DeepSeek Harness 破甲:让所有模型都能破甲,不同模型可换不同提示词;默认提示词面向国模「小码酱」。Jailbreak for every model — swap prompts per model. 求 Star 收藏 ⭐ 如要二开,请查看署名要求部分
概要
⚔️ DeepSeek Harness cybersecurity red-team tool (dsh-purge) DeepSeek Harness jailbreak: every model, swap prompts per model. Default prompt for 小码酱. Please star ⭐ If you build on this, see Attribution required. Official dsh web uses profile web. The official desktop EXE (DeepSeek Harness ) uses profile desktop. Install and Apply them separately. This release targets dsh 0.2 only. Older dsh builds need the matching older plugin. Community Desktop is not maintained. Adding the plugin to a profile does not patch the host. Click beside the session title → → . A successful Apply restarts; an unfinished Apply does not. After the restart, start a new chat — that is when the inject enters the session. Node.js . Windows no-flash needs . Do not use the Hub one-click install. Commands are below. If this project helps you, send it over — I'm out here asking~ is a cybersecurity red-team plugin for the official DeepSeek Harness already installed on your machine.
README
⚔️ DeepSeek Harness cybersecurity red-team tool (dsh-purge)
Version 1.1.66
DeepSeek Harness jailbreak: every model, swap prompts per model. Default prompt for 小码酱. Please star ⭐ If you build on this, see Attribution required.
English | 中文
Official Web and the official desktop app are both supported. Official
dsh webuses profileweb. The official desktop EXE (DeepSeek Harness 0.2.0-rc.2) uses profiledesktop. Install and Apply them separately. This release targets dsh 0.2 only. Older dsh builds need the matching older plugin. Community Desktop is not maintained.Adding the plugin to a profile does not patch the host. Click dsh-purge beside the session title → Clean → Apply. A successful Apply restarts; an unfinished Apply does not. After the restart, start a new chat — that is when the inject enters the session.
Node.js ≥18. Windows no-flash needs Node ≥22. Do not use the Hub one-click install. Commands are below.
Contents
- Sponsor
- What this is
- Attribution required
- Supported hosts
- Install
- Preview
- Usage
- Own servers
- How it works
- Restore
- Releases
☕ Sponsor
If this project helps you, send it over — I’m out here asking~
| Asset | Address |
|---|---|
| USDT (TRC20) | TV5ajPkRD8RH623Dx9mqvYZVNN8nPGRKid |
| Solana | 6x16GhRgLVpKFFXaU1seKNdx2rypspSJTL4dbpt6Xpwk |
| Ethereum | 0xB68BD60C0e8c519513B7DF9bB147696815423B3E |
| Bitcoin | bc1qu70yxkrtwnymt8ryluz9x8y8hqzune5340npht |
What this is
dsh-purge is a cybersecurity red-team plugin for the official DeepSeek Harness already installed on your machine. Official Web (dsh web) and the official desktop EXE are both supported. Install and Apply them separately.
Harness does more than forward a prompt. It rewrites prompts, approval gates, sandbox policy, and session migration at runtime. Asking only “will the model answer” treats a host-layer block as a model refusal. This plugin separates those two layers on your own install, for controlled evaluation and for seeing which default policy is too tight.
| You get | What it does |
|---|---|
| dsh-purge dock | A button beside the session title opens the right dock. Two pages: Clean and Drill |
| Clean | Grouped patch status, Apply / Restore / Uninstall, prompt editor, multiple rule sets |
| Drill | Built into the stable release. After authorization: assets, skills, and the local environment. Only for a host you manage, an offline target, or a written authorized exercise |
| Host policy | Default copy, permission policy, and tool limits. Official capabilities stay. No second invented identity |
| On start | Checks and reapplies. After npm overwrites node_modules, you do not hand-edit files |
No hardcoded drive letters. It looks at $DSH_HOME, .dsh next to the dsh launcher, then ~/.dsh. It does not patch the Harness source tree. Apply on the Clean page of dsh-purge is what writes the changes. Identity comes from the encrypted prompt shipped in the plugin, the text the prompt box shows by default. The host prompt file is not read.
It only touches the official @deepseek-ai packages and local config on the user’s machine. It is not a public scanner and not an attack kit for third-party sites. The repo does not ship malware, unauthorized-exploit scripts, or payloads aimed at the public internet.
