dsh-mask avatar

dsh-mask

PII masking middleware for DeepSeek Harness: anonymize names, phones, emails, ID cards, bank cards, keys, and addresses to placeholders before they reach the model, restore them at the display layer, keep the restore table only in memory and a controlled storage domain, never log plaintext, and expose /mask and the mask_test tool

PluginSecurityKnowledgeStorageMemoryStorage
Verification
L5 · Run tested
Verified
Risk
Low
Health
Active
Trust
Gold

Install verification: runtime verified (L5) · tested on dsh 0.2.0-rc.1 · last checked Install verification details →

Install verification badge dsh 0.2.0-rc.1Install verification badge dsh 0.1.7-rc.2Install verification badge dsh 0.1.7-rc.1Install verification badge dsh 0.1.5-rc.2Install verification badge dsh 0.1.2-rc.1

What it doesAI

PII masking middleware for anonymizing sensitive data before sending to model, restoring at display.

  • Anonymizes names, emails, phones, IDs, bank cards, keys, addresses
  • Restores placeholders at display layer with in-memory table
  • Never logs plaintext; exposes /mask and mask_test tool
securityAImemoryAIstorageAI

Capability tags are AI-inferred or rule-extracted from the README (see badge) — vocabulary-limited, not install-verified. AI = inferred; README = literal keyword from the readme.

Installation

dsh plugin --profile web add dsh-mask@0.2.15

security scan passed · npm package v0.2.15

Install method: npm · runtime verified (L5)

Verification & Compatibility

Grouped by plugin version: each card lists the dsh versions actually tested against that artifact version and their install verdicts (L5 wins). Untested combinations are omitted — absence means untested, never assumed compatible. L1–L3 are a plugin-level static archive (independent of the dsh version — the same verdict on every dsh row): they sit in each row's level grid next to L4/L5, marked "static", while their evidence is stored once per plugin inside that row's "checks & evidence" instead of being duplicated per version.

External credentials (plugin-level): none detected

Install compatibility matrix (rows = plugin versions〔latest 5〕, columns = dsh versions〔latest 5〕)
At-a-glance → evidence in the cards below
plugin \ dshdsh 0.2.0-rc.1
current
dsh 0.1.7-rc.2dsh 0.1.7-rc.1dsh 0.1.6-alpha.2dsh 0.1.6-alpha.1
0.2.15✓····
0.2.14·✓···
0.2.13·····
0.2.12··✓··
0.2.11···✓·
Install compatibility (by plugin version, dsh versions within)
Legend:✓ L5 runtime verified○ ecosystem plugin◼ ecosystem app✗ failed
0.2.15npm✓ 2 runtime-verified2026-09-30

dsh-mask

✓dsh 0.2.0-rc.1current2026-09-29L5 · runtime verified
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.2.0-rc.1
  • • Plugin artifact: npm · dsh-mask@0.2.15
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Passed
Install + runtime smoke verified in the dsh sandbox — installs and runs
L5 · runtime verified · valid for dsh 0.2.0-rc.1

ID: dsh-mask@0.2.15@dsh0.2.0-rc.1 · profile: l4-sandbox

Issued: 2026-09-29 · expires: 2026-10-06

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-30
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-30
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-29
spec dsh-mask · channel npm package · outcome ran · exit 0
check took: 58.2s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-29
spec dsh-mask · channel npm package · outcome ran · exit 0
check took: 58.2s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-29
spec dsh-mask · channel npm package · outcome ran · exit 0
check took: 58.2s
Resolved version recorded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-29
spec dsh-mask · channel npm package · outcome ran · exit 0
check took: 58.2s
L5 · Run tested✓ Passed

active in loader tree (150 entries)

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-29
spec dsh-mask · install mode reused L4 scratch
check took: 12ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-29
ready line dsh web: http://127.0.0.1:61642/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-29
path / · HTTP 200 · took 12ms
Plugin active in inventory✓ Passed
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-29
verdict active · entries 150
match: include:mask · dsh-mask · phase active
phases: active 122 · null 28

