Skip to main content

Security & Permissions

Security & Permissions plugins harden DeepSeek-Harness (dsh) against risky tool calls and malicious plugins. This category covers policy-based tool gating with allow/deny/ask tiers, pre-install scanners for plugin bundles and npm tarballs, prompt-injection and secret-exfiltration guards, telemetry redaction, and hash-chained audit trails.

269 plugins found

G

dsh-agent-loop-guard

goodandready/dsh-agent-loop-guard

Fail-closed runtime tool-call loop guard for DeepSeek Harness.

03 days agoSecurity & PermissionsMIT
Z

dsh-permission-matrix

zhang8019/dsh-permission-matrix

Turns DSH permissions into 9 selectable presets (3 sandbox modes x 4 approval tiers), with rule plus LLM risk classification across four risk levels, password-gated approval for high-risk operations, and a JSONL audit log.

022 days agoSecurity & PermissionsMIT
L

dsh-risk-gate

leetom314/dsh-risk-gate

Semantic risk grading and progressive authorization: classifies tool calls into safe/risky/redline, asks before irreversible actions, auto-allows only approved-and-succeeded signatures.

025 days agoSecurity & PermissionsMIT
A

dsh-workspace-tools

ahiosuz/dsh-workspace-tools

Applies per-workspace default Agent and permission presets to new root sessions automatically (Settings - Workspace defaults), using only official extension points.

023 days agoSecurity & PermissionsMIT
B

dsh-semgrep-sast

baiiduu/dsh-semgrep-sast

Semgrep SAST bundle and model-facing scan tool for DeepSeek Harness.

022 days agoSecurity & PermissionsMIT
S

dsh-totp

sodazheng/dsh-totp

TOTP-only access control for personal DeepSeek Harness Web instances, with in-app QR enrollment, single-use recovery codes, live protection controls and lock-all revocation of page access.

010 days agoSecurity & PermissionsMIT
C

dsh-dolphin-security

ccr-wer/dsh-dolphin-security

此为 DSH 生态插件。Dolphin - 主动巡检型安全防御插件,支持本地扫描与远程 SSH 巡逻。将渗透测试方法论(信息收集→漏洞探测→利用验证→报告)转化为主动防御巡检流程:基于 Semgrep 的扫描层与基于 SSH 的执行层相融合,可对本地目录做静态扫描,也可将扫描命令经 SSH 下发至远程主机执行并回收结构化结果。

024 days agoSecurity & Permissions
W

dsh-security-guard

weisofns/dsh-security-guard

DSH plugin security guard: 28-rule static scanner, risk scoring, whitelist/blacklist policy, local web dashboard and in-DSH risk popups.

023 days agoSecurity & PermissionsMIT
D

dsh-turn-doctor

d3vmeh/dsh-turn-doctor

Explains which layer killed a failed turn: times every model request (first byte, longest silence, total) and combines that with the error to name the culprit (dsh idle watchdog vs Node undici timers vs SDK timer vs server crash, context overflow, gate queue, tool timeouts, failed compactions) and the exact setting to change; verdicts in the DSH terminal plus a /why command, subagents included.

029 days agoSecurity & PermissionsMIT
U

dsh-plugin-cyrene

under-the-ocean/dsh-plugin-cyrene

昔涟 (Cyrene) 主题 + 桌宠 for the dsh web GUI — pearl-white pink theme, Live2D desktop pet, particle background, gradient, and a collapsible config card. Ported from Cyrene-Agent (MIT) with the Live2D model creator's permission.

028 days agoSecurity & PermissionsMIT
V

dsh-route-fence-linter

vladimir-kryshchenko/dsh-route-fence-linter

Audits every plugin HTTP route in a profile for a browser-trust fence: plugin routes win the web server's longest-prefix match ahead of the /api gateway, so they never see its trust check and must pin the Host to loopback themselves. Grades PASS/WARN/FAIL per route and fails a fence that compares Origin to Host without pinning it (bypassable by DNS rebinding). Ships as a CLI for CI and a route_fence_scan tool.

