Plugins
Browse, filter, and install DeepSeek-Harness plugins.
39 plugins found
dsh-remote
xgone/dsh-remote
Secure remote access for the DeepSeek Harness Web UI: a login gate, MFA/TOTP, signed session cookies, optional admin/user/guest roles, in-browser workspace selection, and allowlisted remote file previews.
dsh-plugin-hub (dsh-lan-proxy)
wingsky-1/dsh-plugin-hub
Access the dsh web UI over LAN: HTTP/HTTPS/WS forwarding plus TLS (self-signed or custom certificates); adaptive Brotli/gzip compression for HTTP and permessage-deflate for WebSocket; half-open WebSocket probing keeps mobile clients from going stale after backgrounding; launch-token auto-injection lets LAN devices connect without copying the token; DNS-rebinding protection + loopback-only upstream allowlist.
dsh-one-gateway
tiantianflow/dsh-one-gateway
Private loopback DSH Web gateway for Tailscale Serve, Cloudflare Access, and Headscale TCP Serve, with exact principal allowlists and guided fail-closed setup.
dsh-tailscale-gateway
tiantianflow/dsh-tailscale-gateway
Private Tailscale access for DeepSeek Harness Web that allowlists users from the trusted Tailscale-User-Login header that Serve injects, with a loopback-only gateway and guarded Serve setup.
dsh-imessage
photon-hq/dsh-imessage
Two-way iMessage channel for DeepSeek Harness over Photon: sender allowlisting, session commands, in-chat approvals and questions, and a Settings page for device authorization and hosted-line setup.
dsh-mysql
1321928757/dsh-mysql
MySQL connector for DeepSeek Harness: configure multiple connections in the settings page with per-connection table allowlist and write permission, switch the active connection from the composer, and expose mysql_query / mysql_tables / mysql_execute tools to every agent preset.
dsh-plugins (tailnet-gateway)
creait-nl/dsh-plugins
Identity-gated Tailscale access to the Web GUI with dsh still bound to loopback: a 127.0.0.1 proxy published by `tailscale serve` admits a request only when the Tailscale login it stamps is allowed, with an optional per-device allowlist, so the privileged /api methods behind the loopback check — Settings, Models, Plugins — answer without dsh being told to trust a remote host.
dsh-plugins (web-fetch)
creait-nl/dsh-plugins
A guarded local fetch provider for the ctx.web seam — the backend dsh does not ship for its own web_fetch tool. Every redirect hop is re-resolved and checked against the non-routable ranges, with a streamed size cap and a content-type allowlist.
dsh-lark-bridge
moyu-good/dsh-lark-bridge
Feishu/Lark IM channel for DeepSeek Harness agents with native thinking-process messages, approval cards, live goal and todo cards, workflow fan-out lines, session text search, and background job and subagent settlement notices. Access is bounded by the Feishu app's own visibility scope by design — anyone the app admits can drive the agent and answer its approvals unless the optional sender, group and approver allowlists are filled in.
dsh-model-router
superboy911/dsh-model-router
Deterministic keyword routing, allowlisted model switching, and an isolated image_gen channel for DeepSeek Harness.
dsh-feishu-bridge
wz-heng/dsh-feishu-bridge
Fail-closed Feishu (Lark) channel bridge: chat with a bot, get dsh agent turns back — with opt-in human-in-the-loop tool approval (Allow/Deny cards before every bash call, fail-closed timeout). Official-Python-SDK-only integration (exact-pinned); deny-by-default allowlist, webhook signature/timestamp/replay verification, per-chat sticky sessions; daily latest-SDK compatibility canary; bilingual docs.
dsh-lark-claw
illuminated2020/dsh-lark-claw
Feishu/Lark gateway for DeepSeek Harness with topic-persistent conversations, live execution cards, image and file inputs, in-chat approvals and questions, source allowlists, and durable one-time or recurring agent tasks created in natural language.
dsh-subagent-router
xmoon/dsh-subagent-router
Adds subagent_route and subagent_fork_route delegation tools where the model itself picks the provider/model route for each child; the deployment only sets the spawn/fork backend, background policy and allowedProviders allowlist, while continuable children and background jobs reuse the official send_message / job_output tools.
dsh-cua-pre
aik358/dsh-cua-pre
Windows desktop automation for DeepSeek Harness: accessibility-first observe/act loop with 30 standard tools (element/coordinate targets, auto/a11y/event strategy routing), superseded-observations and no-replay safety semantics, persistent kill switch, RuntimeId/rect-drift stale protection, chat cards and a floating panel (live ops, frame wall, env auto-detect settings), tiled vision describe for low-res models, JSONL audit trail and a pid allowlist. Requires Windows 10+ and Python 3.9+ with uiautomation and pillow (installable from the settings page).
dsh-better
wackyju2-beep/dsh-better
Archived-session management, task-stop notifications, an update checker, model routing (keyword rules + allowlist-gated model_route), multi-task scheduled triggers (heartbeats and fixed-time tasks), and a DeepSeek-style message scroll nav for the dsh web GUI.
dsh-wsl-im
173787247/dsh-wsl-im
Bridges Feishu, WeCom aibot, DingTalk Stream and QQ Gateway chats into dsh agents over outbound long connections, with an im_status tool. Ships with an empty user allowlist, which means EVERYONE can drive your agent — set allowedUserIds before exposing a bot; IM input can run tools on the host.
dsh-wechat-channel
shr-cs/dsh-wechat-channel
WeChat Official Account channel for DSH — WeChat messages run agent turns and the answers are pushed back through the customer-service message API, with signature-checked callbacks and an openid allowlist.
dsh-wsl-expose
173787247/dsh-wsl-expose
Advises or applies allowlisted Windows portproxy for a WSL listen port, preferring the kit :3081 relay and launch token for local dsh UI.
dsh-wsl-launch
173787247/dsh-wsl-launch
Launches allowlisted Windows apps such as VS Code, Explorer, and browsers from WSL.
dsh-ssh-logs
452926826/dsh-ssh-logs
Read and search bounded log output from allowlisted SSH servers and log roots without exposing arbitrary remote commands.
dsh-feishu-channel
wyattjhayes/dsh-feishu-channel
Security-focused Feishu (Lark) channel for DeepSeek Harness: allowlisted remote-agent access with workspace-scoped paths, symlink checks, risk-based approvals, session isolation, redacted logs, and bounded message queues.
dsh-ui-translate
radicalgitter/dsh-ui-translate
Translates visible Chinese UI and content in DeepSeek Harness Web, using a browser-local OPUS-MT model for session titles, workspace names, messages, search results, and opted-in plugin prose while keeping remote translation limited to allowlisted UI labels.
dsh-coding-remote-kit
lninghaha/dsh-coding-remote-kit
Mobile pairing remote for DeepSeek Harness: E2EE companion over dual-plane allowlisted RPC (LAN, Tailscale, optional Cloudflare Quick Tunnel or self-hosted rendezvous).
dsh-egress-guard
tancheng33/dsh-egress-guard
Runtime security gate on the tool pipeline: denies calls naming hosts outside an egress allowlist, redacts credentials from results at the canonical value rather than only the rendered content, and appends every decision to a JSONL audit log; ships in monitor-only mode.