- Inicio
- Categorías
- Seguridad y permisos
Seguridad y permisos
Los plugins de Seguridad y permisos protegen DeepSeek-Harness (dsh) frente a llamadas a herramientas arriesgadas y plugins maliciosos. Esta categoría cubre control de herramientas basado en políticas con niveles allow/deny/ask, escáneres previos a la instalación para paquetes de plugins y tarballs de npm, protección contra inyección de prompts y filtración de secretos, ocultación de telemetría y registros de auditoría encadenados por hash.
269 plugins encontrados
noatmark-dsh-plugin
ylwl1997/noatmark-dsh-plugin
Higiene de texto como plugin de dsh: sanea texto no confiable, detecta caracteres invisibles, limpia el formato generado por LLM y escapa la inyección de fórmulas CSV.
dsh-escalation-review
trentswd/dsh-escalation-review
Escalation-only LLM reviewer: reviews sandbox escapes only, keeps the sandbox, fails closed.
crwu-ai
mmungdong/crwu-ai
中瑞世联工作台 / CRWU audit workbench for DeepSeek Harness: pick a pending audit report, dispatch one AI audit subagent, watch and stop/restart it, auto-upload deliverables to Aliyun OSS.
dsh-approval-policy
fan56/dsh-approval-policy
dsh plugin: unattended approval gate — subagent/scheduled/cron approval requests get a bounded answer window, then settle with a fail-closed default instead of hanging forever (per origin or per session)
chinese-script-policy
ksf1216/chinese-script-policy
Harness-neutral Traditional Chinese enforcer + offline converter (skill, DSH bundle, CLI). One script axis either way + Cantonese/Japanese-only filters. Converts both ways; optional wording preference. Also: an LLM output guard, cp950/GBK console scan.
dsh-decision-layer
xbzbing/dsh-decision-layer
A structured decision layer for the DeepSeek Harness agent loop: a danger-call gate, output self-check, tool narrowing, and loop guard backed by a pluggable adjudication model.
dsh-opencode-free-tier
docutee/dsh-opencode-free-tier
Make DSH llm-pi-ai opencode routes pass Zen free-tier gate: opencode User-Agent + canonical ses_ session + bash/read tools. Scoped to opencode.ai only.
dsh-approval-gate
goodandready/dsh-approval-gate
Host-only command safety gate for DeepSeek Harness: blocks recognized dangerous operations and requests DSH approval when a command cannot be inspected.
dsh-skill-audit
caesarloo/dsh-skill-audit
Audit DSH skills automatically: a host-layer tools/post-execute plugin that ships both the skill body and the audit engine, runs the engine after skill files change (write/edit/shell) or after a bulk restore/backup (any tool invoked with mode: restore|bac
dsh-keychain-credentials
nengong-ai/dsh-keychain-credentials
Pure JavaScript macOS Keychain credentials provider for DeepSeek Harness, replacing plaintext .credentials.yaml storage and fully supporting both refs and records without native builds, signing, or Xcode.
data-asset-inspector
liuhange789/data-asset-inspector
Shared infrastructure for data assetization plugins: business rules loader, file format adapter, report generator, path validator, audit logger Also known as @deepseek-ai/dsh-data-asset-shared.
dsh-fs-allowlist
wzn16/dsh-fs-allowlist
Approval-free writes into whitelisted directories — wraps the filesystem fence for write/edit tools and auto-answers bash sandbox escalations that touch whitelisted paths, with a settings GUI.
dsh-contract-check
imtokenxinluo/dsh-contract-check
Contract check for DeepSeek Harness plugins: statically verifies that registered tools' output.render() returns ContentBlock[], and warns when a session event type falls outside the kernel vocabulary. Warn-only. 契约体检插件(不检测恶意)。
dsh-cache-guard
loonylabs-dev/dsh-cache-guard
Host- and agent-layer DeepSeek Harness plugin that prices every automatic context rewrite before it lands, asks the human by default, and reports what the provider had to re-read cold.
