Skip to main content

Security & Permissions

Security & Permissions plugins harden DeepSeek-Harness (dsh) against risky tool calls and malicious plugins. This category covers policy-based tool gating with allow/deny/ask tiers, pre-install scanners for plugin bundles and npm tarballs, prompt-injection and secret-exfiltration guards, telemetry redaction, and hash-chained audit trails.

269 plugins found

0

dsh-ui-auth

0qwq0/dsh-ui-auth

Authentication gate for the DeepSeek Harness Web UI: the login gate covers pages, /api, /plugins and WebSocket upgrades; PBKDF2 password hashing, HttpOnly SameSite session cookies and IP-based login lockout; invite-code registration; two-factor login with TOTP or passkeys (WebAuthn: several keys per account, phone enrolment by QR, username-less sign-in, and a password or second-factor step-up before any login factor is added or removed); a user-management settings panel (users edit their own profile and manage their own TOTP and passkeys, admins add or remove users, reset passwords, manage invites and clear the passkeys of a lost device); admin-only model and API-key configuration guards; per-user isolation on the REST/list APIs and on the WebSocket event streams; session persistence across restarts; a JSONL audit log; and a fail-closed gateway. Runs on both DSH transport lines (0.1.1-rc.2 legacy and 0.1.2+ modern) with no configuration; passkey login needs a localhost or HTTPS origin because browsers require a secure context.

62 days agoSecurity & PermissionsMIT
L

dsh-automode

log-li/dsh-automode

CC-style auto-approval for DeepSeek Harness: deterministic deny/allow rules plus a two-stage allow/reject classifier with a circuit breaker and denial guidance.

65 days agoSecurity & PermissionsMIT
G

dsh-multi-tenant

guomonth/dsh-multi-tenant

Multi-tenant primitives for DeepSeek Harness (DSH): tenant identity, immutable session ownership, fail-closed authorization, and a replaceable ownership-store contract.

6last monthSecurity & PermissionsMIT
H

dsh-auth

hxy91819/dsh-auth

Caddy forward_auth administrator login for DeepSeek Harness Web, with Argon2id passwords, revocable sessions, bilingual UI, and a native sidebar sign-out action.

612 days agoSecurity & PermissionsMIT
Y

dsh-encrypt

yauntyour/dsh-encrypt

Credential provider for DSH with password-protected AES-256-GCM storage, Argon2id key derivation (legacy scrypt v2 auto-upgrade), SHA3-256 integrity checks, and temporary runtime decryption.

62 months agoSecurity & PermissionsMIT
S

dsh-auto

simon300000/dsh-auto

Adds an Auto Approve permission preset to the Web UI, using a fresh restricted Reviewer Agent to allow or deny each approval request.

622 days agoSecurity & PermissionsMIT
B

dsh-pause

better-er/dsh-pause

DSH Web 暂停插件:agent 完成一轮工具交互、正要发出下一次模型请求之前暂停,保持 composer 输入框可用,人类以回车/发送放行并可携带补充文字;此暂停不打断任何在途 API 调用,模型上下文始终完整、无感知。纯插件自包含,不改 DSH 源码。

522 days agoSecurity & PermissionsMIT
Y

dsh-workspace-write-plus

yzxxy010/dsh-workspace-write-plus

Adds a workspace-write++ permission that keeps file tools inside the workspace while skipping the Windows process sandbox for wildcard-allowlisted executables such as Git Bash.

526 days agoSecurity & PermissionsMIT
N

npm-safe-fordsh

nisconder/npm-safe-fordsh

DeepSeek Harness plugin that blocks risky npm installs with metadata and deep supply-chain scans

5last monthSecurity & PermissionsApache-2.0
J

dsh-plugin-audit

jkrandom-sudo/dsh-plugin-audit

Security audit plugin for DeepSeek Harness: static permission profiling and a runtime sentinel for third-party plugins

5last monthSecurity & PermissionsMIT
E

dsh-sentinel-scanner

eligahyu/dsh-sentinel-scanner

Static security scanner for DSH plugins: read-only audit (exec, credentials, exfiltration, obfuscation, install scripts, bundle manifest) with a 0-100 risk score.

