- Home
- All plugins
- Security
- Taintguard

Taintguard
Plugin for DeepSeek Harness
Repository ownersashankhdsh-taintguard
Indirect prompt-injection guard for DeepSeek Harness: taints tool output by origin, gates privileged calls that follow untrusted content, and refuses credentials heading off the machine.
How to install
dsh plugin --profile web add github:sashankh/dsh-taintguardSuggested commands are derived from the catalog record. Review the repository README, requested permissions, and source before installation. Read the full guide.
What this plugin does
Indirect prompt-injection guard for DeepSeek Harness: taints tool output by origin, gates privileged calls that follow untrusted content, and refuses credentials heading off the machine.
Purpose evidence: this record includes a GitHub repository description. Any localized fallback copy is not independent verification of its capability claims.
Repository and source evidence
This public repository was verified through the GitHub API. The catalog source links the plugin to this repository, but directory inclusion is not an official endorsement.
- Repository owner
- sashankh
- Author
- No independently verified author field is available
- Source
- https://github.com/topics/dsh-plugin
Example configuration
The directory snapshot does not include a repository-verified, plugin-specific configuration example, so no configuration keys are generated or guessed here. After installation, use the official DSH command to inspect the composed configuration for the active profile:
dsh --profile web --dump-configFor plugin-specific configuration, use the repository README and manifests as the source of truth: https://github.com/sashankh/dsh-taintguard
Supported DeepSeek Harness versions
No explicit DSH version range in catalog evidence
Neither the repository evidence nor the directory record provides a verifiable DSH version range. Test the target DSH version in an isolated environment.
Environment, permissions, and dependencies
Environment
GitHub primary language: TypeScript. The directory has not verified the runtime or its version.
Permissions
No verified permission manifest is captured. Review the README, patches, environment variables, and external service access before installation.
Dependencies
The dependency tree was not captured or verified. Use the repository package manifest and lockfile as the source of truth.
GitHub metadata
- Stars / forks
- 0 / 0
- Last repository update
- August 16, 2026
- Latest release
- v0.1.0 · August 16, 2026
- License
- MIT
- Default branch
- main
- Available / archived
- Publicly reachable and not archived
Installation safety
No plugin-specific security assessment was collected. The following is generic DeepSeek Harness installation guidance, not a safety rating or audit conclusion for this plugin.
Third-party plugins can execute code inside your Harness environment. Before installation, review the source, recent activity, dependencies, build scripts, and requested permissions, then test in an isolated environment. Directory inclusion is not a security certification.
Git installs may execute prepare/build scripts on your machine, outside the agent sandbox. Only allow trusted source and pin a commit where possible.
Read the plugin safety guideCommon errors and troubleshooting
No plugin-specific error documentation was collected. The steps below are generic DeepSeek Harness troubleshooting, not fixes verified for this plugin.
- 1. Plugin missing after installation
Confirm installation and launch use the same profile, then run dsh --profile web --dump-config to check whether the bundle entered the composed configuration.
- 2. Git dependency build is blocked
pnpm 10+ may block prepare scripts. Only after reviewing the source, add the exact package key reported by pnpm to allowBuilds, then retry.
- 3. Version or configuration mismatch
Check the repository README, releases, and compatibility evidence. Do not treat directory-wide commands as promises from the plugin author.
Security
More plugins in this category

Mirage
strukto-ai / mirage
The World's First Unified Virtual Filesystem For AI Agents

Aegis
GanyuanRan / Aegis
Make AI coding agents architecture-aware: baseline-first, evidence-verified, drift-checked, and safe across long tasks.

Api Relay Audit
toby-bridges / api-relay-audit
Local security audit for AI API relays and LLM proxies: detects prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet risks.

K8e
xiaods / k8e
k8e.sh - OpenSource Agentic AI Sandbox Matrix

Hol Guard
hashgraph-online / hol-guard
Open-source antivirus for AI agents: block risky tools, secret access, prompt injection, malicious packages, MCP servers, plugins, and skills at runtime.

Anolisa
alibaba / anolisa
ANOLISA (Agentic Nexus Operating Layer & Interface System Architecture) | Agentic OS with runtime, security, observability, and Tokenless response compression for lower token usage and cost.

Pulseaiclub Phi
pulseaiclub / pulseaiclub-phi
a coding Agent from pi. ∞ providers, sub-agents, hashline edits, and a permission gate

Auto Mode
NanmiCoder / dsh-auto-mode
Safe automatic permissions for DeepSeek Harness.