Skip to main content

Security & Permissions

Security & Permissions plugins harden DeepSeek-Harness (dsh) against risky tool calls and malicious plugins. This category covers policy-based tool gating with allow/deny/ask tiers, pre-install scanners for plugin bundles and npm tarballs, prompt-injection and secret-exfiltration guards, telemetry redaction, and hash-chained audit trails.

269 plugins found

A

dsh-agentvalet

agentvalet/dsh-agentvalet

Governed platform access for DeepSeek Harness — no credential on the machine

0last monthSecurity & PermissionsMIT
T

dsh-dros-vajraclaw

top-celestial-company-ltd/dsh-dros-vajraclaw

Local tool-call failsafe for DSH: blocks a fixed list of high-risk shell patterns and credential-file reads before execution, with a per-session hash-linked JSONL audit log, and an optional external Gateway for centralized policy.

011 days agoSecurity & Permissions
X

enterprise-compliance

xiaoliang2/enterprise-compliance

Enterprise compliance for DeepSeek Harness — SOC2/GDPR automated checks, sensitive-info redaction, and a redacted tool audit trail. · DSH 企业级合规插件:SOC2/GDPR 自动化合规自检、敏感信息拦截与脱敏、操作日志审计追溯。

0last monthSecurity & PermissionsMIT
T

capmark

taltara/capmark

Hold a DeepSeek Harness agent to a capmark capability manifest: mask its tools and judge every call.

0last monthSecurity & PermissionsMIT
J

faultseed (dsh)

jw53222/faultseed

Honesty guardrails on the tool pipeline: blocks a coding agent from weakening tests, swallowing errors, stubbing type checks, or deleting tests through the shell — nine deterministic hooks, each backed by a planted-failure test proving the guard can fail.

0last monthSecurity & PermissionsMIT
D

dsh-supervisor

docjlm/dsh-supervisor

Lifecycle supervision, evidence-driven audit subagents, safe intervention, and blind acceptance gates for DeepSeek Harness

0last monthSecurity & PermissionsMIT
S

dsh-taintguard

sashankh/dsh-taintguard

Taints the agent when tool results carry untrusted content, gates the privileged calls that follow, and refuses credentials passed to network-capable tools in every mode.

02 months agoSecurity & PermissionsMIT
Z

dsh-safeguard

zhijiangtang/dsh-safeguard

Pre-execution guardrail: vetoes dangerous shell commands and blocks secret/credential leaks before they run.

02 months agoSecurity & PermissionsMIT
J

dsh-timeout-auto-reject

jiesou/dsh-timeout-auto-reject

Auto-reject unanswered permission requests with a model-visible timeout notice

02 months agoSecurity & PermissionsMIT
C

dsh-netguard

charlotten7/dsh-netguard

Egress policy for DeepSeek Harness: a host allowlist on web_fetch and web_search enforced at connect time, audit-mode by default, with OCSF Network Activity records

02 months agoSecurity & PermissionsMIT
J

dsh-managed-approval

jalllychun/dsh-managed-approval

Codex-inspired managed approval for DeepSeek Harness: risk-based MCP review, one-time grants, explicit denials, and human fallback on reviewer failure.

02 months agoSecurity & PermissionsMIT
R

dsh-password-shield

ruby1304/dsh-password-shield

Silence Chrome/iCloud password-manager prompts over DeepSeek Harness API-key inputs: rewrites password-type secret fields into masked text fields so browser password managers never treat DSH API keys as account passwords.

02 months agoSecurity & PermissionsMIT
H

dsh-file-confirm

hfh1999/dsh-file-confirm

文件改动确认机制(双面插件):write/edit/str_replace_editor 写入前弹出确认条,内嵌 GitHub 风格 diff(行号 + 红删绿增),允许本次 / 拒绝。File-change confirmation with inline diff for DeepSeek Harness.

02 months agoSecurity & PermissionsMIT
C

dsh-ocsf-forwarder

charlotten7/dsh-ocsf-forwarder

Read-side SIEM forwarder for DeepSeek Harness: normalises session activity to OCSF and ships it

02 months agoSecurity & PermissionsMIT
C

dsh-dlp

charlotten7/dsh-dlp

Data-loss-prevention plugin for DeepSeek Harness: a non-configurable tool guard floor, tool-result redaction, and fail-closed telemetry redaction

02 months agoSecurity & PermissionsMIT
K

dsh-accounts

kangshifu1/dsh-accounts

DSH 多租户账户与授权插件:PostgreSQL 存储 + admin 管理 API + 每账户独立工作目录(独立插件,不改 DSH 核心)

02 months agoSecurity & Permissions
R

dsh-login

ravenli059/dsh-login

Password gate for dsh-web: opening the web port requires a username/password login; account credentials are stored salted+scrypt-hashed and AES-256-GCM encrypted in a local config file under $DSH_HOME. Host-only cordis plugin, no dsh source changes.

02 months agoSecurity & PermissionsMIT
M

dsh-lan-gate

maxesisnclaw/dsh-lan-gate

Password + CIDR gate for DeepSeek Harness web / DeepSeek Harness 局域网密码门禁

02 months agoSecurity & PermissionsMIT
T

dsh-credentials-vault

tancheng33/dsh-credentials-vault

HashiCorp Vault backend for the credential seam: KV v2/v1, AppRole machine auth, per-operation reads so rotation needs no restart, and compare-and-swap writes.

02 months agoSecurity & PermissionsMIT
T

dsh-code-runtime-container

tancheng33/dsh-code-runtime-container

Container-isolated backend for the `ctx.codeRuntime` seam: each Code Mode program runs in a fresh container with no network, a read-only rootfs, dropped capabilities, and kernel-enforced memory, CPU and pid ceilings.

02 months agoSecurity & PermissionsMIT
S

dsh-risk-guard

shuxue6662-a11y/dsh-risk-guard

Zero-interruption audit and fuse blocking for DeepSeek Harness: silently records every tool call with deterministic risk scoring, cumulative-risk bonuses, risk-level breakdowns and retention-based cleanup; blocks irreversible catastrophes (protected-path deletion, disk wipe, force-push to protected branches/refs, credential exfiltration), and renders a redacted /risk-guard operation bill with --since filtering.

02 months agoSecurity & PermissionsMIT
P

dsh-plugin-judge

pengxuding/dsh-plugin-judge

Plugin value auditor: pre-install review (source scan + LLM judge) and post-install audit of installed bundles, with model-switch re-audit reminders.

02 months agoSecurity & PermissionsMIT
8

dsh-plugin-gate

863683348/dsh-plugin-gate

Installation safety gate for DSH plugins: antivirus-style scan of install scripts, permissions, secrets and network callbacks on local directories or npm tarballs, returning a BLOCK/WARN/PASS verdict before "dsh plugin add".

022 days agoSecurity & PermissionsMIT
8

dsh-gov

863683348/dsh-gov

Agent governance suite: policy-based tool gating (allow/deny/ask with wildcards and priorities), a structured JSONL audit trail, and per-agent token quotas against the host token meter, with state under $DSH_HOME/gov.

022 days agoSecurity & PermissionsMIT