Skip to content
dsh-market Browse plugins GitHub 中文

amwangfan/dsh-privacy-guard

Control panel for a local credential-redaction gateway in DeepSeek Harness: gateway and model health, audit metrics, a dry-run leak tester, an exemption whitelist, encrypted key management, credential-protected model entries and deployment controls.

Stars ★ 0 Category Security & Permissions Listed 2026-09-18

Install

Inside DeepSeek Harness, with dsh-market

dsh plugin --profile web add dshmarket

Or from the command line

dsh plugin --profile web add github:amwangfan/dsh-privacy-guard

Installing runs third-party code with your own permissions — it can read your files, use your credentials and reach the network. Review the source first, and pin a commit (github:owner/repo#sha) when you can.

README

English | 简体中文

DeepSeek Harness (DSH) Web plugin for local privacy protection: gateway monitoring, an audit dashboard, the exemption whitelist, encryption-key management, a credential-protected model entry, and deployment controls.

Named "Privacy Protection" rather than "redaction" because semantic sensitive-information filtering is planned.

Designed to accompany amwangfan/privacy-gateway.


🌟 Features

  1. 🛡️ Gateway & Model Health Probes:
    • Live status of the local reverse proxy (:8317) and Qwen2.5-0.5B residual classifier (:8319).
  2. 📊 Audit Metrics Dashboard:
    • Real-time counters for redacted credentials (API_KEY, private keys, database passwords, JWTs, etc.).
    • Outbound DFA stream restoration counters.
    • Active memory vault entries count and persistent SQLite rows.
    • 0.5B model classification hits and cache metrics.
  3. ⚙️ Custom Master Password & Secret List Guidance:
    • Guidance for configuring custom master passphrase (VAULT_PASSWORD) using PBKDF2-HMAC-SHA256 to derive AES-256 keys.
    • Support for custom proprietary token lists via CUSTOM_SECRETS or custom_secrets.txt.
  4. 🧪 Interactive Leak-Test Sandbox (Dry-Run Tester):
    • Built directly into the DSH Settings panel.
    • Paste any configuration or text with credentials to instantly preview redacted placeholders before actual LLM calls (100% local, zero WAN egress).
  5. 🔑 Encryption key configuration (optional):
    • Choose between the generated key file and a custom passphrase; the passphrase is never echoed back.
    • Changing the key re-encrypts and verifies existing credentials first, rolls back on failure, and keeps older placeholders restorable.
  6. 🔓 Exemption whitelist and in-page banner:
    • The panel lists every term whose filtering is currently paused (scope, reason, actor, expiry, hits) and lets you edit it line by line: one term per line, removing a line revokes it.
    • When an exemption is added or revoked, an in-page banner (not a browser alert) reports which term, why, and who did it.
  7. 🛡️ Credential-protected model entry: copy an existing provider into a gateway-routed route in the model list while the original returns to the direct route. For the built-in DeepSeek provider, which is a singleton and cannot be copied, the panel reads its own configuration and adds an OpenAI-compatible provider pointing at the gateway's /deepseek prefix (reusing DEEPSEEK_API_KEY), leaving the original direct route in place.
  8. 🚀 Deployment controls: download and deploy the gateway or the model, start/stop/restart them, read their logs, and edit their addresses and ports — all from the panel.

🛡️ Credential-protected models (a second route in the model list)

The "Credential-protected models" card copies an existing provider, points its baseURL at the local gateway and writes it into the model list in ~/.dsh/settings.yaml, while moving the original provider back to the direct route. The model list then carries both:

Entry Route Use
自建聚合 direct backend :8316 no redaction wanted (fastest, no added latency)
自建聚合(凭据保护) through the gateway :8317 redaction wanted
DeepSeek 官方 (built-in) direct api.deepseek.com official API, direct
DeepSeek 官方(凭据保护) through the gateway :8317/deepseek official API with redaction

Selecting the entry marked "credential-protected" routes that model through the gateway. No restart is needed: dsh-settings-file watches the file with chokidar and publishes external edits (a page refresh shows them).

