api-relay-audit: A Local AI Relay Security Audit Plugin for DeepSeek Harness

toby-bridges/api-relay-audit

Development & OperationsVerified
Listed on 2026-08-25
Page last updated 2026-10-04

A DSH plugin for local security audit of AI API relays and LLM proxies, detecting prompt injection, model substitution, tool-call rewriting, SSE anomalies, and Web3 wallet risks, producing Markdown reports.

api-relay-audit is a local security audit plugin built for DeepSeek Harness, helping you generate a repeatable Markdown audit report before trusting a third-party AI API relay or LLM proxy. It covers prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet risks. All probes run locally, and your API key is sent only to the relay URL you specify. The plugin separates audits into distinct query families to keep evidence boundaries clean, and offers general, full, and web3 profiles for different audit depths.

How to Install

install
dsh plugin --profile web add github:toby-bridges/api-relay-audit
Category
Development & Operations
Platform
DSH Plugin
Author
toby-bridges
Distribution
Plugin

api-relay-audit Key Features

Detect prompt injection/extractionIdentify model substitution signalsAudit tool-call rewritingSpot SSE stream anomaliesGenerate Markdown reports
Listed on dsh-plugin.org

api-relay-audit Repo Summary

What Does It Do?

API Relay Audit is a DSH plugin for DeepSeek Harness that performs local security audits of AI API relays and LLM proxies. It addresses risks like prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet vulnerabilities, enabling you to generate a repeatable Markdown report before trusting a relay with production or wallet-related traffic. Maintained by toby-bridges under the AGPL-3.0 license, it was last updated in August 2026.

Core Features

  • Detect relay tampering: covers prompt injection, prompt extraction, identity consistency, context truncation, tool-call rewriting, error-response leakage, and SSE stream anomalies.
  • Run locally: the standalone script uses only Python stdlib and curl; your API key is sent only to the relay URL you specify.
  • Produce reviewable evidence: each run generates a structured Markdown report with per-step findings and a final LOW / MEDIUM / HIGH verdict.
  • Clear query family boundaries: separates API relay audit, prompt injection audit, model substitution signals, and Web3 relay audit into distinct families to maintain evidence boundaries.
  • Support Web3 scenarios: provides a web3 profile to check wallet-sensitive relay behavior.

How to Use This Plugin?

After enabling it in DSH, run the audit script from the command line, passing your API key, relay URL, and output file path. For example, run a general audit for standard relays or use the web3 profile for wallet-related workflows. The report is generated as a Markdown file with findings for each probe step and an overall risk level. To adjust audit depth, use the general or full profile.

This page is an independent rewrite of the plugin's official README — for authoritative documentation and the latest changes, refer to the source: toby-bridges/api-relay-audit. The plugin is third-party code that runs on your machine once installed; inclusion does not imply endorsement — please review the source before installing.

Install, update, and uninstall this plugin in the Plugin Market of DeepSeek Harness's DSH Plugin Hub

More DSH Plugin articles

View all 1 articles

DSH Plugin FAQ