All plugins

DSH / BUNDLE / BUNDLES

dsh-secure-audit

v0.2.10PensiveFei / dsh-secure-audit91bc723264

InstallableBundlesBundles & other modulesCommunity · Topic auto-analysis

Overview

dsh-secure-audit

Read-only security & compliance toolkit for DeepSeek Harness: prompt-injection detection (rule engine with a pluggable model classifier), Chinese-PII and structured-JSON redaction, and a local configuration security audit that emits redacted, reproducible, self-checksummed risk reports.

README / EN

Package documentation

Registry summary

Read-only security & compliance toolkit for DeepSeek Harness: prompt-injection detection (rule engine with a pluggable model classifier), Chinese-PII and structured-JSON redaction, and a local configuration security audit that emits redacted, reproducible, self-checksummed risk reports.

dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.

Read the full README on GitHub

LIMITATIONS

Known limitations

This plugin is a read-only, heuristic aid. It is not a security product, not a certification, and not a substitute for a proper threat model. Read this before relying on it. **Detection is heuristic.** - The injection rules are a fixed pattern table (English + Chinese). They can miss novel or obfuscated attacks (false negatives) and can over-flag benign phrasing (false positives). `allow` means "no rule fired", not "safe". Fail-open timeouts and truncation downgrade to `allow` with an explicit warning — treat those as "not fully scanned". - The optional model classifier runs only on `review` verdicts, only when configured, and depends on a local model you operate (the built-in adapter targets Ollama / Llama-Guard). Without a classifier, ambiguous cases stay at `review` for a human. **Redaction is type-limited.** - Only the listed PII types are masked (CN mobile / ID / bank card, email, IPv4, API keys, URL credentials). Chinese names, addresses, and other context-sensitive PII are NOT covered. Regex + structural validation cuts false positives (order numbers) but cannot guarantee zero misses. **The audit is a posture snapshot.** - Nine fixed checks; every report carries a `limitations` field stating what that run does not cover. - File-permission checks use POSIX mode bits; **Windows ACLs are not inspected** (Node has no native ACL API). - Live listening-port ground truth runs on **Linux only** (`/proc/net`); other platforms rely on env/config evidence. - Session-file PII sampling covers up to 10 files by default; raise `sampleLimit` for large session directories. - The live `deps-supply-chain` registry lookup is **opt-in** (`supplyChainLive: true`) and sends installed plugin names+versions to registry.npmjs.org; offline inventory is the default. - Absence of findings does not imply the machine is secure. **Compatibility.** - Tested against `@deepseek-ai/dsh-tools` 0.1.2-alpha.2 only. DSH is pre-1.0; verify against your pinned version. Live loading in a Cordis host was validated at the dsh-tools registration/execution contract level, not in a fully running host — install, run `security_audit`, and re-verify after upgrading either side. **Legal.** - Provided under MIT, "as is", without warranty of any kind (see [LICENSE](LICENSE)). - Unofficial third-party tool; not affiliated with, endorsed by, or sponsored by DeepSeek (see the top disclaimer).