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

✓prehistory2026-09-30L5 · runtime verified
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: unknown
  • • Plugin artifact: npm · dsh-mask@0.2.15
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Passed
Install + runtime smoke verified in the dsh sandbox — installs and runs
L5 · runtime verified · valid for prehistory

ID: dsh-mask@0.2.15@dshunknown · profile: l4-sandbox

Issued: 2026-09-30 · expires: 2026-10-07

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-30
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-30
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-30
spec dsh-mask · channel npm package · outcome ran · exit 0
check took: 16.1s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-30
spec dsh-mask · channel npm package · outcome ran · exit 0
check took: 16.1s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-30
spec dsh-mask · channel npm package · outcome ran · exit 0
check took: 16.1s
L5 · Run tested✓ Passed

active in loader tree (150 entries)

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-30
spec dsh-mask · install mode reused L4 scratch
check took: 100ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-30
ready line dsh web: http://127.0.0.1:54795/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-30
path / · HTTP 200 · took 100ms
Plugin active in inventory✓ Passed
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-30
verdict active · entries 150
match: include:mask · dsh-mask · phase active
phases: active 122 · null 28

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

0.2.14npm✓ 1 runtime-verified2026-09-25

dsh-mask

✓dsh 0.1.7-rc.22026-09-25L5 · runtime verified
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.7-rc.2
  • • Plugin artifact: npm · dsh-mask@0.2.14
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Passed
Install + runtime smoke verified in the dsh sandbox — installs and runs
L5 · runtime verified · valid for dsh 0.1.7-rc.2

ID: dsh-mask@0.2.14@dsh0.1.7-rc.2 · profile: l4-sandbox

Issued: 2026-09-25 · expires: 2026-10-02

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-30
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-30
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-25
spec dsh-mask · channel npm package · outcome ran · exit 0
check took: 6.8s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-25
spec dsh-mask · channel npm package · outcome ran · exit 0
check took: 6.8s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-25
spec dsh-mask · channel npm package · outcome ran · exit 0
check took: 6.8s
L5 · Run tested✓ Passed

active in loader tree (150 entries)

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-25
spec dsh-mask · install mode reused L4 scratch
check took: 38ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-25
ready line dsh web: http://127.0.0.1:54873/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-25
path / · HTTP 200 · took 38ms
Plugin active in inventory✓ Passed
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-25
verdict active · entries 150
match: include:mask · dsh-mask · phase active
phases: active 122 · null 28

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

0.2.13npm2026-09-23

dsh-mask

No runtime install test for this version (static scan only) — compatibility unknown, never assumed.

0.2.12npm✓ 1 runtime-verified2026-09-23

dsh-mask

✓dsh 0.1.7-rc.12026-09-23L5 · runtime verified
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.7-rc.1
  • • Plugin artifact: npm · dsh-mask@0.2.12
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Passed
Install + runtime smoke verified in the dsh sandbox — installs and runs
L5 · runtime verified · valid for dsh 0.1.7-rc.1

ID: dsh-mask@0.2.12@dsh0.1.7-rc.1 · profile: l4-sandbox

Issued: 2026-09-23 · expires: 2026-09-30

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-30
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-30
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-23
spec dsh-mask · channel npm package · outcome ran · exit 0
check took: 9.7s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-23
spec dsh-mask · channel npm package · outcome ran · exit 0
check took: 9.7s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-23
spec dsh-mask · channel npm package · outcome ran · exit 0
check took: 9.7s
L5 · Run tested✓ Passed

active in loader tree (150 entries)

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-23
spec dsh-mask · install mode reused L4 scratch
check took: 55ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-23
ready line dsh web: http://127.0.0.1:62165/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-23
path / · HTTP 200 · took 55ms
Plugin active in inventory✓ Passed
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-23
verdict active · entries 150
match: include:mask · dsh-mask · phase active
phases: active 122 · null 28

