secrets 7
Fail-closed canonical tool-output tokenization for DeepSeek Harness
dsh plugin add dsh-redactDeepSeek Harness plugin for SecurStack security scans, policy checks, doctor diagnostics, and JSON CLI results.
dsh plugin add @securstack/dsh-pluginSecret-scrubbing guard plugin: irreversible regex redaction of secrets before session-log persistence and model requests
dsh plugin add dsh-secret-scrubDeepSeek Harness plugin: manage a local sops+age encrypted credential vault from a sidebar panel. Agents see structure only; plaintext flows only on human click.
dsh plugin add dsh-plugin-sops-vaultDeny an AI agent access to .env files, credential stores, keys and any path you hide β across file tools, shell commands, search selectors and run_code. A DeepSeek Harness (dsh) plugin.
dsh plugin add dsh-hidden-pathsSecure credential vault for DeepSeek Harness: store GitHub/npm/API tokens (secrets never leave the host), run gh/npm/npx/node/git with the token injected in the environment, and manage tokens from a Settings page.
dsh plugin add @yyfather/dsh-token-vaultε―η ζ¬ for the DeepSeek Harness: an end-to-end encrypted personal secrets book on a private gist (age format, node:crypto only), with a browser page for people and value-free tools for the agent.
dsh plugin add dsh-passbook