
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
Fail-closed canonical tool-output tokenization for DeepSeek Harness.
dsh-redact replaces common credentials with opaque, Agent-scoped tokens before the final tool result reaches model context or durable Session history. It replaces the successful canonical value through tools/post-execute, so Harness validates the replacement against the tool's declared output schema and renders model content from the accepted value again.
password=FAKE_PASSWORD
→ password=⟦dsh:redact:550e8400-e29b-41d4-a716-446655440000⟧
The token mapping exists only in process memory. Agent disposal clears it, and a restart makes old tokens intentionally unrestorable.
From a Harness environment:
dsh plugin --profile web add dsh-redact
dsh --profile web --dump-config
For local development, run the same command from this directory and replace the package name with ..
The bundle patch registers the plugin as redact; version 1 has no user configuration.
Source references such as environment-variable reads, function calls, type annotations, and declaration placeholders remain visible. JSON-encoded strings are parsed structurally and serialized back as valid JSON. Encoding deeper than 8 string layers is blocked instead of falling back to unsafe pass-through.
tools/post-execute listener wraps later post policies and sanitizes their effective decision.error, meta, or deferred context fields become safe blocked results instead of retaining the original structure.redaction/applied is appended only after a replacement and contains exactly a count and sorted category list:{
"count": 2,
"categories": ["password", "token"]
}
No original value, replacement token, tool name, arguments, or error detail enters that event.
Version 1 does not:
finalizeContent callback introduces after tools/post-execute;ToolRuntime.execute() call.Tools that need an original credential cannot consume a returned token in version 1. Tool definitions and plugins that run after the canonical boundary remain trusted code and must not synthesize secrets into later presentation content.
A successful downstream post policy that replaces only rendered content is superseded by the canonical value replacement, because retaining a raw canonical value would weaken the confidentiality boundary. Downstream security or spill policies should transform canonical values when they must compose with dsh-redact.
Restoration is available only as an explicit in-memory primitive; the default plugin does not reveal tokens. A trusted same-process host can retain its own policy instance:
import { RedactionPolicy, installRedactionPolicy } from 'dsh-redact'
const policy = new RedactionPolicy()
installRedactionPolicy(ctx, policy)
// Presentation only. Never append this value to the Session log.
const visible = policy.restore(agent, tokenizedText)
restore() replaces only tokens owned by that Agent's live vault. Unknown token-looking strings stay unchanged.
pnpm install --frozen-lockfile
pnpm --filter dsh-redact run check
pnpm --filter dsh-redact run pack:check
See the repository security policy for vulnerability reporting.
FAQs
Fail-closed canonical tool-output tokenization for DeepSeek Harness
The npm package dsh-redact receives a total of 47 weekly downloads. As such, dsh-redact popularity was classified as not popular.
We found that dsh-redact demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.