Model or dataset
Minglink/dsh-infinite-gen-4 avatar
Minglink/dsh-infinite-gen-4

dsh-infinite-gen-4: A DeepSeek Red-Team Plugin for Security Researchers

DeepSeek v4.1 flash 网络安全红队工具(无限四代) — jailbreak prompts and test suite for DeepSeek 求 Star 收藏 ⭐欢迎大家提交项目的改进

2,190 stars188 forksJavaScriptNOASSERTION

At a glance

What is it?
dsh-infinite-gen-4 is an open-source plugin for the DeepSeek Harness desktop client that injects a dual-layer prompt kernel into DeepSeek V4.1 and V4 Flash sessions, producing a test environment for LLM robustness research and authorized red-team assessments. The repository ships the prompt kernels, a deterministic regression test suite, and a one-click install protocol targeting the DeepSeek Harness ecosystem.
Who is it for?
dsh-infinite-gen-4 is appropriate for security researchers and AI safety engineers who need a reproducible red-team baseline for DeepSeek V4.1 and V4 Flash under authorized, controlled conditions. It requires the DeepSeek Harness desktop client and is restricted to offline synthetic targets or authorized lab environments by its own terms.
Can I use it commercially?
Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
Is it still maintained?
Yes. The repository last received commits 2 days ago.
What is it written in?
Mainly JavaScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

Purpose and Scope of the Red-Team Toolkit

dsh-infinite-gen-4 is a network security red-team tool and robustness benchmark suite designed for use against DeepSeek V4.1 and V4 Flash models. The project positions itself in a specific research context: probing an LLM's input escape paths, prompt injection boundaries, and unintended behaviors in a controlled environment so that security teams can identify defensive gaps before real-world adversarial use.

The README states three justifications for this kind of tooling. First, red-team testing exposes model defensive boundaries and feeds back into safety guardrail improvements. Second, a standardized test case collection gives enterprises and security auditors a measurement against which defensive strategies can be evaluated. Third, the project aims to contribute a transparent and reproducible benchmark baseline to academic and security engineering research.

The repository is published under the MIT license and the README includes extensive disclaimers. Use is restricted to offline local synthetic targets, authorized red-team exercise environments, and compliant laboratory settings. The README states that any use in violation of these terms causes the license to terminate immediately. The project is described as independent of DeepSeek's official organization.

The Dual-Layer Kernel Architecture

The v0.4.0 release introduces what the README calls a zero-tool-face architecture combined with a dual-layer cooperative injection kernel. The zero-tool-face design eliminates decision noise from the model's reasoning phase by removing tool interfaces. The dual-layer approach injects at two ordered slots: `infinite-gen-4:global-system-prompt` at order 100 and `infinite-gen-4:dual-layer-reinforce` at order 200.

The `index.js` file controls this injection through a `DUAL_LAYER_INJECTION` switch. Setting it to false converts the plugin to single-segment injection, which the README describes as behaviorally equivalent for most cases.

The `prompts/` directory contains three kernel files: `infinite-gen-3.md` (the classic third-generation kernel), `infinite-gen-4.md` (the fourth-generation general kernel covering output contracts and rejection resistance), and `infinite-gen-4.1-flash.md` (the V4.1 reinforced mirror layer targeting the training-track output path and shallow reasoning). These files are the core research artifacts of the repository.

Installing via the dsh Protocol or Shell Script

The fastest install path requires the DeepSeek Harness official desktop client already installed. The dsh:// URI scheme triggers a one-click install directly from the browser or from a link:

code
dsh://plugin/install?id=dsh-infinite-gen-4&name=%E6%97%A0%E9%99%90%E5%9B%9B%E4%BB%A3&version=0.4.0&repo=Minglink%2Fdsh-infinite-gen-4&permissions=%E7%B3%BB%E7%BB%9F%E6%8F%90%E7%A4%BA%E8%AF%8D%E6%B3%A8%E5%85%A5%2C%E5%AE%A2%E6%88%B7%E7%AB%AF%E7%8A%B6%E6%80%81%E6%9D%A1&downloadUrl=https%3A%2F%2Fgithub.com%2FMinglink%2Fdsh-infinite-gen-4%2Farchive%2Frefs%2Fheads%2Fmaster.zip

For Linux and macOS, a shell installer is included:

bash
./install.sh

For Windows, `install.ps1` and `install.bat` are provided for PowerShell and double-click batch installs respectively. The repository also includes uninstall scripts: `uninstall.ps1` for Windows and `uninstall.sh` for Linux and macOS. These scripts automate environment configuration and protocol registration.