Non-profit public project. Commercial sale, paid resale, and profit from illegal or gray-market activity are forbidden. For technical reference only.
Attribution required
If you borrow this project’s name, ideas, code, or prompts, you must credit the author and name the source repository: YuJunZhiXue/dsh-purge.
Using them without attribution, hiding the source, or passing them off as your own will be pursued.
Supported hosts
The latest plugin supports dsh 0.2 only — do not apply it to 0.1.x.
- dsh 0.2 (official desktop 0.2.0-rc.2 / official
dsh web): use 1.1.40 or newer. This page installs that line. - dsh 0.1.7 (incl. rc.1 / rc.2): use 1.1.39 or older — pick the tag on Releases.
Unmatched patches stay pending or skipped; nothing is rewritten blindly.
Install
Web and the official desktop EXE are the two maintained hosts. Install and patch each separately, and only the host you actually run.
| What you run | Profile | Command |
|---|---|---|
Official dsh web |
web |
dsh plugin --profile web add |
| Official desktop EXE | desktop |
dsh plugin --profile desktop add |
`` = https://github.com/YuJunZhiXue/dsh-purge/archive/refs/heads/master.tar.gz. If this directory is already a clone, use add . instead of the URL. If dsh is not on PATH, use Manual install.
For the desktop client you can also click the button (dsh:// deep link):
Install in desktop client
Do not use the Hub one-click install or
deepseek.stream/api/plugins/download?...— it runsgit+https://…dsh-purge.gitand fails atgit ls-remote. Use the.tar.gzcommand above. The Hub page is read-only.
After the command: three steps
Adding the plugin to a profile does not patch @deepseek-ai by itself.
- Quit and reopen the host you installed into — stop and restart
dsh web, or quit the desktop tray and reopen that app. - On that host, click dsh-purge beside the session title, then Apply on the Clean page. It is not on the host Settings page.
- A successful Apply restarts once so patches load. It does not restart if it did not finish.
Web controls affect Web only; desktop controls affect the desktop app only. Do not Apply one host from the other.
How to tell it installed
- dsh-purge sits beside the session title, with Apply on its Clean page.
/purge statusin chat printsDSH_HOMEand the patch list — the path should be the home you actually run.- Optional packages that are not installed (liangshen) show as skipped and do not block Apply.
Hand this to an assistant
Paste the block below to a local assistant. It should only run the install command — no disk scan, no other edits, no Apply, no restart.
Manual install
Use this when the command fails or dsh is not on PATH. Edit only the profile for the host you run — do not touch the other, and do not delete existing bundles.
Uninstall
dsh-purge beside the session title → Clean → Uninstall. Confirm the dialog: it reverts any applied patches, restores the original Harness, and restarts the current host.
# or from a terminal / chat
dsh-purge --uninstall
# /purge uninstall
Plugin config lives in cordis.patch.yml (postPrompt is empty by default):
- insert:
- id: dsh-purge
name: 'dsh-purge'
config:
enabled: true
autoApplyOnStart: true
autoUpdateOnStart: false
autoRevertOnMissing: false
verbose: false
postPromptOrder: 5100
postPrompt: ""
Preview
dsh-purge sits beside the session title. It opens a right-hand dock with two pages: Clean and Drill. Switch Light / Ink. Patches are grouped; the count only includes items that actually applied. Rule sets sit in a list above the editor, with Enable and Delete on each row.
The first time you open Drill you read the notice, wait out the countdown, scroll to the end, and check three boxes. Clean does not need that step. Drill is only for a host you manage, an offline target, or an exercise that already has written authorization.
Clean
Drill authorization
Drill
Patches
Own servers
On the Clean page, under Prompt. One host per line, then Save list. Steps are in Own servers.
| Area | What it shows |
|---|---|
| dsh-purge | button beside the session title; opens or collapses the dock |
| Clean | the old Rules page: patches, prompt, rule sets, skills |
| Drill | assets, skills, and environment after authorization. The tab says Unauthorized until then |
| Patches | grouped status, Apply, Restore, or Uninstall |
| Prompt | edit prompt-inject.md as the session override |
| Own servers | one IP or exact hostname per line, saved to $DSH_HOME/net-scope-allow.txt |
| Rule sets | multiple AGENTS.md / CLAUDE.md; Enable writes under $DSH_HOME, Delete removes the row |
| Skills | import a zip or folder into this host’s official $DSH_HOME/skills//SKILL.md (web and desktop each use their own home; no drive letter is hardcoded); DSH owns match, load, and /name. You can also delete that folder yourself |
Layout
bin/ is the CLI, lib/ is patches and the drill console, presets/redteam/ is the red-team preset, skills/redteam/ is the bundled skills, and client.js is the dock.
