- Accueil
- Catégories
- Sécurité et permissions
Sécurité et permissions
Les plugins Sécurité et permissions renforcent DeepSeek-Harness (dsh) contre les appels d'outils risqués et les plugins malveillants. Cette catégorie couvre le contrôle des outils par politiques avec niveaux allow/deny/ask, les scanners de pré-installation pour les bundles de plugins et les tarballs npm, les protections contre l'injection de prompt et l'exfiltration de secrets, la rédaction de la télémétrie et les journaux d'audit chaînés par hachage.
269 plugins trouvés
noatmark-dsh-plugin
ylwl1997/noatmark-dsh-plugin
Hygiène du texte en plugin dsh : assainit le texte non fiable, détecte les caractères invisibles, nettoie le formatage LLM et échappe les injections de formules CSV.
dsh-escalation-review
trentswd/dsh-escalation-review
Escalation-only LLM reviewer: reviews sandbox escapes only, keeps the sandbox, fails closed.
crwu-ai
mmungdong/crwu-ai
中瑞世联工作台 / CRWU audit workbench for DeepSeek Harness: pick a pending audit report, dispatch one AI audit subagent, watch and stop/restart it, auto-upload deliverables to Aliyun OSS.
dsh-approval-policy
fan56/dsh-approval-policy
dsh plugin: unattended approval gate — subagent/scheduled/cron approval requests get a bounded answer window, then settle with a fail-closed default instead of hanging forever (per origin or per session)
chinese-script-policy
ksf1216/chinese-script-policy
Harness-neutral Traditional Chinese enforcer + offline converter (skill, DSH bundle, CLI). One script axis either way + Cantonese/Japanese-only filters. Converts both ways; optional wording preference. Also: an LLM output guard, cp950/GBK console scan.
dsh-decision-layer
xbzbing/dsh-decision-layer
A structured decision layer for the DeepSeek Harness agent loop: a danger-call gate, output self-check, tool narrowing, and loop guard backed by a pluggable adjudication model.
dsh-opencode-free-tier
docutee/dsh-opencode-free-tier
Make DSH llm-pi-ai opencode routes pass Zen free-tier gate: opencode User-Agent + canonical ses_ session + bash/read tools. Scoped to opencode.ai only.
dsh-approval-gate
goodandready/dsh-approval-gate
Host-only command safety gate for DeepSeek Harness: blocks recognized dangerous operations and requests DSH approval when a command cannot be inspected.
dsh-skill-audit
caesarloo/dsh-skill-audit
Audit DSH skills automatically: a host-layer tools/post-execute plugin that ships both the skill body and the audit engine, runs the engine after skill files change (write/edit/shell) or after a bulk restore/backup (any tool invoked with mode: restore|bac
dsh-keychain-credentials
nengong-ai/dsh-keychain-credentials
Pure JavaScript macOS Keychain credentials provider for DeepSeek Harness, replacing plaintext .credentials.yaml storage and fully supporting both refs and records without native builds, signing, or Xcode.
data-asset-inspector
liuhange789/data-asset-inspector
Shared infrastructure for data assetization plugins: business rules loader, file format adapter, report generator, path validator, audit logger Also known as @deepseek-ai/dsh-data-asset-shared.
dsh-fs-allowlist
wzn16/dsh-fs-allowlist
Approval-free writes into whitelisted directories — wraps the filesystem fence for write/edit tools and auto-answers bash sandbox escalations that touch whitelisted paths, with a settings GUI.
dsh-contract-check
imtokenxinluo/dsh-contract-check
Contract check for DeepSeek Harness plugins: statically verifies that registered tools' output.render() returns ContentBlock[], and warns when a session event type falls outside the kernel vocabulary. Warn-only. 契约体检插件(不检测恶意)。
dsh-cache-guard
loonylabs-dev/dsh-cache-guard
Host- and agent-layer DeepSeek Harness plugin that prices every automatic context rewrite before it lands, asks the human by default, and reports what the provider had to re-read cold.
