YD

yujunzhixue/dsh-purge

Developer tools
4.3K stars Quality 70 Trend 70

DeepSeek Harness 破甲:让所有模型都能破甲,不同模型可换不同提示词;默认提示词面向国模「小码酱」。Jailbreak for every model — swap prompts per model. 求 Star 收藏 ⭐ 如要二开,请查看署名要求部分

Overview

⚔️ DeepSeek Harness cybersecurity red-team tool (dsh-purge) DeepSeek Harness jailbreak: every model, swap prompts per model. Default prompt for 小码酱. Please star ⭐ If you build on this, see Attribution required. Official dsh web uses profile web. The official desktop EXE (DeepSeek Harness ) uses profile desktop. Install and Apply them separately. This release targets dsh 0.2 only. Older dsh builds need the matching older plugin. Community Desktop is not maintained. Adding the plugin to a profile does not patch the host. Click beside the session title → → . A successful Apply restarts; an unfinished Apply does not. After the restart, start a new chat — that is when the inject enters the session. Node.js . Windows no-flash needs . Do not use the Hub one-click install. Commands are below. If this project helps you, send it over — I'm out here asking~ is a cybersecurity red-team plugin for the official DeepSeek Harness already installed on your machine.

README

⚔️ DeepSeek Harness cybersecurity red-team tool (dsh-purge)

Version 1.1.66

DeepSeek Harness jailbreak: every model, swap prompts per model. Default prompt for 小码酱. Please star ⭐ If you build on this, see Attribution required.

English | 中文

Official Web and the official desktop app are both supported. Official dsh web uses profile web. The official desktop EXE (DeepSeek Harness 0.2.0-rc.2) uses profile desktop. Install and Apply them separately. This release targets dsh 0.2 only. Older dsh builds need the matching older plugin. Community Desktop is not maintained.

Adding the plugin to a profile does not patch the host. Click dsh-purge beside the session title → Clean → Apply. A successful Apply restarts; an unfinished Apply does not. After the restart, start a new chat — that is when the inject enters the session.

Node.js ≥18. Windows no-flash needs Node ≥22. Do not use the Hub one-click install. Commands are below.

Contents


☕ Sponsor

If this project helps you, send it over — I’m out here asking~

Asset Address
USDT (TRC20) TV5ajPkRD8RH623Dx9mqvYZVNN8nPGRKid
Solana 6x16GhRgLVpKFFXaU1seKNdx2rypspSJTL4dbpt6Xpwk
Ethereum 0xB68BD60C0e8c519513B7DF9bB147696815423B3E
Bitcoin bc1qu70yxkrtwnymt8ryluz9x8y8hqzune5340npht

What this is

dsh-purge is a cybersecurity red-team plugin for the official DeepSeek Harness already installed on your machine. Official Web (dsh web) and the official desktop EXE are both supported. Install and Apply them separately.

Harness does more than forward a prompt. It rewrites prompts, approval gates, sandbox policy, and session migration at runtime. Asking only “will the model answer” treats a host-layer block as a model refusal. This plugin separates those two layers on your own install, for controlled evaluation and for seeing which default policy is too tight.

You get What it does
dsh-purge dock A button beside the session title opens the right dock. Two pages: Clean and Drill
Clean Grouped patch status, Apply / Restore / Uninstall, prompt editor, multiple rule sets
Drill Built into the stable release. After authorization: assets, skills, and the local environment. Only for a host you manage, an offline target, or a written authorized exercise
Host policy Default copy, permission policy, and tool limits. Official capabilities stay. No second invented identity
On start Checks and reapplies. After npm overwrites node_modules, you do not hand-edit files

No hardcoded drive letters. It looks at $DSH_HOME, .dsh next to the dsh launcher, then ~/.dsh. It does not patch the Harness source tree. Apply on the Clean page of dsh-purge is what writes the changes. Identity comes from the encrypted prompt shipped in the plugin, the text the prompt box shows by default. The host prompt file is not read.

It only touches the official @deepseek-ai packages and local config on the user’s machine. It is not a public scanner and not an attack kit for third-party sites. The repo does not ship malware, unauthorized-exploit scripts, or payloads aimed at the public internet.


Non-profit public project. Commercial sale, paid resale, and profit from illegal or gray-market activity are forbidden. For technical reference only.