Runtime files live under $DSH_HOME: prompt-inject.md, rules/, skills/, net-scope-allow.txt, redteam/. If DSH_HOME is unset, the launcher-adjacent .dsh wins over ~/.dsh. Web and the desktop app each use their own home. Skills are not part of the inject section and do not replace the prompt.
Usage
dsh-purge --status
dsh-purge --apply
dsh-purge --revert
dsh-purge --uninstall
dsh-purge --edit
/purge status | apply | revert | uninstall | edit | help
/rules list | use | create | delete | reset | help
/skills list | import | create [description] | delete | help
/rewind
purge_status purge_apply purge_revert
After a successful Apply, the host restarts so patched packages load; you can also click Restart manually. Under the patch title are the stable release and the test release. The test release follows the beta branch. Switch to stable installs master and clears any pin. Picking an older stable version pins it; click Update to return to the latest. Old test tags are not listed.
The composer Undo once and Undo last round stay in the current conversation and do not open a branch. The sent line goes back into the input, and that cut’s already-sent messages and completed tasks leave the current conversation; edit and send again. From 1.1.61, rewind bounds follow the current turn, not the first user message. /rewind does the same.
If the same task works in standard but fails in minimal or PTC, preset run_code, sandbox, or plan intercept text is often still uncleared, or built-in minimal is missing agent-instructions. Use 1.1.61+, then quit the host fully → Apply in Clean → restart → start a new chat. Switching preset alone does not reload patches in the running process.
Response speed
DSH runs Bash calls in a tool batch one at a time. Older dsh-purge releases raised the default foreground wait from 60 seconds to 10 minutes, so one slow command could hold up later calls for that long. Patch #21 now restores marked plugin values to the official 60-second default. Unmarked timeouts and other custom values are preserved; an unmarked 10-minute value cannot reliably be distinguished from a user setting.
For a shorter wait in dsh web on macOS/Linux, add this entry to $DSH_HOME/profiles/web/cordis.patch.yml (normally ~/.dsh/profiles/web/cordis.patch.yml). Edit an existing entry with the same id instead of adding a duplicate. This profile layer is applied after the bundled configuration, so future plugin applies keep the override.
- id: bash-sandbox
config:
timeoutMs: 10000
With the standard jobs service and promoteOnTimeout: true, an unfinished command returns a background job id after 10 seconds and keeps running. Read it with job_output or stop it with job_kill. This changes the foreground wait, not the command’s speed. Without that service or with promotion disabled, the timeout kills the command. A per-call timeoutMs overrides this default; run_in_background: true returns a job id immediately.
For routine tasks, you can also opt into Low reasoning for new sessions:
- id: agent-default-model
config:
provider: deepseek-official
model: deepseek-flash
reasoningEffort: low
Restart dsh web to load the profile. The model and reasoning defaults apply to newly created sessions; select Low in the composer for an existing session. The plugin does not change these model preferences automatically. Keep High when the task needs deeper reasoning, and narrow file searches rather than recursively scanning every application directory.
Own servers
Addresses in mainland China, Hong Kong, and Macau stay forbidden unless that one host was registered first. Saying “this is my server” in chat does not allow it. A key or a password does not allow it either.
The box sits under Prompt. If the dock does not show it yet, quit DeepSeek Harness completely and open it again.
- Click dsh-purge beside the session title and stay on Clean.
- Scroll past Prompt. Own servers is the next block.
- Put one host on each line, in one of these forms:
203.0.113.10— one IP.my-vps.example.com— one exact hostname. After you save, the addresses that hostname resolves to at lookup time are allowed too.[email protected]— the account only identifies this form. It does not prove the machine is yours.
- Click Save list. The list is written to
$DSH_HOME/net-scope-allow.txt. - Keys, passwords, ranges, and wildcards are dropped on save. Unlisted mainland China, Hong Kong, and Macau addresses stay forbidden.