dsh-approval-gate
iamnewhands/dsh-approval-gate
Maintained fork of dsh-approval-gate. A neutral operation whose confirmation count has reached the threshold auto-approves when the judge is unavailable, instead of prompting a human again; approver-facing explanations are generated in Chinese from the real sandbox mode, command and paths. Also carries deterministic hard-deny for credential exfiltration and system-path destruction, judge-input redaction, a judge model candidate chain, fingerprint-scoped allow rules, and an approval view with unified diff and one-click revert.
dsh-jev-guard
7starsseeker/dsh-jev-guard
Pre-execution safety valve for DSH that judges with TypeSafe Jev: it hooks tools/pre-execute and decides every bash/pwsh call by first applying offline static rules, then by asking the Jev model — the System One model from TypeSafe, which returns a structured decision instead of prose — one yes-no question ("will this command irreversibly delete or overwrite real data?"), turning the answer into allow, revise, block or escalate; revise hands the model a safer rewrite, escalate offers a one-shot human token; exhausted credit or a missing API key degrades loudly instead of failing silent, and a missing key is requested in the conversation itself (`guard key set`, read from stdin); every verdict is appended to a shared audit log and the text people read is bilingual zh-CN/en.
dsh-theme-studio
hj01857655/dsh-theme-studio
Customize the dsh UI theme: 12 accent presets, dark-mode aware accents with a contrast guard, density, font family, animation toggle, and raw design-token overrides.
dsh-tm-guard
chaojie0/dsh-tm-guard
Zero-intervention permission gate for DSH agents on macOS: auto-allows local writes made reversible by git or Time Machine, blocks network, package installs, process control and sensitive-path reads, with full audit logs.
dsh-unsandboxed-winbash
xswt442-cmd/dsh-unsandboxed-winbash
让 dsh 在 Windows 上使用用户自安装的 Git Bash,并绕过其沙箱限制 | Enable dsh to use a user-installed Git Bash on Windows by bypassing its sandbox restrictions.
dsh-almazom-approve-escalate
almazom/dsh-almazom-approve-escalate
One-click Approve & escalate on the approval card: answers the pending request and switches the live session to a permission preset.
dsh-jumpserver
we39/dsh-jumpserver
Query and manage JumpServer through conversation: assets, users, accounts, permissions, sessions, command audit logs, command filters, and RBAC roles, authenticated with an AccessKeyID/AccessKeySecret pair (HTTP Signature).
dsh-fs-allowlist
wangzhaonan16/dsh-fs-allowlist
Approval-free writes into whitelisted directories — wraps the filesystem fence for write/edit tools and auto-answers bash sandbox escalations that touch whitelisted paths, with a settings GUI.
dsh-auto-pass
sujingkpo/dsh-auto-pass
A continuation of simon300000/dsh-auto: the Auto Approve permission preset for the DSH Web UI reviews each approval with one single-shot model call instead of a reviewer subagent, auto-approves only the actions that pass and hands the rest to human approval, and remembers confirmed decisions as project- and global-scope allow/deny lists, with an approval timeline in the right sidebar.
dsh-sandbox-arg-guard
apex-mochen/dsh-sandbox-arg-guard
Keeps a redundant sandbox-escalation argument from failing a tool call. Escalating tools (pwsh, bash, write, edit) advertise the full sandbox_permissions enum, but DSH only accepts a level strictly wider than the one already in effect — a check its own source calls 'deliberately not a schema constraint'. A model that reflexively passes the argument therefore picks the level it is already at and the call dies before running with 'sandbox escalation to "workspace-write" is not strictly wider than this call's current "workspace-write" mode', costing some models a whole turn of retries. This plugin registers one tools/execute waterfall listener and, only on that documented rejection and only when the arguments really carried an escalation field, re-issues the identical call once without it. Safe by DSH's own documentation: the rejection precedes any execution ('nothing has run'), and the corrected call cannot match again, so the retry is loop-free. Reproduced and verified end to end — before: isError true, the command never ran; after: the command's real output, isError false, one tool/call and one tool/result. Zero dependencies.