What it does
Indirect prompt-injection guard for DeepSeek Harness: taints tool output by origin, gates privileged calls that follow untrusted content, and refuses credentials heading off the machine.
Installation
dsh plugin --profile web add github:sashankh/dsh-taintguardInstall method: GitHub · not yet tested in container (L3+)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
Requirements
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
No security scan record for this plugin yet. Newly indexed plugins are scanned by the daily pipeline.
——421e6726d9d0The scan result is only valid for the scanned commit. If the latest commit differs, the badge shows outdated until the daily pipeline rescans.
Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
• Static heuristic scan: pending
• Dependency vulnerabilities: —
• Hardcoded secrets: —
• Supply chain risks: —
Activity
Last commit 2026-08-16 · activity: Active
• Repo created: 2026-08-18
• Stars: ★ 0 · Forks: 0
• Health: Active — committed within last 30 days
