# dsh-taintguard

> Indirect prompt-injection guard for DeepSeek Harness: taints tool output by origin, gates privileged calls that follow untrusted content, and refuses credentials heading off the machine.

## Metadata

- Author: [@sashankh](https://github.com/sashankh)
- Repo: <https://github.com/sashankh/dsh-taintguard>
- GitHub: [sashankh/dsh-taintguard](https://github.com/sashankh/dsh-taintguard)
- Stars: 0
- Language: TypeScript
- License: [MIT](https://spdx.org/licenses/MIT.html)
- Topics: `agent-security`, `ai-security`, `deepseek-harness`, `dsh`, `dsh-plugin`, `guardrails`, `prompt-injection`
- Forks: 0
- Open Issues: 0
- Last push: 2026-08-16T15:34:21.000Z
- Added: 2026-08-16T00:00:00.000Z

## Install

```bash
dsh plugin --profile web add github:sashankh/dsh-taintguard
```

---

This document is auto-generated by [deepseek-plugin.org](https://deepseek-plugin.org). HTML page: [dsh-taintguard](https://deepseek-plugin.org/plugins/sashankh/dsh-taintguard)
