Saltar al contenido principal

Seguridad y permisos

Los plugins de Seguridad y permisos protegen DeepSeek-Harness (dsh) frente a llamadas a herramientas arriesgadas y plugins maliciosos. Esta categoría cubre control de herramientas basado en políticas con niveles allow/deny/ask, escáneres previos a la instalación para paquetes de plugins y tarballs de npm, protección contra inyección de prompts y filtración de secretos, ocultación de telemetría y registros de auditoría encadenados por hash.

269 plugins encontrados

M

dsh-plugin-trustlens

mengshang-spec/dsh-plugin-trustlens

Read-only DSH plugin auditor with static scanning, current-session model review, and confirmation gates.

1el mes pasadoSeguridad y permisosMIT
X

dsh-full-access-switch

xtd1145/dsh-full-access-switch

One-time Full access switch for DeepSeek Harness: new sessions (workspaces and conversations) start with danger-full-access and skip the per-session Full access confirmation; installable as a dsh bundle or via patch scripts.

1el mes pasadoSeguridad y permisosMIT
W

dsh-feishu-channel

wyattjhayes/dsh-feishu-channel

Security-focused Feishu (Lark) channel for DeepSeek Harness: allowlisted remote-agent access with workspace-scoped paths, symlink checks, risk-based approvals, session isolation, redacted logs, and bounded message queues.

1el mes pasadoSeguridad y permisosMIT
L

dsh-hawkeye-scan (npm)

liuqingman/dsh-hawkeye-scan

AI-driven source-code security scanning workbench: 5 model tools (start/finding/status/report/list) plus a /hawkeye web UI and JSON/Markdown/HTML vulnerability reports; zero-dependency Cordis plugin, installable as agent preset or npm package.

1el mes pasadoSeguridad y permisosMIT
A

dsh-llm-approve-for-me

alaxrpg/dsh-llm-approve-for-me

Uses an isolated LLM review to approve or reject DSH sandbox permission requests.

1hace 25 díasSeguridad y permisosMIT
T

dsh-plugin-guard

taxueseek/dsh-plugin-guard

Static-only plugin gate and clinic for DSH: audit before install, hash-and-capability lock after install, local fingerprint peer search over GitHub topic:dsh-plugin, and mechanical detox. Never executes the target plugin.

1el mes pasadoSeguridad y permisosMIT
A

dsh-auto-review

accpowered/dsh-auto-review

LLM approval answerer for sandbox escalations beyond workspace-write: a deterministic regex filter first, then a clean-context reviewer model; humans are asked only when it is unsure. Requires the bundled core patches.

1el mes pasadoSeguridad y permisosMIT
A

dsh-credential-manager

accpowered/dsh-credential-manager

Named user credentials the model uses by reference: values are entered on a Settings → Credentials page and injected into each shell execution as DSH_CM_* variables instead of being printed into the transcript, with credential_read as the documented last resort.

1hace 14 díasSeguridad y permisosMIT
G

dsh-compaction-audit

gendui123/dsh-compaction-audit

Compaction quality / hallucination detector: when a conversation span is compacted, check on two axes that key information survived 鈥?FIDELITY (assertions in the summary must be found verbatim in the original leaf events, else flagged as fabricated) and C

1el mes pasadoSeguridad y permisosMIT
G

dsh-compaction-probe

gendui123/dsh-compaction-probe

Step-0 observation probe for dsh-compaction-audit: logs every compaction/* session event and probes whether shadowedSeqs still resolve to readable events in session.events. Observe-only; never injects, never blocks.

1el mes pasadoSeguridad y permisosMIT
G

dsh-plan-adversarial

gendui123/dsh-plan-adversarial

Command-triggered red/blue adversarial review for ANY plan (not quant-specific). /plan-adversarial <plan>: arms a gate that requires the agent to derive two independent subagents (red=attack, blue=defend), have them converge on a consensus plan with NO th

1el mes pasadoSeguridad y permisosMIT
A

dsh-todo-guard

a903067276-rgb/dsh-todo-guard

Reliable todo panel that survives restarts (official panel only re-renders on write — fixed via projection pre-warm) with three-state completion verification: evidence exists → verified, fake evidence → blocked, no evidence → unverified badge; settings toggle to fall back to official behavior.

