セキュリティと権限
セキュリティと権限プラグインは、危険なツール呼び出しや悪意あるプラグインから DeepSeek-Harness(dsh)を守ります。このカテゴリには、allow/deny/ask の階層を持つポリシーベースのツールゲート、プラグインバンドルや npm tarball のインストール前スキャナー、プロンプトインジェクションと秘密情報流出の防御、テレメトリのマスキング、ハッシュチェーン型の監査ログが含まれます。
269 件のプラグインが見つかりました
dsh-plugin-trustlens
mengshang-spec/dsh-plugin-trustlens
Read-only DSH plugin auditor with static scanning, current-session model review, and confirmation gates.
dsh-full-access-switch
xtd1145/dsh-full-access-switch
One-time Full access switch for DeepSeek Harness: new sessions (workspaces and conversations) start with danger-full-access and skip the per-session Full access confirmation; installable as a dsh bundle or via patch scripts.
dsh-feishu-channel
wyattjhayes/dsh-feishu-channel
Security-focused Feishu (Lark) channel for DeepSeek Harness: allowlisted remote-agent access with workspace-scoped paths, symlink checks, risk-based approvals, session isolation, redacted logs, and bounded message queues.
dsh-hawkeye-scan (npm)
liuqingman/dsh-hawkeye-scan
AI-driven source-code security scanning workbench: 5 model tools (start/finding/status/report/list) plus a /hawkeye web UI and JSON/Markdown/HTML vulnerability reports; zero-dependency Cordis plugin, installable as agent preset or npm package.
dsh-llm-approve-for-me
alaxrpg/dsh-llm-approve-for-me
Uses an isolated LLM review to approve or reject DSH sandbox permission requests.
dsh-plugin-guard
taxueseek/dsh-plugin-guard
Static-only plugin gate and clinic for DSH: audit before install, hash-and-capability lock after install, local fingerprint peer search over GitHub topic:dsh-plugin, and mechanical detox. Never executes the target plugin.
dsh-auto-review
accpowered/dsh-auto-review
LLM approval answerer for sandbox escalations beyond workspace-write: a deterministic regex filter first, then a clean-context reviewer model; humans are asked only when it is unsure. Requires the bundled core patches.
dsh-credential-manager
accpowered/dsh-credential-manager
Named user credentials the model uses by reference: values are entered on a Settings → Credentials page and injected into each shell execution as DSH_CM_* variables instead of being printed into the transcript, with credential_read as the documented last resort.
dsh-compaction-audit
gendui123/dsh-compaction-audit
Compaction quality / hallucination detector: when a conversation span is compacted, check on two axes that key information survived 鈥?FIDELITY (assertions in the summary must be found verbatim in the original leaf events, else flagged as fabricated) and C
dsh-compaction-probe
gendui123/dsh-compaction-probe
Step-0 observation probe for dsh-compaction-audit: logs every compaction/* session event and probes whether shadowedSeqs still resolve to readable events in session.events. Observe-only; never injects, never blocks.
dsh-plan-adversarial
gendui123/dsh-plan-adversarial
Command-triggered red/blue adversarial review for ANY plan (not quant-specific). /plan-adversarial <plan>: arms a gate that requires the agent to derive two independent subagents (red=attack, blue=defend), have them converge on a consensus plan with NO th
dsh-todo-guard
a903067276-rgb/dsh-todo-guard
Reliable todo panel that survives restarts (official panel only re-renders on write — fixed via projection pre-warm) with three-state completion verification: evidence exists → verified, fake evidence → blocked, no evidence → unverified badge; settings toggle to fall back to official behavior.
dsh-skill-security-inspector
kakapengta/dsh-skill-security-inspector
一个可直接链接到 DeepSeek Harness(DSH)Web profile 的独立安全检查插件。在安装或使用不受信任的 Skill 前,先执行浏览器本地粗检,再由用户决定是否调用 DSH 已配置的大模型进行结构化复核。
forge
mjxupup/forge
Forge quality gates for DeepSeek Harness (dsh): task gates, read-before-edit, bash hazard interception and quality scoring, driven by the forge CLI through DSH's typed interception points.
dsh-guardian-approval
scotlight/dsh-guardian-approval
DSH向けの独立したCodex Guardian風承認レビューアー
nexusclaw-agent-governance
nexusclawhq/nexusclaw-agent-governance
agent-governance サイドカーによる DeepSeek Harness (dsh) 承認応答装置 — すべての承認/リクエストはデフォルト拒否のゲート、L0〜L4 ルール、および組織監査チェーンによって決定される。
dsh-provenance
darren-tang/dsh-provenance
DeepSeek Harness プラグインのインストール前サプライチェーンチェック:インストールしようとしている tarball が、あなたが読んだソースと一致するかを、コードが実行される前に検証。
dsh-Almost_Full_Access
alnita-m/dsh-almost_full_access
workspace-write と full access の中間の権限モード:シェルコマンドは決定論的ルールとサブエージェントレビューでチェックされ、不可逆またはシステムレベルの操作には明示的な承認が必要。
dsh-perm-guard
a903067276-rgb/dsh-perm-guard
自動承認の権限ガード:workspace-writeとdanger-full-accessの中間層 — 信頼ディレクトリ内の安全な操作は自動承認し、破壊的な操作は必ず人間に確認を求める。カテゴリ別スイッチ11個と監査ログを備えています。
dsh-write-gate
couldbeme/dsh-write-gate
コミットメント書き込みゲート:ツール呼び出しの実行前に運用者が作成したルールを適用 — 決定論的なガード層と LLM 審判層、既定で fail-closed、ブロックはすべて矛盾ログに記録されます。
skill-security-guard
rrrrrredy/skill-security-guard
skill-security-guard 静的スキャナーのための DeepSeek Harness コミュニティ Bundle。
dsh-access-gate
bamboostrip/dsh-access-gate
DSH プラグイン。リモート(非ループバック)の /api アクセスに対するパスワードゲート(デフォルトではパスワードなし)。ループバック固定の特権エンドポイントのブロックを解除し、アンインストール時にすべてを復元し、ローカルの 127.0.0.1 ユーザーにワークスペース選択用のネイティブ OS フォルダピッカーを提供します。selec
dsh-safety-net
asuna486-desuwa/dsh-safety-net
DeepSeek Harness の自己保護ガードレール。保護パスの傍受、破壊前バックアップ、CLI 自己復旧コマンド、厳格なサンドボックスのデフォルト化を提供します。
riskproof
onlyqzq/riskproof
DeepSeek Harness 向けの来歴を考慮した実行セキュリティ。ツール呼び出しをまたいで機密データを追跡し、実行前に危険な副作用を阻止します。