518 days agoSecurity & PermissionsMIT
A

dsh-plugin-security-review

ateen18/dsh-plugin-security-review

Pre-install static security review and runtime guard for dsh plugins: deobfuscation decoding, supply-chain checks, web one-click review/install/uninstall, and optional runtime tool-call guard.

4last monthSecurity & Permissions
K

dsh-ankh-guard

khorsheed/dsh-ankh-guard

Hard gate for self-modification restarts: a green-build credential bound to the git HEAD, checked before any restart of the running instance

42 months agoSecurity & PermissionsMITArchived
T

dsh-plugin-vetting

truelove-dreamer/dsh-plugin-vetting

Vets third-party plugins before you trust them: static scan for malicious patterns (exfiltration, credential access, obfuscation, persistence) and over-privileged path use, transitive-dependency coverage, official-package hash baseline for supply-chain tamper detection, and an optional plugin-tool call gate.

4last monthSecurity & Permissions
0

dsh-verification-receipt

030611/dsh-verification-receipt

Writes local JSONL summaries of per-turn tool counts and coarse verification signals without storing prompts, tool arguments, or result text.

429 days agoSecurity & PermissionsMIT
D

dsh-tool-policy

drifter-yh/dsh-tool-policy

Allow, ask, or deny DeepSeek Harness tool calls before execution

313 days agoSecurity & PermissionsMIT
D

dsh-auto-approve

dnalec/dsh-auto-approve

Automatic approval and review for tool calls that need approval: keyword buckets match red lines without context, then a judge model classifies what was requested and sends it to allow, reject or a human according to the matching row and risk level; a judgment that never ran always goes to a human, and rejections tell the model why.

317 days agoSecurity & PermissionsMIT
A

dsh-write-protect

azazo1/dsh-write-protect

Keep declared workspace subpaths (e.g. .git) read-only, honor a read-only rules file at the workspace root, grant extra writable roots under workspace-write, and let the model request session-scoped write access; enforced for sandboxed CLI commands and the write/edit tools.

34 days agoSecurity & PermissionsMIT
J

dsh-always-require-tools-approval

j0ss077/dsh-always-require-tools-approval

Requires one-shot user approval before configured tools (default bash, pwsh) execute — gated tools pause and ask, everything else delegates, and a missing approval channel fails closed.

326 days agoSecurity & PermissionsMIT
M

dsh-agent-approval

moonlitdropofblood/dsh-agent-approval

An independent approval subagent judges every sandbox escalation, with a configurable model and an audit log.

32 days agoSecurity & PermissionsMIT
S

securstack-dsh-plugin

securstack/securstack-dsh-plugin

DeepSeek Harness plugin for SecurStack security scans, policy checks, doctor diagnostics, and JSON CLI results.

3last monthSecurity & PermissionsMIT
W

dsh-plugin-vet

wulun811/dsh-plugin-vet

Plugin trust pipeline for DeepSeek Harness: deterministic static scan with verdicts, opt-in runtime guard with honeypot lures, agent audit-protocol skill, and a browser shield status light. Alarm-only, never an enforcer.

34 days agoSecurity & PermissionsMIT
S

dsh-yolo-mode

severuszh/dsh-yolo-mode

LLM auto-approval for sandbox escalation requests, with presets and a fail-closed fallback.

34 days agoSecurity & PermissionsMIT
J

dsh-rule-engine

jilian-dsh/dsh-rule-engine

Rules execution engine for dsh: parses AGENTS.md, hard-blocks rule-violating tool calls, text-based B/D rule auditing, /guard command, version-guard for versioned files, and free-zone support (engine skips free-zone sections).

39 days agoSecurity & PermissionsMIT