- Home
- Categories
- Security & Permissions
Security & Permissions
Security & Permissions plugins harden DeepSeek-Harness (dsh) against risky tool calls and malicious plugins. This category covers policy-based tool gating with allow/deny/ask tiers, pre-install scanners for plugin bundles and npm tarballs, prompt-injection and secret-exfiltration guards, telemetry redaction, and hash-chained audit trails.
269 plugins found
dsh-guardian
cdxiaodong/dsh-guardian
Agent security guardrail: intercepts and audits every tool call, requiring human confirmation on sensitive operations.
dsh-lineage
dongsheng123132/dsh-lineage
Content-addressed artifact, fact, action and report lineage for DeepSeek Harness
sandbox-micro
omdsh-dev/sandbox-micro
Support for the microsandbox backend.
qiushi-dsh-evidence-audit
030611/qiushi-dsh-evidence-audit
Appends local hash-chained JSONL receipts for tool results and session events without storing prompts, tool arguments, result text, or raw session IDs.
dsh-action-outbox
jimchen-g/dsh-action-outbox
Stages exact DSH tool calls without dispatch, presents complete canonical arguments in a durable Batch Review Inbox, invalidates approvals after edits or restarts, and commits only a matching SHA-256 digest plus single-use nonce through the normal DSH tool pipeline.
KISS_Law-DSH
shaky77/kiss_law-dsh
English edition of Weiwen's Law (KISS's Law): the first and only domain-agnostic white-box causal adjudication middleware for AI agents. Unlike domain-specific causal-inference tooling (statistics/economics/ML) or evidence-gated agent firewalls, it adjudicates *every* tool call along a deterministic structural causal chain (R->S->D->H->M) before execution - across any domain, with no training or per-domain tuning. It blocks destructive and credential-file operations, escalates repeated boundary violations, cuts faulting links until verified-fixed, and gives risk verdicts on un-auditable execution; runs fully local with zero API cost.
dsh-redteam-mode
jueze-2019/dsh-redteam-mode
DSH RedTeam 模式:一句话拉起红队作战智能体(资产测绘 / 攻击链 / 得分目标 / 报告 / POC 知识库),含四个角色、13 个原生技能与常驻右侧控制台
dsh-secret-scrub
jkt-check/dsh-secret-scrub
Irreversible secret-scrubbing guard: rewrites access keys, bearer tokens, and private key blocks into `[REDACTED:<category>]` placeholders before they reach the session log and the model.
dsh-trust-check
liuwenji007/dsh-trust-check
Static capability disclosure for DeepSeek Harness plugins: a Settings page and CLI that list installed plugins' capabilities, literal destinations, install scripts, and injection shapes (prompt registrations, shipped skill text, bundle patch), each with file:line evidence. Code-determined, reproducible, zero-token. Disclosure only — not a security verdict, never a safety claim.
dsh-sonarqube
maxmilian/dsh-sonarqube
Read-only SonarQube Community Build tools: instance status, project Quality Gate for a branch or pull request, issue and Security Hotspot search, single hotspot detail, and coverage, duplication or caller-selected measures. Issue and hotspot results carry a normalized location with component key, file path, line and text range.
dsh-guardrail
jypjypjypjyp/dsh-guardrail
String-matches tool-call input arguments, blocks dangerous tool calls (deny) or allows them with an injected warning (warn), and ships a full rules-management panel.
dsh-repeat-stop
173787247/dsh-repeat-stop
Hard-stop consecutive identical tool calls after a configurable streak so the agent cannot spin in place.
dsh-full-with-approval
zjuhbh/dsh-full-with-approval
Fourth permission preset for dsh: unconfined, GPU-capable sessions (danger-full-access) with per-operation user approval for writes outside the workspace or to protected paths (.git/**, .env*); implemented purely as a bundle over the official tools/pre-execute ask hook, no core edits.
dsh-guardwall
iiiweiii/dsh-guardwall
Vets local, npm, and GitHub plugin source before installation, blocks configured high-risk tool calls at runtime, audits output secret patterns, and writes HMAC-chained local audit logs.
dsh-plugin-security-review
shanhaifish/dsh-plugin-security-review
Static bundle form of the DSH plugin-install security gate: reviews cordis_define/cordis_run with a fail-safe policy, plus review/audit tools and a browser approval popup (agree / agree+whitelist / reject; agree+whitelist writes the plugin family into tru
dsh-action-outbox
jimchengchina/dsh-action-outbox
Stages exact DSH tool calls without dispatch, presents complete canonical arguments in a durable Batch Review Inbox, invalidates approvals after edits or restarts, and commits only a matching SHA-256 digest plus single-use nonce through the normal DSH tool pipeline.
dsh-web-auth
summersec/dsh-web-auth
Transport-level authentication gate for the DeepSeek Harness Web GUI with server-side sessions, HttpOnly cookies, IP-based login throttling, and an scrypt password CLI.
dsh-cve-audit
sarthak2511/dsh-cve-audit
Live CVE/supply-chain audit for your workspace's own project dependencies (npm/pip/go), backed by OSV.dev, with a `cve_audit` tool plus optional automatic re-scan on lockfile changes.
dsh-permissions
940842546/dsh-permissions
Claude Code-style permission rules engine: hard/deny/ask/allow tiers with a hard tier above full access, workspace-scoped rules, wildcard path protection, and a visual staged editor; rules persist in settings.yaml.
dsh-acp-plugin
agentic-control-plane/dsh-acp-plugin
Agentic Control Plane for DeepSeek Harness — check every tool call against your policies before it runs, and keep a durable record of what was allowed and why.
dsh-plugin-langfuse
linyp/dsh-plugin-langfuse
Langfuse observability for DeepSeek Harness: exports session logs as OpenTelemetry traces (GenAI semantic conventions) to Langfuse's OTLP endpoint
sandbox-nono
omdsh-dev/sandbox-nono
Support for the nono sandbox backend.
dsh-telemetry-redactor
030611/dsh-telemetry-redactor
Redacts supported secret patterns from the `session-telemetry/record` export copy before configured telemetry backends receive it.
dsh-permission-gate
juntiantan/dsh-permission-gate
UI-level access gate + process-wide agent tool brake for DeepSeek Harness: shared session, strict 60-minute idle lock, native settings module. NOT server-side authentication.