精选
为什么选中它
待人工精选——以下事实来自源码仓库。
它能做什么
Fail-closed export-copy redaction for DeepSeek Harness session telemetry
适合谁
想用 DSH 获得这项能力的用户;装前建议先看源码和文档。
风险提示
- 未发现明显风险信号;安装前仍建议查看源码。
Fail-closed export-copy redaction for DeepSeek Harness session telemetry
待人工精选——以下事实来自源码仓库。
Fail-closed export-copy redaction for DeepSeek Harness session telemetry
想用 DSH 获得这项能力的用户;装前建议先看源码和文档。
dsh plugin --profile web add github:030611/dsh-telemetry-redactor 作者没有声明支持的平台。
Redact supported credential patterns from outbound telemetry copies before configured backends receive them—without rewriting canonical session logs. sh dsh plugin --profile web add dsh-telemetry-redactor > Community-maintained and not an official DeepSeek project. Related trust-layer plugins: Verification Receipt, Evidence Audit, and Context Provenance. dsh-telemetry-redactor is a minimal DeepSeek Harness Profile Bundle that redacts sensitive values from session telemetry before a backend receives them. It mounts on the official session-telemetry/record waterfall, calls next() so other deployment rules still compose, and returns a new recursively redacted record. The official telemetry coordinator deep-copies canonical session events before this waterfall and contains thrown rules per record. Therefore this plugin changes only the outbound copy: it never rewrites the canonical session log. In this document, fail-closed means only that this coordinator withholds one failing export copy and continues the agent loop. It is not a claim that every telemetry path or listener order is impossible to bypass. ## What it redacts - Values under high-risk key names such as authorization, cookie, credential, password, secret, token, apiKey, access_token, clientSecret, and privateKey; recognized credential patterns in key names are replaced too. - Bearer and Basic authorization values embedded in strings. - Common credential forms including sk-..., GitHub tokens, Slack tokens, JWT-like triples, and token=... / api_key: ... assignments. Keys are tokenized before matching, so telemetry counters such as inputTokens, output_tokens, tokenUsage, tokenCount, and contextTokenCount, and ordinary fields such as tokenizer, remain intact. Redaction is a safety filter, not a proof that an arbitrary unknown secret format is absent. The exact supported and unsupported cases are in SECRET-MATRIX.md; see SECURITY.md for the trust boundary. The listener is prepended so it normally wraps deployment rules mounted before or after it and redacts their final output. A deliberately prepended outer listener can still add content after this plugin; review the complete waterfall listener set in security-sensitive deployments. ## Install Install the public package into the selected DSH profile, then inspect the resolved configuration: sh dsh plugin --profile web add dsh-telemetry-redactor dsh --profile web --dump-config The dump must contain the inserted telemetry-redactor row. The bundle does not add, replace, or enable a telemetry backend; it only protects records handled by whatever backend the deployment already selected. ## Configuration The only option is replacement, which defaults to [REDACTED]. It must contain 1 to 128 characters and must not itself match a supported credential pattern; invalid values fail loudly when the Cordis plugin fiber is awaited. yaml - id: telemetry-redactor config: replacement: '[TELEMETRY-REDACTED]' The key and pattern rules are fixed security behavior and cannot be disabled through configuration. ## Verification sh pnpm run typecheck pnpm test pnpm run build pnpm run test:smoke pnpm run test:performance pnpm run test:official-head pnpm run test:official-patch pnpm run test:packed:clean-env The tests include a real Cordis Loader composition with the SessionTelemetryCoordinator: the backend receives the replacement while the authoritative session event retains the fixture secret, and an over-deep record is withheld without escaping the capture handler. Release smokes use the packaged frozen fixture for official commit 47f943859bef60e4160492346772ded9b24f765a: it pins the reviewed source hashes, exact published runtime versions and runtime-file hashes, then verifies the required Cordis/session/LLM/coordinator API surface before composing it with the built or tarball-installed plugin. test:official-patch similarly pins the reviewed Include source hash before applying cordis.patch.yml. No environment variable or installed official checkout is required. ## Model Experience None. The plugin observes an outbound telemetry copy after session logging and contributes no prompt text, tool schema, message, or provider request. #### KV Cache effect None; no model request changes. ## Known limitations - Unknown secret formats that have neither a sensitive key nor a recognized string pattern may pass through. Add deterministic coverage before extending the fixed patterns. - Accessor properties and non-plain objects are rejected rather than read or silently converted. Enumerable JSON data in arrays, ordinary objects, and null-prototype objects is supported; non-enumerable fields are outside the telemetry contract. - A key-name match redacts the complete value. This favors safety over retaining structure beneath fields named as credentials. - Redaction occurs synchronously on the telemetry capture path. The implementation is recursive and bounded to 64 nested containers; very large but shallow records still cost linear CPU time. - A Proxy can run or throw from reflection traps before the plugin can inspect its contents. The official coordinator's own structuredClone normally rejects a Proxy before this waterfall; direct third-party dispatch is not a supported hostile-object sandbox. - dsh.plugin.json is supplemental community metadata. DSH installation is controlled by package.json's dsh.bundle field and cordis.patch.yml. ## License MIT不看 Star,人工一条条挑的。
把 DSH 的 settings.yaml 做成可视化看板:所有已注册的 settings namespace——包括官方界面从未覆盖的第三方插件配置——都渲染成可编辑表单。项目还早,但方向很对:告别手改 YAML。
给 DSH 的 DIY 轨迹可视化:把 agent 的计划与执行画成图,不用翻原始日志也能看清它在干嘛。项目还早,但补上了「一眼看懂 agent 在做什么」这个真实缺口。
从 Claude Code / Codex 把活派给 DSH:在宿主内拉起带分级预设的 DSH agent 会话,看原生子代理进度,还能借它的多模态桥给纯文本的 DSH 补上视觉和生图。编排型插件,把 DSH 变成其他编码 agent 的后端。