dsh-approval-gate
iamnewhands/dsh-approval-gate
Maintained fork of dsh-approval-gate. A neutral operation whose confirmation count has reached the threshold auto-approves when the judge is unavailable, instead of prompting a human again; approver-facing explanations are generated in Chinese from the real sandbox mode, command and paths. Also carries deterministic hard-deny for credential exfiltration and system-path destruction, judge-input redaction, a judge model candidate chain, fingerprint-scoped allow rules, and an approval view with unified diff and one-click revert.
dsh-jev-guard
7starsseeker/dsh-jev-guard
Pre-execution safety valve for DSH that judges with TypeSafe Jev: it hooks tools/pre-execute and decides every bash/pwsh call by first applying offline static rules, then by asking the Jev model — the System One model from TypeSafe, which returns a structured decision instead of prose — one yes-no question ("will this command irreversibly delete or overwrite real data?"), turning the answer into allow, revise, block or escalate; revise hands the model a safer rewrite, escalate offers a one-shot human token; exhausted credit or a missing API key degrades loudly instead of failing silent, and a missing key is requested in the conversation itself (`guard key set`, read from stdin); every verdict is appended to a shared audit log and the text people read is bilingual zh-CN/en.
dsh-theme-studio
hj01857655/dsh-theme-studio
Customize the dsh UI theme: 12 accent presets, dark-mode aware accents with a contrast guard, density, font family, animation toggle, and raw design-token overrides.
dsh-tm-guard
chaojie0/dsh-tm-guard
Zero-intervention permission gate for DSH agents on macOS: auto-allows local writes made reversible by git or Time Machine, blocks network, package installs, process control and sensitive-path reads, with full audit logs.
dsh-unsandboxed-winbash
xswt442-cmd/dsh-unsandboxed-winbash
让 dsh 在 Windows 上使用用户自安装的 Git Bash,并绕过其沙箱限制 | Enable dsh to use a user-installed Git Bash on Windows by bypassing its sandbox restrictions.
dsh-almazom-approve-escalate
almazom/dsh-almazom-approve-escalate
One-click Approve & escalate on the approval card: answers the pending request and switches the live session to a permission preset.
dsh-jumpserver
we39/dsh-jumpserver
Query and manage JumpServer through conversation: assets, users, accounts, permissions, sessions, command audit logs, command filters, and RBAC roles, authenticated with an AccessKeyID/AccessKeySecret pair (HTTP Signature).
dsh-fs-allowlist
wangzhaonan16/dsh-fs-allowlist
Approval-free writes into whitelisted directories — wraps the filesystem fence for write/edit tools and auto-answers bash sandbox escalations that touch whitelisted paths, with a settings GUI.
dsh-auto-pass
sujingkpo/dsh-auto-pass
A continuation of simon300000/dsh-auto: the Auto Approve permission preset for the DSH Web UI reviews each approval with one single-shot model call instead of a reviewer subagent, auto-approves only the actions that pass and hands the rest to human approval, and remembers confirmed decisions as project- and global-scope allow/deny lists, with an approval timeline in the right sidebar.
dsh-sandbox-arg-guard
apex-mochen/dsh-sandbox-arg-guard
Keeps a redundant sandbox-escalation argument from failing a tool call. Escalating tools (pwsh, bash, write, edit) advertise the full sandbox_permissions enum, but DSH only accepts a level strictly wider than the one already in effect — a check its own source calls 'deliberately not a schema constraint'. A model that reflexively passes the argument therefore picks the level it is already at and the call dies before running with 'sandbox escalation to "workspace-write" is not strictly wider than this call's current "workspace-write" mode', costing some models a whole turn of retries. This plugin registers one tools/execute waterfall listener and, only on that documented rejection and only when the arguments really carried an escalation field, re-issues the identical call once without it. Safe by DSH's own documentation: the rejection precedes any execution ('nothing has run'), and the corrected call cannot match again, so the retry is loop-free. Reproduced and verified end to end — before: isError true, the command never ran; after: the command's real output, isError false, one tool/call and one tool/result. Zero dependencies.