Skip to main content

Security & Permissions

Security & Permissions plugins harden DeepSeek-Harness (dsh) against risky tool calls and malicious plugins. This category covers policy-based tool gating with allow/deny/ask tiers, pre-install scanners for plugin bundles and npm tarballs, prompt-injection and secret-exfiltration guards, telemetry redaction, and hash-chained audit trails.

269 plugins found

M

dsh-plugin-trustlens

mengshang-spec/dsh-plugin-trustlens

Read-only DSH plugin auditor with static scanning, current-session model review, and confirmation gates.

1last monthSecurity & PermissionsMIT
X

dsh-full-access-switch

xtd1145/dsh-full-access-switch

One-time Full access switch for DeepSeek Harness: new sessions (workspaces and conversations) start with danger-full-access and skip the per-session Full access confirmation; installable as a dsh bundle or via patch scripts.

1last monthSecurity & PermissionsMIT
W

dsh-feishu-channel

wyattjhayes/dsh-feishu-channel

Security-focused Feishu (Lark) channel for DeepSeek Harness: allowlisted remote-agent access with workspace-scoped paths, symlink checks, risk-based approvals, session isolation, redacted logs, and bounded message queues.

1last monthSecurity & PermissionsMIT
L

dsh-hawkeye-scan (npm)

liuqingman/dsh-hawkeye-scan

AI-driven source-code security scanning workbench: 5 model tools (start/finding/status/report/list) plus a /hawkeye web UI and JSON/Markdown/HTML vulnerability reports; zero-dependency Cordis plugin, installable as agent preset or npm package.

1last monthSecurity & PermissionsMIT
A

dsh-llm-approve-for-me

alaxrpg/dsh-llm-approve-for-me

Uses an isolated LLM review to approve or reject DSH sandbox permission requests.

125 days agoSecurity & PermissionsMIT
T

dsh-plugin-guard

taxueseek/dsh-plugin-guard

Static-only plugin gate and clinic for DSH: audit before install, hash-and-capability lock after install, local fingerprint peer search over GitHub topic:dsh-plugin, and mechanical detox. Never executes the target plugin.

1last monthSecurity & PermissionsMIT
A

dsh-auto-review

accpowered/dsh-auto-review

LLM approval answerer for sandbox escalations beyond workspace-write: a deterministic regex filter first, then a clean-context reviewer model; humans are asked only when it is unsure. Requires the bundled core patches.

1last monthSecurity & PermissionsMIT
A

dsh-credential-manager

accpowered/dsh-credential-manager

Named user credentials the model uses by reference: values are entered on a Settings → Credentials page and injected into each shell execution as DSH_CM_* variables instead of being printed into the transcript, with credential_read as the documented last resort.

114 days agoSecurity & PermissionsMIT
G

dsh-compaction-audit

gendui123/dsh-compaction-audit

Compaction quality / hallucination detector: when a conversation span is compacted, check on two axes that key information survived 鈥?FIDELITY (assertions in the summary must be found verbatim in the original leaf events, else flagged as fabricated) and C

1last monthSecurity & PermissionsMIT
G

dsh-compaction-probe

gendui123/dsh-compaction-probe

Step-0 observation probe for dsh-compaction-audit: logs every compaction/* session event and probes whether shadowedSeqs still resolve to readable events in session.events. Observe-only; never injects, never blocks.

1last monthSecurity & PermissionsMIT
G

dsh-plan-adversarial

gendui123/dsh-plan-adversarial

Command-triggered red/blue adversarial review for ANY plan (not quant-specific). /plan-adversarial <plan>: arms a gate that requires the agent to derive two independent subagents (red=attack, blue=defend), have them converge on a consensus plan with NO th

1last monthSecurity & PermissionsMIT
A

dsh-todo-guard

a903067276-rgb/dsh-todo-guard

Reliable todo panel that survives restarts (official panel only re-renders on write — fixed via projection pre-warm) with three-state completion verification: evidence exists → verified, fake evidence → blocked, no evidence → unverified badge; settings toggle to fall back to official behavior.

1last monthSecurity & PermissionsMIT
K

dsh-skill-security-inspector

kakapengta/dsh-skill-security-inspector

一个可直接链接到 DeepSeek Harness(DSH)Web profile 的独立安全检查插件。在安装或使用不受信任的 Skill 前,先执行浏览器本地粗检,再由用户决定是否调用 DSH 已配置的大模型进行结构化复核。

1last monthSecurity & Permissions
M

forge

mjxupup/forge

Forge quality gates for DeepSeek Harness (dsh): task gates, read-before-edit, bash hazard interception and quality scoring, driven by the forge CLI through DSH's typed interception points.

1last monthSecurity & PermissionsApache-2.0
S

dsh-guardian-approval

scotlight/dsh-guardian-approval

Independent Codex Guardian-style approval reviewer for DSH.

1last monthSecurity & PermissionsMIT
N

nexusclaw-agent-governance

nexusclawhq/nexusclaw-agent-governance

DeepSeek Harness (dsh) approval answerer backed by the agent-governance sidecar — every approval/request is decided by the deny-by-default gate, L0–L4 rules and the organizational audit chain.

1last monthSecurity & PermissionsApache-2.0
D

dsh-provenance

darren-tang/dsh-provenance

Pre-install supply-chain checks for DeepSeek Harness plugins: verify the tarball you are about to install matches the source you read, before any code runs.

1last monthSecurity & PermissionsMIT
A

dsh-Almost_Full_Access

alnita-m/dsh-almost_full_access

Permission mode between workspace-write and full access: shell commands are checked by deterministic rules and a subagent review; irreversible or system-level actions require explicit approval.

123 days agoSecurity & PermissionsMIT
A

dsh-perm-guard

a903067276-rgb/dsh-perm-guard

Auto-approval permission guard: a middle tier between workspace-write and danger-full-access — auto-allows safe operations inside trust directories, always asks a human for destructive ones, with 11 per-category switches and an audit trail.

12 days agoSecurity & PermissionsMIT
C

dsh-write-gate

couldbeme/dsh-write-gate

Commitment write-gate: operator-authored rules enforced before a tool call runs — a deterministic guard tier plus an LLM-judge tier, fail-closed by default, every block written to a contradictions log.

1last monthSecurity & PermissionsMIT
R

skill-security-guard

rrrrrredy/skill-security-guard

DeepSeek Harness community Bundle for the skill-security-guard static scanner

12 months agoSecurity & PermissionsMIT
B

dsh-access-gate

bamboostrip/dsh-access-gate

DSH plugin: password gate for remote (non-loopback) /api access (passwordless by default), unblock the loopback-pinned privileged endpoints, restore everything on uninstall, and give the local 127.0.0.1 user the native OS folder picker for workspace selec

12 months agoSecurity & PermissionsMIT
A

dsh-safety-net

asuna486-desuwa/dsh-safety-net

Self-protection guardrails for the DeepSeek Harness: protected-path interception, backup-before-destroy, CLI self-recovery commands, and strict sandbox defaulting

12 months agoSecurity & PermissionsMIT
O

riskproof

onlyqzq/riskproof

Provenance-aware execution security for DeepSeek Harness. Track sensitive data across tool calls and stop risky side effects before execution.

12 months agoSecurity & PermissionsApache-2.0