All plugins

dsh-taintguard

Verified

by sashankh · Security & Policy

Indirect prompt-injection guard for DeepSeek Harness: taints tool output by origin, gates privileged calls that follow untrusted content, and refuses credentials heading off the machine.

Verified plugin

Depends on the Cordis runtime or ships a cordis.yml, so it loads as a real dsh plugin.

What we found in the repo

  • depends on @deepseek-ai/cordis
  • depends on @deepseek-ai/dsh-llm
  • npm package dsh-taintguard

Installing

Install the package, then register it in your cordis.yml:

npm install dsh-taintguard
# cordis.yml
plugins:
  dsh-taintguard:

Plugin keys and config options vary — check the repo's README before copying this in. dsh is in developer preview and its loader format is still changing.

Before you install

A listing here is not a security audit. The tier above records whether this repo is wired as a real dsh plugin — not whether it is safe to run. A plugin executes with your agent's permissions: your files, your shell, your network. How to vet a dsh plugin before installing

Found malware or an impersonation in this repo? Report this listing

Repository details

Stars
0
Forks
0
Open issues
0
Language
TypeScript
License
MIT
npm package
dsh-taintguard @ 0.1.0
Created
2026-08-16
Last push
2026-08-16

Topics

agent-securityai-securitydeepseek-harnessdshdsh-pluginguardrailsprompt-injection

More in Security & Policy