Passer au contenu principal

Sécurité et permissions

Les plugins Sécurité et permissions renforcent DeepSeek-Harness (dsh) contre les appels d'outils risqués et les plugins malveillants. Cette catégorie couvre le contrôle des outils par politiques avec niveaux allow/deny/ask, les scanners de pré-installation pour les bundles de plugins et les tarballs npm, les protections contre l'injection de prompt et l'exfiltration de secrets, la rédaction de la télémétrie et les journaux d'audit chaînés par hachage.

56 plugins trouvés

T

dsh-auth-gate

tecfancy/dsh-auth-gate

Login gate for the dsh web surface: password or shared-token authentication, session cookies, rate limiting, and a user-management CLI (dsh.bundle manifest since 0.4.1, one-command `dsh plugin add` mounting).

2il y a 8 heuresSécurité et permissionsMIT
M

dsh-approval-gate

moon09300731/dsh-approval-gate

Risk-gated approval automation for DeepSeek Harness: flash pre-classifies whether a write/command is irreversible — safe operations are auto-approved, dangerous ones are escalated to human approval (fail-safe).

2il y a 15 heuresSécurité et permissionsMIT
P

dsh-skill-pack-security

perrylink/dsh-skill-pack-security

Plugin fournisseur optionnel pour dsh-skill-pack-security : enregistre le dossier skills/ (zh) ou skills-en/ (en) du pack dans ctx.skills. Les deux éditions sont embarquées dans pack/.

2il y a 4 heuresSécurité et permissionsApache-2.0
A

dsh-turn-approval

arrow949/dsh-turn-approval

Approbations « Autoriser pour cette tâche », limitées au tour : autorise automatiquement les escalades `danger-full-access` correspondantes uniquement pour la tâche en cours, puis expire.

2il y a 5 joursSécurité et permissionsMIT
O

sandbox-mxc

omdsh-dev/sandbox-mxc

Prise en charge du sandbox multiplateforme Microsoft.

2il y a 7 heuresSécurité et permissions
C

dsh-mcpguard

chenlaoshiyf/dsh-mcpguard

Analyse les skills et les configurations MCP à la recherche d'injections de prompt, d'homoglyphes, d'Unicode caché, de commandes shell dangereuses et de fuites d'identifiants.

2il y a 11 heuresSécurité et permissionsMIT
T

dsh-egress-guard

tancheng33/dsh-egress-guard

Runtime security gate on the tool pipeline: denies calls naming hosts outside an egress allowlist, redacts credentials from results at the canonical value rather than only the rendered content, and appends every decision to a JSONL audit log; ships in monitor-only mode.

1il y a 3 joursSécurité et permissionsMIT
S

dsh-web-auth

summersec/dsh-web-auth

Transport-level authentication gate for the DeepSeek Harness Web GUI with server-side sessions, HttpOnly cookies, IP-based login throttling, and an scrypt password CLI.

1hierSécurité et permissionsMIT
S

dsh-code-security

stardustlc666/dsh-code-security

Deterministic code security review: 40+ rules, secret entropy detection, staged-diff review, SARIF export, baseline acceptance and SBOM-lite dependency inventory.

1il y a 6 heuresSécurité et permissionsMIT
J

dsh-rule-engine

jilian-dsh/dsh-rule-engine

Rules execution engine for dsh: parses AGENTS.md, hard-blocks rule-violating tool calls, text-based B/D rule auditing, /guard command, version-guard for versioned files, and free-zone support (engine skips free-zone sections).

1hierSécurité et permissionsMIT
B

dsh-security-guard

bigclawd/dsh-security-guard

Static and runtime security guard for dsh: rule-based scans for malicious code, prompt injection and token waste, runtime interception of dangerous tool calls, /scan command, plugin_scan tool, web panel, and allowlist.

1il y a 3 joursSécurité et permissionsMIT
L

dsh-guardian

lonelymoon87/dsh-guardian

Ajoute des vérifications de politique pour les opérations dangereuses, une rédaction de sortie et un workflow de revue de sécurité.

