Zum Hauptinhalt springen

Sicherheit & Berechtigungen

Sicherheit & Berechtigungen-Plugins härten DeepSeek-Harness (dsh) gegen riskante Tool-Aufrufe und bösartige Plugins. Diese Kategorie umfasst richtlinienbasiertes Tool-Gating mit allow/deny/ask-Stufen, Scanner vor der Installation für Plugin-Bundles und npm-Tarballs, Schutz vor Prompt-Injection und Geheimnisabfluss, Telemetrie-Schwärzung und hash-verkettete Audit-Protokolle.

269 Plugins gefunden

G

dsh-agent-loop-guard

goodandready/dsh-agent-loop-guard

Fail-closed runtime tool-call loop guard for DeepSeek Harness.

0vor 3 TagenSicherheit & BerechtigungenMIT
Z

dsh-permission-matrix

zhang8019/dsh-permission-matrix

Turns DSH permissions into 9 selectable presets (3 sandbox modes x 4 approval tiers), with rule plus LLM risk classification across four risk levels, password-gated approval for high-risk operations, and a JSONL audit log.

0vor 22 TagenSicherheit & BerechtigungenMIT
L

dsh-risk-gate

leetom314/dsh-risk-gate

Semantic risk grading and progressive authorization: classifies tool calls into safe/risky/redline, asks before irreversible actions, auto-allows only approved-and-succeeded signatures.

0vor 24 TagenSicherheit & BerechtigungenMIT
A

dsh-workspace-tools

ahiosuz/dsh-workspace-tools

Applies per-workspace default Agent and permission presets to new root sessions automatically (Settings - Workspace defaults), using only official extension points.

0vor 23 TagenSicherheit & BerechtigungenMIT
B

dsh-semgrep-sast

baiiduu/dsh-semgrep-sast

Semgrep SAST bundle and model-facing scan tool for DeepSeek Harness.

0vor 22 TagenSicherheit & BerechtigungenMIT
S

dsh-totp

sodazheng/dsh-totp

TOTP-only access control for personal DeepSeek Harness Web instances, with in-app QR enrollment, single-use recovery codes, live protection controls and lock-all revocation of page access.

0vor 10 TagenSicherheit & BerechtigungenMIT
C

dsh-dolphin-security

ccr-wer/dsh-dolphin-security

此为 DSH 生态插件。Dolphin - 主动巡检型安全防御插件,支持本地扫描与远程 SSH 巡逻。将渗透测试方法论(信息收集→漏洞探测→利用验证→报告)转化为主动防御巡检流程:基于 Semgrep 的扫描层与基于 SSH 的执行层相融合,可对本地目录做静态扫描,也可将扫描命令经 SSH 下发至远程主机执行并回收结构化结果。

0vor 24 TagenSicherheit & Berechtigungen
W

dsh-security-guard

weisofns/dsh-security-guard

DSH plugin security guard: 28-rule static scanner, risk scoring, whitelist/blacklist policy, local web dashboard and in-DSH risk popups.

0vor 22 TagenSicherheit & BerechtigungenMIT
D

dsh-turn-doctor

d3vmeh/dsh-turn-doctor

Explains which layer killed a failed turn: times every model request (first byte, longest silence, total) and combines that with the error to name the culprit (dsh idle watchdog vs Node undici timers vs SDK timer vs server crash, context overflow, gate queue, tool timeouts, failed compactions) and the exact setting to change; verdicts in the DSH terminal plus a /why command, subagents included.

0vor 29 TagenSicherheit & BerechtigungenMIT
U

dsh-plugin-cyrene

under-the-ocean/dsh-plugin-cyrene

昔涟 (Cyrene) 主题 + 桌宠 for the dsh web GUI — pearl-white pink theme, Live2D desktop pet, particle background, gradient, and a collapsible config card. Ported from Cyrene-Agent (MIT) with the Live2D model creator's permission.

0vor 27 TagenSicherheit & BerechtigungenMIT
V

dsh-route-fence-linter

vladimir-kryshchenko/dsh-route-fence-linter

Audits every plugin HTTP route in a profile for a browser-trust fence: plugin routes win the web server's longest-prefix match ahead of the /api gateway, so they never see its trust check and must pin the Host to loopback themselves. Grades PASS/WARN/FAIL per route and fails a fence that compares Origin to Host without pinning it (bypassable by DNS rebinding). Ships as a CLI for CI and a route_fence_scan tool.