1el mes pasadoSeguridad y permisosMIT
K

dsh-skill-security-inspector

kakapengta/dsh-skill-security-inspector

一个可直接链接到 DeepSeek Harness(DSH)Web profile 的独立安全检查插件。在安装或使用不受信任的 Skill 前,先执行浏览器本地粗检,再由用户决定是否调用 DSH 已配置的大模型进行结构化复核。

1el mes pasadoSeguridad y permisos
M

forge

mjxupup/forge

Forge quality gates for DeepSeek Harness (dsh): task gates, read-before-edit, bash hazard interception and quality scoring, driven by the forge CLI through DSH's typed interception points.

1el mes pasadoSeguridad y permisosApache-2.0
S

dsh-guardian-approval

scotlight/dsh-guardian-approval

Revisor de aprobaciones independiente estilo Codex Guardian para DSH.

1el mes pasadoSeguridad y permisosMIT
N

nexusclaw-agent-governance

nexusclawhq/nexusclaw-agent-governance

Respondedor de aprobaciones para DeepSeek Harness (dsh) respaldado por el sidecar agent-governance — cada aprobación/solicitud la decide una puerta con denegación por defecto, reglas L0–L4 y la cadena de auditoría organizacional.

1el mes pasadoSeguridad y permisosApache-2.0
D

dsh-provenance

darren-tang/dsh-provenance

Verificaciones de cadena de suministro previas a la instalación para plugins de DeepSeek Harness: comprueba que el tarball que está a punto de instalar coincida con el código fuente que leyó, antes de que se ejecute cualquier código.

1el mes pasadoSeguridad y permisosMIT
A

dsh-Almost_Full_Access

alnita-m/dsh-almost_full_access

Modo de permisos intermedio entre workspace-write y acceso total: los comandos de shell se verifican mediante reglas deterministas y una revisión por subagente; las acciones irreversibles o a nivel del sistema requieren aprobación explícita.

1hace 23 díasSeguridad y permisosMIT
A

dsh-perm-guard

a903067276-rgb/dsh-perm-guard

Guarda de permisos con autoaprobación: un nivel intermedio entre workspace-write y danger-full-access — permite automáticamente las operaciones seguras dentro de los directorios de confianza y siempre pide confirmación humana para las destructivas, con 11 interruptores por categoría y un registro de auditoría.

1anteayerSeguridad y permisosMIT
C

dsh-write-gate

couldbeme/dsh-write-gate

Puerta de escritura por compromisos: reglas redactadas por el operador aplicadas antes de ejecutar una llamada a herramienta — un nivel de guardia determinista más un nivel de juez LLM, fail-closed por defecto, y cada bloqueo se registra en un registro de contradicciones.

1el mes pasadoSeguridad y permisosMIT
R

skill-security-guard

rrrrrredy/skill-security-guard

Bundle comunitario de DeepSeek Harness para el escáner estático skill-security-guard.

1hace 2 mesesSeguridad y permisosMIT
B

dsh-access-gate

bamboostrip/dsh-access-gate

Plugin de DSH: puerta con contraseña para el acceso remoto (no loopback) a /api (sin contraseña por defecto), desbloquea los endpoints privilegiados fijados a loopback, restaura todo al desinstalar y ofrece al usuario local de 127.0.0.1 el selector de carpetas nativo del sistema para seleccionar el espacio de trabajo. selec

1hace 2 mesesSeguridad y permisosMIT
A

dsh-safety-net

asuna486-desuwa/dsh-safety-net

Barreras de autoprotección para DeepSeek Harness: interceptación de rutas protegidas, copia de seguridad antes de destruir, comandos de autorrecuperación de CLI y configuración predeterminada de sandbox estricta.

1hace 2 mesesSeguridad y permisosMIT
O

riskproof

onlyqzq/riskproof

Seguridad de ejecución consciente de la procedencia para DeepSeek Harness. Rastrea datos sensibles a través de llamadas a herramientas y detiene efectos secundarios riesgosos antes de la ejecución.

1hace 2 mesesSeguridad y permisosApache-2.0