Attribution required

If you borrow this project’s name, ideas, code, or prompts, you must credit the author and name the source repository: YuJunZhiXue/dsh-purge.

Using them without attribution, hiding the source, or passing them off as your own will be pursued.



Supported hosts

The latest plugin supports dsh 0.2 only — do not apply it to 0.1.x.

  • dsh 0.2 (official desktop 0.2.0-rc.2 / official dsh web): use 1.1.40 or newer. This page installs that line.
  • dsh 0.1.7 (incl. rc.1 / rc.2): use 1.1.39 or older — pick the tag on Releases.

Unmatched patches stay pending or skipped; nothing is rewritten blindly.


Install

Web and the official desktop EXE are the two maintained hosts. Install and patch each separately, and only the host you actually run.

What you run Profile Command
Official dsh web web dsh plugin --profile web add
Official desktop EXE desktop dsh plugin --profile desktop add

`` = https://github.com/YuJunZhiXue/dsh-purge/archive/refs/heads/master.tar.gz. If this directory is already a clone, use add . instead of the URL. If dsh is not on PATH, use Manual install.

For the desktop client you can also click the button (dsh:// deep link):

Install in desktop client

Do not use the Hub one-click install or deepseek.stream/api/plugins/download?... — it runs git+https://…dsh-purge.git and fails at git ls-remote. Use the .tar.gz command above. The Hub page is read-only.

After the command: three steps

Adding the plugin to a profile does not patch @deepseek-ai by itself.

  1. Quit and reopen the host you installed into — stop and restart dsh web, or quit the desktop tray and reopen that app.
  2. On that host, click dsh-purge beside the session title, then Apply on the Clean page. It is not on the host Settings page.
  3. A successful Apply restarts once so patches load. It does not restart if it did not finish.

Web controls affect Web only; desktop controls affect the desktop app only. Do not Apply one host from the other.

How to tell it installed

  • dsh-purge sits beside the session title, with Apply on its Clean page.
  • /purge status in chat prints DSH_HOME and the patch list — the path should be the home you actually run.
  • Optional packages that are not installed (liangshen) show as skipped and do not block Apply.

Hand this to an assistant

Paste the block below to a local assistant. It should only run the install command — no disk scan, no other edits, no Apply, no restart.

Manual install

Use this when the command fails or dsh is not on PATH. Edit only the profile for the host you run — do not touch the other, and do not delete existing bundles.

Uninstall

dsh-purge beside the session title → Clean → Uninstall. Confirm the dialog: it reverts any applied patches, restores the original Harness, and restarts the current host.

# or from a terminal / chat
dsh-purge --uninstall
# /purge uninstall

Plugin config lives in cordis.patch.yml (postPrompt is empty by default):

- insert:
    - id: dsh-purge
      name: 'dsh-purge'
      config:
        enabled: true
        autoApplyOnStart: true
        autoUpdateOnStart: false
        autoRevertOnMissing: false
        verbose: false
        postPromptOrder: 5100
        postPrompt: ""

Preview

dsh-purge sits beside the session title. It opens a right-hand dock with two pages: Clean and Drill. Switch Light / Ink. Patches are grouped; the count only includes items that actually applied. Rule sets sit in a list above the editor, with Enable and Delete on each row.

The first time you open Drill you read the notice, wait out the countdown, scroll to the end, and check three boxes. Clean does not need that step. Drill is only for a host you manage, an offline target, or an exercise that already has written authorization.

Clean

Drill authorization

Drill

Patches

Own servers

On the Clean page, under Prompt. One host per line, then Save list. Steps are in Own servers.

Area What it shows
dsh-purge button beside the session title; opens or collapses the dock
Clean the old Rules page: patches, prompt, rule sets, skills
Drill assets, skills, and environment after authorization. The tab says Unauthorized until then
Patches grouped status, Apply, Restore, or Uninstall
Prompt edit prompt-inject.md as the session override
Own servers one IP or exact hostname per line, saved to $DSH_HOME/net-scope-allow.txt
Rule sets multiple AGENTS.md / CLAUDE.md; Enable writes under $DSH_HOME, Delete removes the row
Skills import a zip or folder into this host’s official $DSH_HOME/skills//SKILL.md (web and desktop each use their own home; no drive letter is hardcoded); DSH owns match, load, and /name. You can also delete that folder yourself

Layout

bin/ is the CLI, lib/ is patches and the drill console, presets/redteam/ is the red-team preset, skills/redteam/ is the bundled skills, and client.js is the dock.

