is swappable: install sourc
Connect your ChatGPT subscription to DeepSeek Harness with OAuth, optional GPT Image generation, user-controlled defaults, Harness-native approvals, diagnostics, and reliable session recovery.