First public release of dsh-redact.
- Agent-scoped, memory-only token vault with stable opaque replacement tokens.
- Canonical
tools/post-executevalue replacement with Harness output-schema revalidation. - Recursive password, secret, token, authorization, webhook, URL-query, private-key, PEM, and JSON-string handling derived from Noval's validated semantics.
- Source-code reference preservation and valid JSON serialization.
- Fail-closed handling for sanitizer faults and immutable sensitive failure fields.
- Privacy-minimal
redaction/appliedSession events containing only count and categories.
See dsh-redact/README.md for the security boundary and deliberate v0.1 exclusions.