Skip to main content

Security & Permissions

Security & Permissions plugins harden DeepSeek-Harness (dsh) against risky tool calls and malicious plugins. This category covers policy-based tool gating with allow/deny/ask tiers, pre-install scanners for plugin bundles and npm tarballs, prompt-injection and secret-exfiltration guards, telemetry redaction, and hash-chained audit trails.

269 plugins found

X

dsh-code-scan

xiaohuang-zaianlian/dsh-code-scan

DeepSeek Harness 插件:为 Agent 增加 code_scan 工具,用 semgrep 扫描代码并输出按文件/行号/严重级别分组的中文报告

12 months agoSecurity & PermissionsMIT
0

dsh-codex-approval

040822/dsh-codex-approval

Codex-style approval autopilot for DeepSeek Harness: ordered glob rules (allow/ask/deny) plus an AI risk judge (low/medium/high) mapped through a risk tolerance, as an approval answerer.

12 months agoSecurity & PermissionsMIT
T

dsh-smart-approval

tingrudeng/dsh-smart-approval

Fail-closed LLM-assisted approval reviewer for DeepSeek Harness

12 months agoSecurity & PermissionsMIT
Z

dsh-poison-guard

zoahdev/dsh-poison-guard

Pre-install supply-chain poison scanner for DSH plugins: AST (JS-X-Ray) + deobfuscation + regex heuristics, exits non-zero on findings for CI gating.

12 months agoSecurity & PermissionsMIT
T

dsh-egress-guard

tancheng33/dsh-egress-guard

Runtime security gate on the tool pipeline: denies calls naming hosts outside an egress allowlist, redacts credentials from results at the canonical value rather than only the rendered content, and appends every decision to a JSONL audit log; ships in monitor-only mode.

111 days agoSecurity & PermissionsMIT
S

dsh-code-security

stardustlc666/dsh-code-security

Deterministic code security review: 40+ rules, secret entropy detection, staged-diff review, SARIF export, baseline acceptance, SBOM-lite dependency inventory and health self-check.

113 hours agoSecurity & PermissionsMIT
P

dsh-auto-classifier

pakiknowledge/dsh-auto-classifier

Autonomous permission classifier for the auto preset: tool-scoped allow/deny rules, an LLM semantic judge, and git checkpointing for unattended sessions.

12 months agoSecurity & Permissions
J

secret-guard

johnxu22786/secret-guard

Blocks agents from reading or writing sensitive files (.env, credentials, key material), masks leaked secret-shaped values in tool results, keeps an audit journal, and exposes safe sg_* inspection tools that never print raw values.

13 days agoSecurity & PermissionsMIT
J

safety-net

johnxu22786/safety-net

Destructive-command interception gate for dsh: parses shell semantics, judges risk against 41 built-in rules, and holds irreversible rm -rf, git reset --hard, and git push --force style commands at a confirmation gate.

13 days agoSecurity & PermissionsMIT
D

dsh-plugins (dsh-secret-redactor)

damonkoy/dsh-plugins

Automatic secret redaction in tool results: masks API keys, tokens, JWTs, private keys and configured secrets before the model sees them.

12 months agoSecurity & Permissions
D

dsh-plugins (dsh-approve-for-me)

damonkoy/dsh-plugins

Automated approval review: auto-approve read-only tools, auto-deny dangerous commands, fail-closed policy engine.

12 months agoSecurity & Permissions
B

dsh-plugin-sentinel

botonj/dsh-plugin-sentinel

Static pre-install security auditor for plugin bundles: lifecycle scripts, dynamic execution, credential-exfiltration combos, and patch-layer hazards, with zero dependencies and in-memory tar parsing.

12 months agoSecurity & PermissionsMIT
B

dsh-security-guard

bigclawd/dsh-security-guard

Static and runtime security guard for dsh: rule-based scans for malicious code, prompt injection and token waste, runtime interception of dangerous tool calls, /scan command, plugin_scan tool, web panel, and allowlist.

12 months agoSecurity & PermissionsMIT
A

dsh-auto-reviewer

antarescorn/dsh-auto-reviewer

Codex-style auto-review permission mode: adds an auto-review preset that auto-approves safe sandbox escalations, asks on risky or ambiguous ones, and rejects critical unconfirmed operations.

117 days agoSecurity & PermissionsBSD-3-Clause
M

dsh-approval-comment

mayifei1995/dsh-approval-comment

DSHWeb 审批增强插件:无感替代内置审批窗口,支持「拒绝并附言」,并在拒绝后终止当前回合、让模型重新结合附言思考

12 months agoSecurity & PermissionsMIT
B

dsh-git-guard

bibibala/dsh-git-guard

Git-aware write guard plugin for DeepSeek Harness: blocks whole-file writes that would overwrite the user's uncommitted changes, and reports what happened to protected files at turn end

12 months agoSecurity & PermissionsMIT
B

amber-protocol

bandersnatch0x/amber-protocol

DeepSeek Harness bundle for Amber Protocol governance tools and skills

12 months agoSecurity & PermissionsMIT
T

dsh-governance

tappass/dsh-governance

The authority layer for agentic AI, as a DeepSeek Harness plugin. Governs every tool call against your business rules via the TapPass /v1/govern policy decision point.

12 months agoSecurity & PermissionsMIT
S

dsh-auto-approval-plugin

styxnether/dsh-auto-approval-plugin

A middle permission tier for DeepSeek Harness between workspace-write and danger-full-access: auto-approves harmless commands and operations targeting configured trusted areas, beyond the current workspace.

12 months agoSecurity & PermissionsMIT
L

dsh-guardian

lonelymoon87/dsh-guardian

Adds dangerous-operation policy checks, output redaction, and a security-review workflow.

1last monthSecurity & PermissionsMIT
A

dsh-turn-approval

arrow949/dsh-turn-approval

Turn-scoped “Allow for this task” approvals: automatically allow matching `danger-full-access` escalations only for the current task, then expire.

12 months agoSecurity & PermissionsMIT
O

sandbox-mxc

omdsh-dev/sandbox-mxc

Microsoft cross-platform sandbox support.

1last monthSecurity & Permissions
C

dsh-mcpguard

chenlaoshiyf/dsh-mcpguard

Scans skills and MCP configs for prompt injection, homoglyphs, hidden Unicode, dangerous shell, and credential leaks.

1last monthSecurity & PermissionsMIT
L

dsh-fleet-audit

lesliewylie/dsh-fleet-audit

Read-only agent-fleet credential hygiene audit: credential-file permissions, embedded credentials in git remotes (masked in output), and provider token literal counts; zero-dependency and deterministic.

12 months agoSecurity & PermissionsMIT