Plugins
Parcourez, filtrez et installez des plugins DeepSeek-Harness.
88 plugins trouvés
dsh-llm-approve-for-me
alaxrpg/dsh-llm-approve-for-me
Uses an isolated LLM review to approve or reject DSH sandbox permission requests.
dsh-claude-driver
zhangjunjesse/dsh-claude-driver
Run the main session model on a local Claude Code subscription through the official Claude Agent SDK, taking over the llm/stream route for the claude-code provider, with token-level streaming, session resume, and DSH tools bridged in over MCP so they keep DSH sandbox and approval.
dsh-plugin-background-tasks
yaopushen/dsh-plugin-background-tasks
Antigravity-style run_command for DSH: short commands return inline within a configurable wait window (default 10s) while longer ones auto-promote into ctx.jobs for later collection and completion notices — executed via ctx.shell under the session sandbox and approval pipeline.
dsh-auto-review
accpowered/dsh-auto-review
LLM approval answerer for sandbox escalations beyond workspace-write: a deterministic regex filter first, then a clean-context reviewer model; humans are asked only when it is unsure. Requires the bundled core patches.
dsh-multi-folder-workspace
boy-grid/dsh-multi-folder-workspace
Multi-folder workspace for DeepSeek Harness: pick several folders and create one workspace spanning them (directory-flow occupant + extended workspace/sandbox contract)
dsh-codex
wode25500/dsh-codex
Enveloppe pour l'interface CLI OpenAI Codex : exécution en une fois, revue de dépôt et reprise de session avec un bac à sable en lecture seule par défaut.
dsh-safety-net
asuna486-desuwa/dsh-safety-net
Garde-fous d'autoprotection pour DeepSeek Harness : interception des chemins protégés, sauvegarde avant destruction, commandes d'auto-récupération en CLI et configuration par défaut en bac à sable strict.
dsh-auto-reviewer
antarescorn/dsh-auto-reviewer
Mode d'autorisation de révision automatique de style Codex : ajoute un préréglage de révision automatique qui approuve automatiquement les élévations de bac à sable sûres, demande pour celles risquées ou ambiguës et refuse les opérations critiques non confirmées.
dsh-multi-workspace
somnusovis/dsh-multi-workspace
Bac à sable multi-workspace : accorde automatiquement l'accès en écriture à tous les workspaces enregistrés — ajoutez un workspace, écrivez-y immédiatement, sans configuration ni escalade.
sandbox-mxc
omdsh-dev/sandbox-mxc
Prise en charge du sandbox multiplateforme Microsoft.
dsh-escalation-review
trentswd/dsh-escalation-review
Escalation-only LLM reviewer: reviews sandbox escapes only, keeps the sandbox, fails closed.
DSH-Rtk-rewrite
mengqi1436/dsh-rtk-rewrite
Replaces the web profile's pwsh shell executor with a subclass that rewrites every command through `rtk rewrite` before execution for token savings, running the original command unchanged on any rewrite failure (no equivalent, missing rtk, timeout) and keeping sandbox semantics intact.
dsh-fs-allowlist
wzn16/dsh-fs-allowlist
Approval-free writes into whitelisted directories — wraps the filesystem fence for write/edit tools and auto-answers bash sandbox escalations that touch whitelisted paths, with a settings GUI.
dsh-approval-gate
iamnewhands/dsh-approval-gate
Maintained fork of dsh-approval-gate. A neutral operation whose confirmation count has reached the threshold auto-approves when the judge is unavailable, instead of prompting a human again; approver-facing explanations are generated in Chinese from the real sandbox mode, command and paths. Also carries deterministic hard-deny for credential exfiltration and system-path destruction, judge-input redaction, a judge model candidate chain, fingerprint-scoped allow rules, and an approval view with unified diff and one-click revert.
dsh-native-provider
libre-webui/dsh-native-provider
Use your DSH models in [Libre WebUI](https://github.com/libre-webui/libre-webui) for chat, sandboxed Work and usage tracking, with provider credentials kept in DSH. Requires Libre WebUI 0.37.0 or later.
dsh-unsandboxed-winbash
xswt442-cmd/dsh-unsandboxed-winbash
让 dsh 在 Windows 上使用用户自安装的 Git Bash,并绕过其沙箱限制 | Enable dsh to use a user-installed Git Bash on Windows by bypassing its sandbox restrictions.
dsh-fs-allowlist
wangzhaonan16/dsh-fs-allowlist
Approval-free writes into whitelisted directories — wraps the filesystem fence for write/edit tools and auto-answers bash sandbox escalations that touch whitelisted paths, with a settings GUI.
dsh-sandbox-arg-guard
apex-mochen/dsh-sandbox-arg-guard
Keeps a redundant sandbox-escalation argument from failing a tool call. Escalating tools (pwsh, bash, write, edit) advertise the full sandbox_permissions enum, but DSH only accepts a level strictly wider than the one already in effect — a check its own source calls 'deliberately not a schema constraint'. A model that reflexively passes the argument therefore picks the level it is already at and the call dies before running with 'sandbox escalation to "workspace-write" is not strictly wider than this call's current "workspace-write" mode', costing some models a whole turn of retries. This plugin registers one tools/execute waterfall listener and, only on that documented rejection and only when the arguments really carried an escalation field, re-issues the identical call once without it. Safe by DSH's own documentation: the rejection precedes any execution ('nothing has run'), and the corrected call cannot match again, so the retry is loop-free. Reproduced and verified end to end — before: isError true, the command never ran; after: the command's real output, isError false, one tool/call and one tool/result. Zero dependencies.
dsh-git-bash
vvilliam-qwq/dsh-git-bash
Make a Git for Windows installation resolvable as `bash` inside the dsh host process, so the official bash shell stack (dsh-bash-sandbox + dsh-tool-bash) can run on Windows
dsh-engineer-tools
bycall/dsh-engineer-tools
Engineering work-tools for DeepSeek Harness: registers two model-facing Host Tools — a scoped `git` runner, and a package-manager runner (`dev`) that detects npm/pnpm/yarn/bun from the workspace lockfile and picks the right verb per manager. Both run through dsh's sandboxed shell and return structured stdout/stderr/exitCode, so the agent gets focused, reviewable results instead of raw bash, and adding another tool is a copy-paste of one register block.
dsh-bash-escalation-gate
ruby1304/dsh-bash-escalation-gate
Require a real, immediately preceding sandbox denial before DSH Bash can request wider permissions.
dsh-patch-edit-plus
drscrewdriver/dsh-patch-edit-plus
Patch-style file editing: one apply_patch tool accepting git/unified diff (default) and Codex apply_patch syntax (opt-in), applying every change all-or-nothing after a full read-only verification pass, with sandbox-aware delete and move and a dry-run mode.
dsh-rtk-plugin
errrepe/dsh-rtk-plugin
RTK (Reusable Token Kompressor) tool for DeepSeek Harness — token-optimized CLI proxy exposing read/ls/git/grep/err/test/json and more through the standard shell sandbox.
dsh-teaching-board
arcaneorion/dsh-teaching-board
Teaching board view: agent-generated self-contained HTML is projected into a sandboxed iframe as a board, annotated by hand (brush, four colours, eraser, undo), extended in place across several tool calls, and screenshotted back into the conversation as a real user message.