Install
Inside DeepSeek Harness, with dsh-market
dsh plugin --profile web add dshmarket
Or from the command line
dsh plugin --profile web add github:amwangfan/dsh-privacy-guard
Installing runs third-party code with your own permissions — it can read your files, use your credentials and reach the network. Review the source first, and pin a commit (github:owner/repo#sha) when you can.
README
English | 简体中文
DeepSeek Harness (DSH) Web plugin for local privacy protection: gateway monitoring, an audit dashboard, the exemption whitelist, encryption-key management, a credential-protected model entry, and deployment controls.
Named "Privacy Protection" rather than "redaction" because semantic sensitive-information filtering is planned.
Designed to accompany amwangfan/privacy-gateway.
🌟 Features
- 🛡️ Gateway & Model Health Probes:
- Live status of the local reverse proxy (
:8317) and Qwen2.5-0.5B residual classifier (:8319).
- Live status of the local reverse proxy (
- 📊 Audit Metrics Dashboard:
- Real-time counters for redacted credentials (
API_KEY, private keys, database passwords, JWTs, etc.). - Outbound DFA stream restoration counters.
- Active memory vault entries count and persistent SQLite rows.
- 0.5B model classification hits and cache metrics.
- Real-time counters for redacted credentials (
- ⚙️ Custom Master Password & Secret List Guidance:
- Guidance for configuring custom master passphrase (
VAULT_PASSWORD) using PBKDF2-HMAC-SHA256 to derive AES-256 keys. - Support for custom proprietary token lists via
CUSTOM_SECRETSorcustom_secrets.txt.
- Guidance for configuring custom master passphrase (
- 🧪 Interactive Leak-Test Sandbox (Dry-Run Tester):
- Built directly into the DSH Settings panel.
- Paste any configuration or text with credentials to instantly preview redacted placeholders before actual LLM calls (100% local, zero WAN egress).
- 🔑 Encryption key configuration (optional):
- Choose between the generated key file and a custom passphrase; the passphrase is never echoed back.
- Changing the key re-encrypts and verifies existing credentials first, rolls back on failure, and keeps older placeholders restorable.
- 🔓 Exemption whitelist and in-page banner:
- The panel lists every term whose filtering is currently paused (scope, reason, actor, expiry, hits) and lets you edit it line by line: one term per line, removing a line revokes it.
- When an exemption is added or revoked, an in-page banner (not a browser
alert) reports which term, why, and who did it.
- 🛡️ Credential-protected model entry: copy an existing provider into a gateway-routed route in the model list while the original returns to the direct route. For the built-in DeepSeek provider, which is a singleton and cannot be copied, the panel reads its own configuration and adds an OpenAI-compatible provider pointing at the gateway's
/deepseekprefix (reusingDEEPSEEK_API_KEY), leaving the original direct route in place. - 🚀 Deployment controls: download and deploy the gateway or the model, start/stop/restart them, read their logs, and edit their addresses and ports — all from the panel.
🛡️ Credential-protected models (a second route in the model list)
The "Credential-protected models" card copies an existing provider, points its baseURL at the
local gateway and writes it into the model list in ~/.dsh/settings.yaml, while moving the
original provider back to the direct route. The model list then carries both:
| Entry | Route | Use |
|---|---|---|
自建聚合 |
direct backend :8316 |
no redaction wanted (fastest, no added latency) |
自建聚合(凭据保护) |
through the gateway :8317 |
redaction wanted |
DeepSeek 官方 (built-in) |
direct api.deepseek.com |
official API, direct |
DeepSeek 官方(凭据保护) |
through the gateway :8317/deepseek |
official API with redaction |
Selecting the entry marked "credential-protected" routes that model through the gateway. No
restart is needed: dsh-settings-file watches the file with chokidar and publishes external edits
(a page refresh shows them).
The write loads the whole YAML document, changes only the provider block and writes it back, after
backing the file up as settings.yaml.bak-plugin-*; every other setting is verified unchanged.