1il y a 5 joursSécurité et permissionsMIT
I

dsh-tool-approval

ilharp/dsh-tool-approval

Mode d'approbation manuelle (« Mode Manuel » / « Mode Demander »).

1il y a 5 joursSécurité et permissionsBSD-3-Clause
L

dsh-fleet-audit

lesliewylie/dsh-fleet-audit

Audit en lecture seule de l'hygiène des identifiants d'une flotte d'agents : permissions des fichiers d'identifiants, identifiants intégrés dans les remotes git (masqués dans la sortie), et comptage des jetons de fournisseur en clair ; sans dépendance et déterministe.

1il y a 16 heuresSécurité et permissionsMIT
Y

noatmark-dsh-plugin

ylwl1997/noatmark-dsh-plugin

Hygiène du texte en plugin dsh : assainit le texte non fiable, détecte les caractères invisibles, nettoie le formatage LLM et échappe les injections de formules CSV.

1hierSécurité et permissionsMIT
Z

dsh-poison-guard

zoahdev/dsh-poison-guard

Pre-install supply-chain poison scanner for DSH plugins: AST (JS-X-Ray) + deobfuscation + regex heuristics, exits non-zero on findings for CI gating.

0hierSécurité et permissionsMIT
T

dsh-credentials-vault

tancheng33/dsh-credentials-vault

HashiCorp Vault backend for the credential seam: KV v2/v1, AppRole machine auth, per-operation reads so rotation needs no restart, and compare-and-swap writes.

0il y a 3 joursSécurité et permissionsMIT
T

dsh-code-runtime-container

tancheng33/dsh-code-runtime-container

Container-isolated backend for the `ctx.codeRuntime` seam: each Code Mode program runs in a fresh container with no network, a read-only rootfs, dropped capabilities, and kernel-enforced memory, CPU and pid ceilings.

0il y a 3 joursSécurité et permissionsMIT
S

dsh-risk-guard

shuxue6662-a11y/dsh-risk-guard

Zero-interruption audit and fuse blocking for DeepSeek Harness: silently records every tool call with deterministic risk scoring, cumulative-risk bonuses, risk-level breakdowns and retention-based cleanup; blocks irreversible catastrophes (protected-path deletion, disk wipe, force-push to protected branches/refs, credential exfiltration), and renders a redacted /risk-guard operation bill with --since filtering.

0hierSécurité et permissionsMIT
S

dsh-cve-audit

sarthak2511/dsh-cve-audit

Live CVE/supply-chain audit for your workspace's own project dependencies (npm/pip/go), backed by OSV.dev, with a `cve_audit` tool plus optional automatic re-scan on lockfile changes.

0il y a 3 joursSécurité et permissions
P

dsh-plugin-judge

pengxuding/dsh-plugin-judge

Plugin value auditor: pre-install review (source scan + LLM judge) and post-install audit of installed bundles, with model-switch re-audit reminders.

0il y a 4 joursSécurité et permissionsMIT
P

dsh-auto-classifier

pakiknowledge/dsh-auto-classifier

Autonomous permission classifier for the auto preset: tool-scoped allow/deny rules, an LLM semantic judge, and git checkpointing for unattended sessions.

0avant-hierSécurité et permissions
J

secret-guard

johnxu22786/secret-guard

Blocks agents from reading or writing sensitive files (.env, credentials, key material), masks leaked secret-shaped values in tool results, keeps an audit journal, and exposes safe sg_* inspection tools that never print raw values.

0avant-hierSécurité et permissionsMIT
J

safety-net

johnxu22786/safety-net

Destructive-command interception gate for dsh: parses shell semantics, judges risk against 41 built-in rules, and holds irreversible rm -rf, git reset --hard, and git push --force style commands at a confirmation gate.

0avant-hierSécurité et permissionsMIT