Runtime files live under $DSH_HOME: prompt-inject.md, rules/, skills/, net-scope-allow.txt, redteam/. If DSH_HOME is unset, the launcher-adjacent .dsh wins over ~/.dsh. Web and the desktop app each use their own home. Skills are not part of the inject section and do not replace the prompt.


Usage

dsh-purge --status
dsh-purge --apply
dsh-purge --revert
dsh-purge --uninstall
dsh-purge --edit

/purge status | apply | revert | uninstall | edit | help
/rules list | use  | create  | delete  | reset | help
/skills list | import  | create  [description] | delete  | help
/rewind

purge_status   purge_apply   purge_revert

After a successful Apply, the host restarts so patched packages load; you can also click Restart manually. Under the patch title are the stable release and the test release. The test release follows the beta branch. Switch to stable installs master and clears any pin. Picking an older stable version pins it; click Update to return to the latest. Old test tags are not listed.

The composer Undo once and Undo last round stay in the current conversation and do not open a branch. The sent line goes back into the input, and that cut’s already-sent messages and completed tasks leave the current conversation; edit and send again. From 1.1.61, rewind bounds follow the current turn, not the first user message. /rewind does the same.

If the same task works in standard but fails in minimal or PTC, preset run_code, sandbox, or plan intercept text is often still uncleared, or built-in minimal is missing agent-instructions. Use 1.1.61+, then quit the host fully → Apply in Clean → restart → start a new chat. Switching preset alone does not reload patches in the running process.

Response speed

DSH runs Bash calls in a tool batch one at a time. Older dsh-purge releases raised the default foreground wait from 60 seconds to 10 minutes, so one slow command could hold up later calls for that long. Patch #21 now restores marked plugin values to the official 60-second default. Unmarked timeouts and other custom values are preserved; an unmarked 10-minute value cannot reliably be distinguished from a user setting.

For a shorter wait in dsh web on macOS/Linux, add this entry to $DSH_HOME/profiles/web/cordis.patch.yml (normally ~/.dsh/profiles/web/cordis.patch.yml). Edit an existing entry with the same id instead of adding a duplicate. This profile layer is applied after the bundled configuration, so future plugin applies keep the override.

- id: bash-sandbox
  config:
    timeoutMs: 10000

With the standard jobs service and promoteOnTimeout: true, an unfinished command returns a background job id after 10 seconds and keeps running. Read it with job_output or stop it with job_kill. This changes the foreground wait, not the command’s speed. Without that service or with promotion disabled, the timeout kills the command. A per-call timeoutMs overrides this default; run_in_background: true returns a job id immediately.

For routine tasks, you can also opt into Low reasoning for new sessions:

- id: agent-default-model
  config:
    provider: deepseek-official
    model: deepseek-flash
    reasoningEffort: low

Restart dsh web to load the profile. The model and reasoning defaults apply to newly created sessions; select Low in the composer for an existing session. The plugin does not change these model preferences automatically. Keep High when the task needs deeper reasoning, and narrow file searches rather than recursively scanning every application directory.

Own servers

Addresses in mainland China, Hong Kong, and Macau stay forbidden unless that one host was registered first. Saying “this is my server” in chat does not allow it. A key or a password does not allow it either.

The box sits under Prompt. If the dock does not show it yet, quit DeepSeek Harness completely and open it again.

  1. Click dsh-purge beside the session title and stay on Clean.
  2. Scroll past Prompt. Own servers is the next block.
  3. Put one host on each line, in one of these forms:
    • 203.0.113.10 — one IP.
    • my-vps.example.com — one exact hostname. After you save, the addresses that hostname resolves to at lookup time are allowed too.
    • [email protected] — the account only identifies this form. It does not prove the machine is yours.
  4. Click Save list. The list is written to $DSH_HOME/net-scope-allow.txt.
  5. Keys, passwords, ranges, and wildcards are dropped on save. Unlisted mainland China, Hong Kong, and Macau addresses stay forbidden.

203.0.113.10 and example.com above are only examples of the form. Replace them with your own host before you save.


