DSH Purge Guard Secret Sanitizer & Ephemeral Cleaner

@yujunzhixue/dsh-purge · v1.0.3

An automated cryptographic sanitization and ephemeral cleanup guardian for DeepSeek Harness. Securely shreds temporary secrets, wipes memory key remnants, and clears untracked artifacts.

Data-SanitizationFile-ShredderSecret-PurgeZeroization
GitHub Stars
18 K+
+12.4% this month
Monthly Downloads
71 K+
Monthly registry pulls
Reach Score
97.2/ 100
Top Tier Ecosystem
Runtime
Cordis v3+
Node 18+ / Bun / Deno

Installation & Integration

CLI one-click launch, package managers, and Cordis integration

bash
manager:
$ pnpm add @yujunzhixue/dsh-purge

Architecture

DSH Purge Guard guarantees cryptographically clean teardowns across every agent lifecycle. While executing code refactoring or debugging tasks, autonomous agents frequently unpack sensitive archives, download private repositories, and load API tokens into memory. This plugin implements military-grade data sanitization (compliant with DoD 5220.22-M standards) on the Cordis teardown pipeline. When sessions complete or abort, Purge Guard shreds temporary files with multi-pass random data overwrites, wipes in-memory cryptographic keys, and cleans dangling workspace caches—leaving zero residual artifacts for malicious forensic recovery.

Architectural Principles & Constraints

01
Strict Type Isolation

Guaranteed by TypeScript compile-time contracts, inter-plugin event bus calls enjoy zero-drift safety.

02
Sub-Millisecond Hot Reload

Supports dynamic runtime mounting and graceful unloading without restarting the primary host process.

03
Deterministic State Machine

Embeds multi-phase execution lifecycle guards, preventing context loss during long-horizon reasoning.

04
Zero Native Build Dependencies

Designed for lightweight cross-platform environments, booting instantly across Node.js, Bun, and Deno.

Core Features

01
Multi-Pass File Shredding: Overwrites disk sectors with random noise to prevent forensic recovery
02
In-Memory Secret Zeroization: Actively clears sensitive buffer allocations before garbage collection
03
Pristine Git Workspace Reversion: Cleans untracked test fixtures and build caches automatically
04
Cryptographic Clean Certificate: Produces signed SHA-256 audit logs proving verified disposal

Core Workflow

01

Lifecycle Teardown Interception

Hooks process termination or failure signals, cataloging ephemeral workspace paths.

02

Secret Footprint Audit

Scans workspace directories, git staging, and stdout logs for lingering credentials.

03

Multi-Pass Secure Shredding

Applies multi-pass pseudorandom byte overwrites before unlinking files from disk.

04

Purge Attestation Archival

Generates a signed cryptographic sanitization certificate for compliance auditing.

Configuration Parameters Reference (YAML / JSON)

ParameterTypeDefaultDescription
shredPassesnumber3Number of random overwrite passes per file
cleanUntrackedGitbooleantrueDeeply restore git state with `git clean -fdx`
generateCertbooleantrueGenerate cryptographic sanitization cert

Use Cases

Enterprise Production Agent

Relies on microkernel lifecycle guards and fault-tolerant state machines for continuous reliability.

SWE-bench Benchmark Evaluation

Native integration with SWE-bench workflows, automatically capturing diffs and verification metrics.

Autonomous Code Refactoring

Separates reasoning from tool actions to independently locate and refactor multi-file codebases.

Cross-Tool Workflow Automation

Safely orchestrates events across sandboxes to seamlessly link enterprise developer tooling.

Best Practices

01
Sandbox Permission Guard

Strictly isolate sub-process calls and network scope; deploy within Docker containers in production.

02
Exponential Backoff Retries

Configure adaptive exponential retries with strict timeouts to mitigate upstream model rate limits.

03
Session State Checkpointing

Persist state machine snapshots to survive hardware interruptions and resume instantly without loss.

04
Full Trajectory Audit Logs

Enable full trace logging, aggregating reasoning thought streams and tool I/O into your observability hub.

FAQ

Q1:How to handle timeouts in long-running autonomous tasks?

Increase the timeout parameter inside your YAML configuration and dispatch periodic heartbeat signals across the Cordis event bus. For long-running tool execution and model reasoning, configure persistent session snapshotting so suspended tasks can safely resume their exact context after interruptions, preventing the kernel from recycling active agent sessions prematurely.

Q2:How to capture and stream the model reasoning thought process?

The harness runtime natively provides end-to-end streaming hooks while its state machine automatically intercepts and strips <think> reasoning tags from model responses. Subscribe directly to the onThink event listener to consume live reasoning token streams in real-time, delivering typewriter animation to the user interface while persisting full trajectories for audit compliance.

Q3:How to resolve dependency conflicts across multiple plugins?

Cordis microkernel uses directed acyclic graph topological sorting to dynamically resolve plugin dependencies. When shared services or runtime versions conflict, assign distinct isolated namespaces at the application entrypoint. Leveraging context injection alongside lazy activation ensures dependencies load strictly on-demand when tools are triggered, maintaining system stability and preventing memory bloat.

Q4:How to enforce permissions and sandbox isolation in production?

Combine isolated container sandboxing with fine-grained capability checks to prevent plugins from accessing sensitive files or unauthorized external networks. Enforce explicit runtime system call whitelisting through the microkernel, executing all third-party tool scripts inside isolated ephemeral containers to block arbitrary code execution and eliminate security privilege escalation risks entirely.

Recommended Ecosystem Plugins

Explore related Cordis extensions designed to work synergistically