Indirect prompt-injection guard for DeepSeek Harness: taints tool output by origin, gates privileged calls that follow untrusted content, and refuses credentials heading off the machine.
Install dsh-taintguard
dsh plugin --profile web add github:sashankh/dsh-taintguard