Local checks

npm test
node --check lib/index.js
node --check lib/core.js
node --check lib/surface.js
node --check lib/web.js
node --check lib/desktop.js
node --check lib/host.js
node --check lib/rewind.js
node --check lib/skills.js
node --check client.js

How it works

Apply, on start or when you click Apply:

flowchart TD
  A["Start or click Apply"] --> B{"Patch already in place?"}
  B -->|yes| C["Skip"]
  B -->|no| D["Back up the original as .dshpurge.bak"]
  D --> E["Replace the matched files"]
  E --> F["Override the shim"]
  F --> G["Inject the encrypted prompt shipped in the plugin, the text the prompt box shows by default"]

Override on each session:

flowchart TD
  A["Restart or new session"] --> B["Inject the plugin's encrypted default. No save click, and no host prompt file"]

Prompt injection and ruleset decision at every turn. The three inputs on the left are what you control in the dsh-purge panel; the dotted edges show which decision each one drives:

flowchart TD
  L["Rule library: activate a set → writes prompt-inject.md"]
  W["Local rules: check AGENTS.md / CLAUDE.md in the current dir"]
  P["Workspace policy: strict / fallback / always"]

  A["Turn start"] --> B{"prompt-inject.md non-empty?"}
  B -->|yes| C["Inject = prompt-inject.md (A)"]
  B -->|no| D{"Any checked local md in the current dir, non-empty?"}
  D -->|yes| E["Inject = selected workspace md (B)"]
  D -->|no| F["Inject = plugin encrypted slot default (D)"]
  C --> G{"Workspace baseline policy (C)"}
  E --> G
  F --> G
  G -->|strict| H["Drop DSH workspace baseline section"]
  G -->|fallback default| I{"User inject present above? (A or B)"}
  G -->|always| J["Keep DSH workspace baseline section"]
  I -->|yes| H
  I -->|no| J
  H --> K["Final system prompt"]
  J --> K

  L -.-> B
  W -.-> D
  P -.-> G

Skills stay out of the inject section:

flowchart LR
  A["Settings import or /skills import"] --> B["Write into the official skills directory"]
  B --> C["DSH loads it"]
  C --> D["Uninstall does not delete user skills"]

Restore

  • Each target is copied to .dshpurge.bak before the first apply.
  • Restore or /purge revert copies backups back and deletes them. With no backup, shim lines written by this plugin are stripped.
  • prompt-inject.md is a user file and is kept.
  • Uninstall restores first if patches were applied, then deletes the inject file, rule library, and the plugin itself.
  • Apply is idempotent.

Path detection

The host surface is detected first: web / desktop (gui / tui are reserved and still fall back to web).

Web:

  1. DSH_HOME / DSH_BASE
  2. .dsh next to the dsh launcher (portable install, any drive)
  3. npm prefix -g / npm root -g
  4. Nested @deepseek-ai/dsh/node_modules/@deepseek-ai
  5. ~/.dsh

Official desktop EXE: the running official Harness install (resources/app or the unpacked package). The drive letter is not hard-coded. A successful Apply restarts once.

Community Desktop is not maintained.

Official npm-global is not patched. Sealed host-commands / runtime-commands are scrubbed, never injected.

If nothing is found, set DSH_BASE / DSH_DESKTOP_INSTALL. No files are changed.


Releases

What changed, and the zip, are on Releases. To publish, bump the version in package.json, write Chinese and English notes in release-notes.md, and push master. Pushing the same version again does not publish another package.

Notes

  • Scope is rendered copy, defaults, and runtime logic inside local @deepseek-ai/* packages, plus override files and rule sets under the harness home.
  • After an upgrade, unmatched originals show as skipped. Apply still completes, and those files are left unchanged.
  • Third-party plugin source repos outside @deepseek-ai are left alone (CMD silence may best-effort patch installed doctor / market / liangshen / mnemon at runtime).
  • The npm package name is not published yet. Official Web: dsh plugin --profile web add the master.tar.gz. Official desktop: dsh plugin --profile desktop add the same archive. From this repo, dsh plugin --profile web add . or dsh plugin --profile desktop add .. The Hub page is an introduction only.

Thanks to the LINUX DO community

View this README on GitHub

Recommended Tools

Try a different keyword or remove a filter.

Install

npx skillfish add yujunzhixue/dsh-purge