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

0.2.11npm✓ 1 runtime-verified2026-09-19

dsh-mask

✓dsh 0.1.6-alpha.22026-09-19L5 · runtime verified
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.6-alpha.2
  • • Plugin artifact: npm · dsh-mask@0.2.11
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Passed
Install + runtime smoke verified in the dsh sandbox — installs and runs
L5 · runtime verified · valid for dsh 0.1.6-alpha.2

ID: dsh-mask@0.2.11@dsh0.1.6-alpha.2 · profile: l4-sandbox

Issued: 2026-09-19 · expires: 2026-09-26

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-30
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-30
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-19
spec dsh-mask · channel npm package · outcome ran · exit 0
check took: 8.9s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-19
spec dsh-mask · channel npm package · outcome ran · exit 0
check took: 8.9s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-19
spec dsh-mask · channel npm package · outcome ran · exit 0
check took: 8.9s
L5 · Run tested✓ Passed

active in loader tree (150 entries)

Sandbox install passed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-19
spec dsh-mask · install mode reused L4 scratch
check took: 16ms
Web boot ready✓ Passed
Source: DSH runtime · Method: web boot · Captured 2026-09-19
ready line dsh web: http://127.0.0.1:58060/?token=…
HTTP endpoint served✓ Passed
Source: DSH runtime · Method: HTTP request · Captured 2026-09-19
path / · HTTP 200 · took 16ms
Plugin active in inventory✓ Passed
Source: DSH runtime · Method: plugin inventory query · Captured 2026-09-19
verdict active · entries 150
match: include:mask · dsh-mask · phase active
phases: active 122 · null 28

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

Only the latest 3 published versions are shown; source-snapshot (commit hash) groups, unstated groups and older versions are omitted — the full archive stays in the data layer (snapshot/unstated groups appear only when a plugin has no published version).

Author badges

Embed the official badges in your README to showcase security & install-test status:

dsh.so risk
`[![dsh.so risk](https://www.dsh.so/badge/dsh-mask.svg)](https://www.dsh.so/artifact/dsh-mask/)`
dsh 0.2.0-rc.1 install verified
`[![dsh.so install · dsh 0.2.0-rc.1](https://www.dsh.so/badge/install/dsh-mask@0.2.0-rc.1.svg)](https://www.dsh.so/artifact/dsh-mask/)`
dsh 0.1.7-rc.2 install verified
`[![dsh.so install · dsh 0.1.7-rc.2](https://www.dsh.so/badge/install/dsh-mask@0.1.7-rc.2.svg)](https://www.dsh.so/artifact/dsh-mask/)`
dsh 0.1.7-rc.1 install verified
`[![dsh.so install · dsh 0.1.7-rc.1](https://www.dsh.so/badge/install/dsh-mask@0.1.7-rc.1.svg)](https://www.dsh.so/artifact/dsh-mask/)`
dsh 0.1.5-rc.2 install verified
`[![dsh.so install · dsh 0.1.5-rc.2](https://www.dsh.so/badge/install/dsh-mask@0.1.5-rc.2.svg)](https://www.dsh.so/artifact/dsh-mask/)`
dsh 0.1.2-rc.1 install verified
`[![dsh.so install · dsh 0.1.2-rc.1](https://www.dsh.so/badge/install/dsh-mask@0.1.2-rc.1.svg)](https://www.dsh.so/artifact/dsh-mask/)`

Security Report

Automated static scan, not manual review.

DSH.SO VETPASSED1125ed
Automated review · daily
PASSED

Vet static analysis found no suspicious behavior — verdict is clean.

0 critical·0 high·0 medium
plugin versionv0.2.15dsh manifest
scanned version0.2.15npm2026-10-01
current version0.2.15same version
vet verdictclean · npm

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

No critical or warning findings.

Activity

Last commit 2026-09-25 · activity: Active

• Repo created: 2026-08-17

• Stars: ★ 13 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/PerryLink/dsh-mask

Was this page helpful?