dsh-egress-guard

tancheng33

工具管线上的运行时安全网关:拦截出站白名单之外的主机调用,在 canonical value(而非仅渲染内容)层面脱敏结果中的凭据,每个决策写入 JSONL 审计日志;默认仅监控不拦截。

Runtime security gate on the tool pipeline: denies calls naming hosts outside an egress allowlist, redacts credentials from results at the canonical value rather than only the rendered content, and appends every decision to a JSONL audit log; ships in monitor-only mode.

安装命令

dsh plugin --profile web add github:tancheng33/dsh-egress-guard

该命令来自上游目录,本站的自动审核尚未覆盖它——执行前请自行核对仓库。

安装后运行 dsh --profile web --dump-config 并重启对应 profile。插件会以你的本机权限运行第三方代码,安装前请检查源码。

信号

GitHub Stars1
30 天下载
分发方式Git
收录时间2026-08-15

相关链接

同类插件