The plugin metadata is declared in `package.json` under the `dsh` key with the id `dsh-infinite-gen-4`, version `0.4.0`, and the permissions `系统提示词注入` (system prompt injection) and `客户端状态条` (client status bar). The plugin ecosystem is at deepseek.stream.

The Regression Test Suite

The repository ships a deterministic regression test suite in `scripts/` and `tests/`. The test runner for the fourth-generation kernel is `verify_prompt_gen4.mjs`, which runs 103 strict assertions against the kernel behavior. A V4.1-specific variant is `verify_prompt_gen41.mjs`. A classic validation script, `verify_prompt.mjs`, covers earlier behavior.

The test case libraries in `tests/` are in JSONL format: `prompt-bank.jsonl` for classic bilingual regression cases, `prompt-bank-gen4.jsonl` for fourth-generation cases, `prompt-bank-gen41.jsonl` for V4.1-specific cases, and `v4pro-benchmark.jsonl` for the V4-Pro evaluation benchmark. The shared scorer in `scripts/lib/scorer.mjs` evaluates responses using a rejection-window scoring algorithm.

To run the fourth-generation regression assertions:

bash
node scripts/verify_prompt_gen4.mjs

The deterministic nature of these tests is central to the tool's stated research purpose: reproducible baselines allow comparisons between model versions and across different defensive configurations.

Comparison with Standard LLM Safety Evaluation

Standard LLM safety evaluation tools such as garak focus on automated red-teaming across a broad range of attack categories using a plugin-based scanner architecture, targeting multiple model providers. dsh-infinite-gen-4 is narrower in scope: it targets DeepSeek V4.1 and V4 Flash specifically, using manually authored prompt kernels delivered through the DeepSeek Harness plugin mechanism rather than an automated scanner.

The architectural difference is meaningful. garak probes models through their standard API endpoints. dsh-infinite-gen-4 operates through system prompt injection at the Harness client level, which requires the Harness desktop app as an intermediary. This limits portability: the tool does not work outside the DeepSeek Harness ecosystem.

The repository also ships a generational comparison table covering what it calls the second, third, and fourth generations of the kernel, documenting changes in tool-face design, memory write primitives, output contracts, and client-side status bar behavior. This kind of versioned comparison is uncommon in publicly released security research tools and is useful for tracking how the kernel has evolved across model updates.

Limitations and Compliance Boundaries

The most significant constraint on this tool is its runtime dependency on the DeepSeek Harness desktop client. The plugin mechanism is specific to that ecosystem. Researchers who want to test DeepSeek models through the official API without the Harness client cannot use this plugin as-is.

The README is explicit that the plugin must not be run against unauthorized targets, production systems, or public online services. The compliance disclaimer names Chinese laws including the Cybersecurity Law and the Data Security Law. Use outside authorized testing environments violates the license terms.

The prompt kernels in `prompts/` are the core research artifacts, and their effectiveness depends on the specific model version they target. The V4.1 kernel is distinct from the V4 general kernel. As DeepSeek releases new model versions or updates safety training, the kernels may require revision to remain useful as research baselines.

The last push to the repository was on 2026-09-23.

Editorial conclusion

dsh-infinite-gen-4 is appropriate for security researchers and AI safety engineers who need a reproducible red-team baseline for DeepSeek V4.1 and V4 Flash under authorized, controlled conditions. It requires the DeepSeek Harness desktop client and is restricted to offline synthetic targets or authorized lab environments by its own terms. Organizations that conduct production LLM security audits against DeepSeek should verify whether their engagement scope permits system prompt injection tooling of this kind before deploying it.

Frequently asked questions

Does dsh-infinite-gen-4 work with DeepSeek models accessed through the API directly?

The README does not document API-direct usage. The plugin operates through the DeepSeek Harness desktop client using system prompt injection at the Harness plugin layer, which requires the client as an intermediary.

What is the dual-layer injection kernel in dsh-infinite-gen-4?

The dual-layer kernel injects at two ordered Harness slots: the global system prompt at order 100 and a reinforcement layer at order 200. It combines a zero-tool-face architecture with a V4.1-specific mirror layer. A switch in index.js converts the plugin to single-segment injection.

How many test assertions does the fourth-generation regression suite include?

The verify_prompt_gen4.mjs runner includes 103 strict assertions for the fourth-generation kernel. A separate V4.1-specific script is also included in the scripts directory.

Official sources

  1. Issues
  2. License: MIT
  3. Minglink/dsh-infinite-gen-4 on GitHub
  4. Project website
  5. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/minglink-dsh-infinite-gen-4.svg)](https://hysenlabs.com/projects/minglink-dsh-infinite-gen-4)