0last monthSecurity & PermissionsMIT
R

dsh-security-guard

ruanhaodong-tt/dsh-security-guard

Runtime security guard for DSH: loader import confinement, HTTP Host header validation, and source patch for VM sandbox escapes (4 CVEs). AI-assisted.

028 days agoSecurity & PermissionsMIT
N

dsh-safe-delete

nattocb/dsh-safe-delete

Tools guard that moves agent-issued `rm` targets to the macOS Trash instead of deleting, with a shell-aware lexer covering compound and disguised commands; a switch in Settings → General turns it off.

0last monthSecurity & PermissionsMIT
G

dsh-shadow-auditor

goodandready/dsh-shadow-auditor

Background security auditor for DeepSeek Harness: scans agent outputs for secret leakage, checks command safety before execution, and surfaces findings in a persistent audit log.

06 days agoSecurity & PermissionsMIT
D

dsh-plugin-guard

dingzhiqi5596/dsh-plugin-guard

DSH Desktop plugin safety guard: self-repairs plugin load crashes and runs 8 core safety checks (2 optional: deep-config & smoke), prompting you when a plugin changes. Non-commercial source-available.

0last monthSecurity & Permissions
L

dsh-edit-guardian

lwlaymh/dsh-edit-guardian

File-change diff bar with keep/undo summary, plus dangerous-command approval and red highlighting for bash/pwsh.

0last monthSecurity & PermissionsMIT
G

dsh-completion-guard

greenlv/dsh-completion-guard

Keeps DSH agents from forgetting your requirements during long tasks. It saves important conditions and completion evidence locally, brings them back after context compaction or session resume, and stops partial work from being reported as the whole task done.

015 hours agoSecurity & PermissionsApache-2.0
P

dsh-plugin-windows-guard

pasumao/dsh-plugin-windows-guard

DeepSeek Harness (dsh) Windows 环境防坑守则 skill 插件(纯数据):GBK/BOM/UTF-16 编码坑、PowerShell 引号转义、长路径/文件占用/EACCES、进程与端口、CRLF、stderr 误判、乱码识别——预防性规则,无修复工具。纯技能载体,零运行时依赖,零构建。

0last monthSecurity & PermissionsMIT
G

dsh-checkpoint-memory

gege9527/dsh-checkpoint-memory

Curated file-based long-term memory for DeepSeek Harness — human-readable markdown notes, one plain-file store shared across hosts (git-ignored when it lives inside a project repo), and a deterministic index cap enforced by ctx.tools.guard()

0last monthSecurity & PermissionsMIT
V

dsh-fs-deny-policy

vladlearns/dsh-fs-deny-policy

DeepSeek Harness plugin: a deployment deny list of filesystem roots the model may never touch - fences read, write, search, and shell tool calls at tools/pre-execute

0last monthSecurity & PermissionsMIT
Y

dsh-webgate

yyyq0325-ai/dsh-webgate

Login gate for the DeepSeek Harness web GUI: username/password entry page (DeepSeek style), 12-hour session tokens, slash commands for user management. Background tasks keep running while logged out.

0last monthSecurity & PermissionsMIT
Y

dsh-token-vault

yyfather/dsh-token-vault

Secure credential vault for DeepSeek Harness: store GitHub/npm/API tokens (secrets never leave the host), run gh/npm/npx/node/git with the token injected in the environment, and manage tokens from a Settings page.

0last monthSecurity & PermissionsMIT
D

correctover

dshcorrectover/correctover

AI Agent runtime authorization & evidence verification — tool-call GuardrailProvider, CCS 7-dimension verification standard, MCP/DSH security scanner, SSRF/command-injection/credential-exfil blocking with Ed25519 signed receipts.

0last monthSecurity & Permissions
W

dsh-permission-workspace-write-plus

wonjader/dsh-permission-workspace-write-plus

deepseek harness中workspace write权限的增强插件。使用前请自行评估风险。

0last monthSecurity & Permissions