203.0.113.10 and example.com above are only examples of the form. Replace them with your own host before you save.
Local checks
npm test
node --check lib/index.js
node --check lib/core.js
node --check lib/surface.js
node --check lib/web.js
node --check lib/desktop.js
node --check lib/host.js
node --check lib/rewind.js
node --check lib/skills.js
node --check client.js
How it works
Apply, on start or when you click Apply:
flowchart TD
A["Start or click Apply"] --> B{"Patch already in place?"}
B -->|yes| C["Skip"]
B -->|no| D["Back up the original as .dshpurge.bak"]
D --> E["Replace the matched files"]
E --> F["Override the shim"]
F --> G["Inject the encrypted prompt shipped in the plugin, the text the prompt box shows by default"]
Override on each session:
flowchart TD
A["Restart or new session"] --> B["Inject the plugin's encrypted default. No save click, and no host prompt file"]
Prompt injection and ruleset decision at every turn. The three inputs on the left are what you control in the dsh-purge panel; the dotted edges show which decision each one drives:
flowchart TD
L["Rule library: activate a set → writes prompt-inject.md"]
W["Local rules: check AGENTS.md / CLAUDE.md in the current dir"]
P["Workspace policy: strict / fallback / always"]
A["Turn start"] --> B{"prompt-inject.md non-empty?"}
B -->|yes| C["Inject = prompt-inject.md (A)"]
B -->|no| D{"Any checked local md in the current dir, non-empty?"}
D -->|yes| E["Inject = selected workspace md (B)"]
D -->|no| F["Inject = plugin encrypted slot default (D)"]
C --> G{"Workspace baseline policy (C)"}
E --> G
F --> G
G -->|strict| H["Drop DSH workspace baseline section"]
G -->|fallback default| I{"User inject present above? (A or B)"}
G -->|always| J["Keep DSH workspace baseline section"]
I -->|yes| H
I -->|no| J
H --> K["Final system prompt"]
J --> K
L -.-> B
W -.-> D
P -.-> G
Skills stay out of the inject section:
flowchart LR
A["Settings import or /skills import"] --> B["Write into the official skills directory"]
B --> C["DSH loads it"]
C --> D["Uninstall does not delete user skills"]
Restore
- Each target is copied to
.dshpurge.bakbefore the first apply. - Restore or
/purge revertcopies backups back and deletes them. With no backup, shim lines written by this plugin are stripped. prompt-inject.mdis a user file and is kept.- Uninstall restores first if patches were applied, then deletes the inject file, rule library, and the plugin itself.
- Apply is idempotent.
Path detection
The host surface is detected first: web / desktop (gui / tui are reserved and still fall back to web).
Web:
DSH_HOME/DSH_BASE.dshnext to the dsh launcher (portable install, any drive)npm prefix -g/npm root -g- Nested
@deepseek-ai/dsh/node_modules/@deepseek-ai ~/.dsh
Official desktop EXE: the running official Harness install (resources/app or the unpacked package). The drive letter is not hard-coded. A successful Apply restarts once.
Community Desktop is not maintained.
Official npm-global is not patched. Sealed host-commands / runtime-commands are scrubbed, never injected.
If nothing is found, set DSH_BASE / DSH_DESKTOP_INSTALL. No files are changed.
Releases
What changed, and the zip, are on Releases. To publish, bump the version in package.json, write Chinese and English notes in release-notes.md, and push master. Pushing the same version again does not publish another package.
Notes
- Scope is rendered copy, defaults, and runtime logic inside local
@deepseek-ai/*packages, plus override files and rule sets under the harness home. - After an upgrade, unmatched originals show as skipped. Apply still completes, and those files are left unchanged.
- Third-party plugin source repos outside
@deepseek-aiare left alone (CMD silence may best-effort patch installed doctor / market / liangshen / mnemon at runtime). - The npm package name is not published yet. Official Web:
dsh plugin --profile web addthe master.tar.gz. Official desktop:dsh plugin --profile desktop addthe same archive. From this repo,dsh plugin --profile web add .ordsh plugin --profile desktop add .. The Hub page is an introduction only.
Thanks to the LINUX DO community
推奨ツール
別のキーワードを試すか、フィルタを外してください。
インストール
npx skillfish add yujunzhixue/dsh-purge