0letzten MonatSicherheit & BerechtigungenMIT
R

dsh-security-guard

ruanhaodong-tt/dsh-security-guard

Runtime security guard for DSH: loader import confinement, HTTP Host header validation, and source patch for VM sandbox escapes (4 CVEs). AI-assisted.

0vor 28 TagenSicherheit & BerechtigungenMIT
N

dsh-safe-delete

nattocb/dsh-safe-delete

Tools guard that moves agent-issued `rm` targets to the macOS Trash instead of deleting, with a shell-aware lexer covering compound and disguised commands; a switch in Settings → General turns it off.

0letzten MonatSicherheit & BerechtigungenMIT
G

dsh-shadow-auditor

goodandready/dsh-shadow-auditor

Background security auditor for DeepSeek Harness: scans agent outputs for secret leakage, checks command safety before execution, and surfaces findings in a persistent audit log.

0vor 6 TagenSicherheit & BerechtigungenMIT
D

dsh-plugin-guard

dingzhiqi5596/dsh-plugin-guard

DSH Desktop plugin safety guard: self-repairs plugin load crashes and runs 8 core safety checks (2 optional: deep-config & smoke), prompting you when a plugin changes. Non-commercial source-available.

0letzten MonatSicherheit & Berechtigungen
L

dsh-edit-guardian

lwlaymh/dsh-edit-guardian

File-change diff bar with keep/undo summary, plus dangerous-command approval and red highlighting for bash/pwsh.

0letzten MonatSicherheit & BerechtigungenMIT
G

dsh-completion-guard

greenlv/dsh-completion-guard

Keeps DSH agents from forgetting your requirements during long tasks. It saves important conditions and completion evidence locally, brings them back after context compaction or session resume, and stops partial work from being reported as the whole task done.

0vor 14 StundenSicherheit & BerechtigungenApache-2.0
P

dsh-plugin-windows-guard

pasumao/dsh-plugin-windows-guard

DeepSeek Harness (dsh) Windows 环境防坑守则 skill 插件(纯数据):GBK/BOM/UTF-16 编码坑、PowerShell 引号转义、长路径/文件占用/EACCES、进程与端口、CRLF、stderr 误判、乱码识别——预防性规则,无修复工具。纯技能载体,零运行时依赖,零构建。

0letzten MonatSicherheit & BerechtigungenMIT
G

dsh-checkpoint-memory

gege9527/dsh-checkpoint-memory

Curated file-based long-term memory for DeepSeek Harness — human-readable markdown notes, one plain-file store shared across hosts (git-ignored when it lives inside a project repo), and a deterministic index cap enforced by ctx.tools.guard()

0letzten MonatSicherheit & BerechtigungenMIT
V

dsh-fs-deny-policy

vladlearns/dsh-fs-deny-policy

DeepSeek Harness plugin: a deployment deny list of filesystem roots the model may never touch - fences read, write, search, and shell tool calls at tools/pre-execute

0letzten MonatSicherheit & BerechtigungenMIT
Y

dsh-webgate

yyyq0325-ai/dsh-webgate

Login gate for the DeepSeek Harness web GUI: username/password entry page (DeepSeek style), 12-hour session tokens, slash commands for user management. Background tasks keep running while logged out.

0letzten MonatSicherheit & BerechtigungenMIT
Y

dsh-token-vault

yyfather/dsh-token-vault

Secure credential vault for DeepSeek Harness: store GitHub/npm/API tokens (secrets never leave the host), run gh/npm/npx/node/git with the token injected in the environment, and manage tokens from a Settings page.

0letzten MonatSicherheit & BerechtigungenMIT
D

correctover

dshcorrectover/correctover

AI Agent runtime authorization & evidence verification — tool-call GuardrailProvider, CCS 7-dimension verification standard, MCP/DSH security scanner, SSRF/command-injection/credential-exfil blocking with Ed25519 signed receipts.

0letzten MonatSicherheit & Berechtigungen
W

dsh-permission-workspace-write-plus

wonjader/dsh-permission-workspace-write-plus

deepseek harness中workspace write权限的增强插件。使用前请自行评估风险。

0letzten MonatSicherheit & Berechtigungen