PII masking middleware for DeepSeek Harness: anonymize names, phones, emails, ID cards, bank cards, keys, and addresses to placeholders before they reach the model, restore them at the display layer, keep the restore table only in memory and a controlled storage domain, never log plaintext, and expose /mask and the mask_test tool
Install verification: runtime verified (L5) · tested on dsh 0.2.0-rc.1 · last checked Install verification details →
What it doesAI
PII masking middleware for anonymizing sensitive data before sending to model, restoring at display.
- Anonymizes names, emails, phones, IDs, bank cards, keys, addresses
- Restores placeholders at display layer with in-memory table
- Never logs plaintext; exposes /mask and mask_test tool
Capability tags are AI-inferred or rule-extracted from the README (see badge) — vocabulary-limited, not install-verified. AI = inferred; README = literal keyword from the readme.
Installation
dsh plugin --profile web add dsh-mask@0.2.15security scan passed · npm package v0.2.15
Install method: npm · runtime verified (L5)
Verification & Compatibility
Grouped by plugin version: each card lists the dsh versions actually tested against that artifact version and their install verdicts (L5 wins). Untested combinations are omitted — absence means untested, never assumed compatible. L1–L3 are a plugin-level static archive (independent of the dsh version — the same verdict on every dsh row): they sit in each row's level grid next to L4/L5, marked "static", while their evidence is stored once per plugin inside that row's "checks & evidence" instead of being duplicated per version.
External credentials (plugin-level): none detected
| plugin \ dsh | dsh 0.2.0-rc.1 current | dsh 0.1.7-rc.2 | dsh 0.1.7-rc.1 | dsh 0.1.6-alpha.2 | dsh 0.1.6-alpha.1 |
|---|---|---|---|---|---|
| 0.2.15 | ✓ | · | · | · | · |
| 0.2.14 | · | ✓ | · | · | · |
| 0.2.13 | · | · | · | · | · |
| 0.2.12 | · | · | ✓ | · | · |
| 0.2.11 | · | · | · | ✓ | · |
0.2.15npm✓ 2 runtime-verified2026-09-30
dsh-mask
✓dsh 0.2.0-rc.1current2026-09-29L5 · runtime verified
- • Node.js: v24.14.0
- • DSH: 0.2.0-rc.1
- • Plugin artifact: npm · dsh-mask@0.2.15
ID: dsh-mask@0.2.15@dsh0.2.0-rc.1 · profile: l4-sandbox
Issued: 2026-09-29 · expires: 2026-10-06
View checks & evidence
active in loader tree (150 entries)
L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.
✓prehistory2026-09-30L5 · runtime verified
- • Node.js: v24.14.0
- • DSH: unknown
- • Plugin artifact: npm · dsh-mask@0.2.15
ID: dsh-mask@0.2.15@dshunknown · profile: l4-sandbox
Issued: 2026-09-30 · expires: 2026-10-07
View checks & evidence
active in loader tree (150 entries)
L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.
0.2.14npm✓ 1 runtime-verified2026-09-25
dsh-mask
✓dsh 0.1.7-rc.22026-09-25L5 · runtime verified
- • Node.js: v24.14.0
- • DSH: 0.1.7-rc.2
- • Plugin artifact: npm · dsh-mask@0.2.14
ID: dsh-mask@0.2.14@dsh0.1.7-rc.2 · profile: l4-sandbox
Issued: 2026-09-25 · expires: 2026-10-02
View checks & evidence
active in loader tree (150 entries)
L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.
0.2.13npm2026-09-23
dsh-mask
No runtime install test for this version (static scan only) — compatibility unknown, never assumed.
0.2.12npm✓ 1 runtime-verified2026-09-23
dsh-mask
✓dsh 0.1.7-rc.12026-09-23L5 · runtime verified
- • Node.js: v24.14.0
- • DSH: 0.1.7-rc.1
- • Plugin artifact: npm · dsh-mask@0.2.12
ID: dsh-mask@0.2.12@dsh0.1.7-rc.1 · profile: l4-sandbox
Issued: 2026-09-23 · expires: 2026-09-30
View checks & evidence
active in loader tree (150 entries)
L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.
0.2.11npm✓ 1 runtime-verified2026-09-19
dsh-mask
✓dsh 0.1.6-alpha.22026-09-19L5 · runtime verified
- • Node.js: v24.14.0
- • DSH: 0.1.6-alpha.2
- • Plugin artifact: npm · dsh-mask@0.2.11
ID: dsh-mask@0.2.11@dsh0.1.6-alpha.2 · profile: l4-sandbox
Issued: 2026-09-19 · expires: 2026-09-26
View checks & evidence
active in loader tree (150 entries)
L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.
Only the latest 3 published versions are shown; source-snapshot (commit hash) groups, unstated groups and older versions are omitted — the full archive stays in the data layer (snapshot/unstated groups appear only when a plugin has no published version).
Author badges
Embed the official badges in your README to showcase security & install-test status:
`[](https://www.dsh.so/artifact/dsh-mask/)``[](https://www.dsh.so/artifact/dsh-mask/)``[](https://www.dsh.so/artifact/dsh-mask/)``[](https://www.dsh.so/artifact/dsh-mask/)``[](https://www.dsh.so/artifact/dsh-mask/)``[](https://www.dsh.so/artifact/dsh-mask/)`Security Report
Automated static scan, not manual review.
Vet static analysis found no suspicious behavior — verdict is clean.
v0.2.15dsh manifest0.2.15npm2026-10-010.2.15same versionclean · npmVet is an AST static scan (npm artifact or git source).
Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
Risk details
Activity
Last commit 2026-09-25 · activity: Active
• Repo created: 2026-08-17
• Stars: ★ 13 · Forks: 0
• Health: Active — committed within last 30 days
Source
GitHub: github.com/PerryLink/dsh-mask
Author README
View on GitHub ↗The author's original README from the repository — fetched live, unedited (the English page loads the default README).