🔓 Exemptions (allowlist)
Default posture: everything is filtered. An exemption pauses redaction for one exact literal term; it is not a global off switch, and the gateway enforces these constraints in code:
| Constraint | Detail |
|---|---|
| Reason | the agent entry point (CLI) requires a non-blank reason; the gateway HTTP API does not, so a human can set one without |
| Expiry | permanent by default, until revoked; pass expires_at only when a temporary exemption is wanted |
| Addressable by alias | --term accepts a vault alias such as <SECRET_AWS_AKIA_1>; the gateway resolves it, so the agent never handles plaintext |
| Scope | layer0 (regex), layer1 (0.5B residual classifier), or all |
| Audit trail | add / revoke / expire / hit all appended to exemptions.jsonl |
| Exact matching | boundary-matched against whole candidates, so allowlisting a short word never leaks a real key that contains it |
| Loopback only | the control API rejects any non-loopback request with 403 |
Agent entry point
/root/privacy-gateway/scripts/privacy-exempt.sh allow --term "<literal or vault alias>" --reason "<why it is safe>" [--scope all|layer0|layer1]
/root/privacy-gateway/scripts/privacy-exempt.sh revoke --term "<literal>" --reason "<why filtering can resume>"
/root/privacy-gateway/scripts/privacy-exempt.sh list
/root/privacy-gateway/scripts/privacy-exempt.sh audit
An agent that allowlists a term must also tell the user what it exempted and why; the plugin surfaces the same decision in the banner.
📦 Ecosystem Architecture
| Component | Role | Repository |
|---|---|---|
dsh-privacy-guard (This Repo) |
DSH Web plugin & dashboard (Node.js / React / Cordis) | GitHub: amwangfan/dsh-privacy-guard |
privacy-gateway |
Local high-performance reverse proxy (Python / FastAPI / DFA) | GitHub: amwangfan/privacy-gateway |
qwen2.5-0.5b-privacy |
Residual credential classifier (step-220 LoRA + F16/Q8 GGUF; probe gates on FPR only; weak passwords are not hard-ruled, a miss is a miss) | HuggingFace: amwangfan/privacy-gateway-v4-qwen2.5-0.5b |
🚀 Installation
# Add to your DSH web profile
dsh plugin --profile web add dsh-privacy-guard
Or install from local source (recommended while developing: rebuild and restart DSH to pick changes up):
cd /path/to/dsh-privacy-guard
npm run build # esbuild -> lib/index.js + lib/client.js
dsh plugin --profile web add link:$PWD
systemctl restart deepseek-harness.service
Open your DSH Web GUI -> Settings -> Privacy Guard to view the live dashboard, the exemption list, and the in-page exemption banner.
Self-check:
./scripts/verify.sh
DSH authenticates every
/api/*route, so an unauthenticated probe only sees 401. Confirm the plugin really loaded via the Settings panel andjournalctl -u deepseek-harness.service | grep -i privacy.
🏪 DSH Marketplace Entry (community.json)
{
"id": "dsh-privacy-guard",
"name": "隐私保护",
"nameEn": "Privacy Protection",
"author": "amwangfan",
"description": "DSH 隐私保护插件:本地网关凭据脱敏与流式还原,豁免白名单(一行一词、可编辑),加密密钥管理,凭据保护模型入口,以及网关/小模型的下载部署与链接配置。",
"descriptionEn": "Privacy protection plugin for DSH: credential redaction and stream restoration through a local gateway, an editable exemption whitelist, encrypted key management, credential-protected model entries, and download/deploy plus link configuration for the gateway and local model.",
"repo": "https://github.com/amwangfan/dsh-privacy-guard",
"npm": "dsh-privacy-guard",
"category": "security",
"subcategory": "dlp"
}
📄 License
Apache License 2.0
Comments
Comments live in GitHub Discussions. Sign in with GitHub to post or react.