The write loads the whole YAML document, changes only the provider block and writes it back, after backing the file up as settings.yaml.bak-plugin-*; every other setting is verified unchanged.


🔓 Exemptions (allowlist)

Default posture: everything is filtered. An exemption pauses redaction for one exact literal term; it is not a global off switch, and the gateway enforces these constraints in code:

Constraint Detail
Reason the agent entry point (CLI) requires a non-blank reason; the gateway HTTP API does not, so a human can set one without
Expiry permanent by default, until revoked; pass expires_at only when a temporary exemption is wanted
Addressable by alias --term accepts a vault alias such as <SECRET_AWS_AKIA_1>; the gateway resolves it, so the agent never handles plaintext
Scope layer0 (regex), layer1 (0.5B residual classifier), or all
Audit trail add / revoke / expire / hit all appended to exemptions.jsonl
Exact matching boundary-matched against whole candidates, so allowlisting a short word never leaks a real key that contains it
Loopback only the control API rejects any non-loopback request with 403

Agent entry point

/root/privacy-gateway/scripts/privacy-exempt.sh allow  --term "<literal or vault alias>" --reason "<why it is safe>" [--scope all|layer0|layer1]
/root/privacy-gateway/scripts/privacy-exempt.sh revoke --term "<literal>" --reason "<why filtering can resume>"
/root/privacy-gateway/scripts/privacy-exempt.sh list
/root/privacy-gateway/scripts/privacy-exempt.sh audit

An agent that allowlists a term must also tell the user what it exempted and why; the plugin surfaces the same decision in the banner.


📦 Ecosystem Architecture

Component Role Repository
dsh-privacy-guard (This Repo) DSH Web plugin & dashboard (Node.js / React / Cordis) GitHub: amwangfan/dsh-privacy-guard
privacy-gateway Local high-performance reverse proxy (Python / FastAPI / DFA) GitHub: amwangfan/privacy-gateway
qwen2.5-0.5b-privacy Residual credential classifier (step-220 LoRA + F16/Q8 GGUF; probe gates on FPR only; weak passwords are not hard-ruled, a miss is a miss) HuggingFace: amwangfan/privacy-gateway-v4-qwen2.5-0.5b

🚀 Installation

# Add to your DSH web profile
dsh plugin --profile web add dsh-privacy-guard

Or install from local source (recommended while developing: rebuild and restart DSH to pick changes up):

cd /path/to/dsh-privacy-guard
npm run build                     # esbuild -> lib/index.js + lib/client.js
dsh plugin --profile web add link:$PWD
systemctl restart deepseek-harness.service

Open your DSH Web GUI -> Settings -> Privacy Guard to view the live dashboard, the exemption list, and the in-page exemption banner.

Self-check:

./scripts/verify.sh

DSH authenticates every /api/* route, so an unauthenticated probe only sees 401. Confirm the plugin really loaded via the Settings panel and journalctl -u deepseek-harness.service | grep -i privacy.


🏪 DSH Marketplace Entry (community.json)

{
  "id": "dsh-privacy-guard",
  "name": "隐私保护",
  "nameEn": "Privacy Protection",
  "author": "amwangfan",
  "description": "DSH 隐私保护插件:本地网关凭据脱敏与流式还原,豁免白名单(一行一词、可编辑),加密密钥管理,凭据保护模型入口,以及网关/小模型的下载部署与链接配置。",
  "descriptionEn": "Privacy protection plugin for DSH: credential redaction and stream restoration through a local gateway, an editable exemption whitelist, encrypted key management, credential-protected model entries, and download/deploy plus link configuration for the gateway and local model.",
  "repo": "https://github.com/amwangfan/dsh-privacy-guard",
  "npm": "dsh-privacy-guard",
  "category": "security",
  "subcategory": "dlp"
}

📄 License

Apache License 2.0

Content from the project README on GitHub ↗

Comments

Comments live in GitHub Discussions. Sign in with GitHub to post or react.