- Home
- Categories
- Security & Permissions
Security & Permissions
Security & Permissions plugins harden DeepSeek-Harness (dsh) against risky tool calls and malicious plugins. This category covers policy-based tool gating with allow/deny/ask tiers, pre-install scanners for plugin bundles and npm tarballs, prompt-injection and secret-exfiltration guards, telemetry redaction, and hash-chained audit trails.
269 plugins found
dsh-defend
perrylink/dsh-defend
Detects prompt-injection, jailbreak, and secret-leak patterns on the agent/pre-step, tools/pre-execute, and tools/post-execute seams with allow/ask/block tiers, sanitized defend/detection audit events, a defend_report tool, and a destructive-delete command guard.
dsh-skill-pack-security
perrylink/dsh-skill-pack-security
Security-audit methodology skill pack plus the plugin_vet supply-chain gate: eight agent skills (secret scan, dependency audit, supply-chain review, prompt-injection review, audit orchestration, threat modeling, vuln intel, incident response) in Chinese and English editions, with an npm provider bundle that mounts the skills and registers the automated plugin_vet pre-install scanner.
agent-guard
mokuyoaxis/agent-guard
Harness-neutral reliability infrastructure for AI coding agents: reversible destructive actions, pre-emission redaction, recovery evidence, and a shared Decision Protocol with optional native adapters.
dsh-auth-gate
tecfancy/dsh-auth-gate
Login gate for the dsh web surface: password or shared-token authentication, session cookies, rate limiting, and a user-management CLI (dsh.bundle manifest since 0.4.1, one-command `dsh plugin add` mounting).
dsh-auto-approve
jiao-xxx/dsh-auto-approve
Adds an `auto` permission preset between workspace-write and danger-full-access: a classifier grants routine sandbox escalations once, while dangerous or uncertain requests still go to a human.
weiwen-law-dsh
shaky77/weiwen-law-dsh
White-box causal guardrail for dsh: every tool call is adjudicated before execution along a deterministic causal logic chain — blocks destructive and credential-file operations, escalates repeated boundary violations, cuts faulting links until verified-fixed, and gives risk verdicts on un-auditable execution; runs fully local with zero API cost, plus 6 white-box self-check tools.
dsh-auth-gateway
xbzbing/dsh-auth-gateway
Password + TOTP two-factor authentication gateway for the dsh web UI: every HTTP request and WebSocket upgrade is refused until login, with per-source lockout, global rate limits and one-time backup codes.
dsh-movein (plugin)
sjh9714/dsh-movein
Fine grained per tool permission rules for DSH at the tools/pre-execute gate, deny and ask lists in Claude Code rule syntax (`Bash(rm -rf:*), Read(_secrets_), mcp__server__tool`), works standalone without migrating.
dsh-security-audit
omdsh-dev/dsh-security-audit
Local security audit: config, plugin origins, sessions, network exposure — read-only redacted risk report.
dsh-mask
perrylink/dsh-mask
PII masking for DeepSeek Harness — anonymizes names, phones, emails, ids, and keys before requests and restores them at the display layer, keeping plaintext out of session logs.
dsh-approve-for-me
timeance/dsh-approve-for-me
Rule-gated automatic approval for DeepSeek Harness sandbox escalations with an optional LLM reviewer and native human fallback.
deepseek-harness-auth
taichuy/deepseek-harness-auth
Fail-closed password authentication proxy bundle for the DeepSeek Harness Web profile
upstream-radar
micromilo/upstream-radar
Watches DSH and plugin releases, retests exact published artifacts in disposable runners, publishes machine-readable compatibility evidence, and reconciles managed issues after fixes.
dsh-vault
ox0400/dsh-vault
Encrypted local credentials vault for the Harness: a web settings page and vault_* tools to store, search and copy passwords, API keys, TOTP secrets and card data, with health audits, expiry rotation, imports/exports and read-only/ask access modes.
dsh-login
islibaodong/dsh-login
Multi-user login gateway for the DSH web UI: the first visit creates the admin account, admins add and manage users in the GUI settings panel, ordinary users see only their own conversations, and unauthenticated visitors are redirected to /login.
project-koma
swnotmetal/project-koma
DeepSeek Harness adapter for Koma Miko Agent Specs.
dsh-auto-approval-llm
cuddly-guacamole/dsh-auto-approval-llm
LLM-assisted auto approval with countdown fallback for the Auto permission preset: static rules, risk tiers, breaker and file audit.
dsh-permgate
mrweicodes/dsh-permgate
Fine-grained permission gateway: per-category tool-call review (outside-workspace directories, commands, file read/write, subagents, repeated actions) with global & per-project allow/deny exceptions, quick-tool defaults, custom rules, a bilingual approval modal with inline diff details, custom rejection reasons and a sandbox-upgrade flow.
dshscan
shaoshi20/dshscan
Security scanner for DSH plugins: static and semantic passes over plugin source, DSH-specific attack-surface rules, npm audit, batch scanning, and an HTML report with per-finding severity and evidence.
dsh-webui-auth
yuuz12/dsh-webui-auth
WebUI authentication enforced at the HTTP/transport layer: four-layer login gate (resources, plugin bundles, /api, WebSocket), server-side sessions with HttpOnly cookies.
cue-skills (cue-omni-reader-guard)
sensedeal/cue-skills
Hardening guard for mcp__omni__parse in DeepSeek Harness: a tools/pre-execute listener that denies private/reserved host URLs (SSRF), enforces an allow-list or ask (consent), and is fail-closed when allowedRoots is empty.
dsh-approval-mode
nevstop-lab/dsh-approval-mode
Adds an approval-mode toggle next to the permission selector: default approval keeps per-call confirmation, bypass approval auto-approves every tool call while staying in Workspace Write.
dsh-riskproof
onlyqzq/dsh-riskproof
Live security beacon for DSH that follows tool activity. Click to view call statistics, risk provenance chains and blocked actions, with read-only task restrictions and tool metadata change detection.
dsh-approval-llm
letter2025/dsh-approval-llm
Model-based permission approval: an approval-request answerer backed by a separate reviewer model.