플러그인
DeepSeek-Harness 플러그인을 찾아보고, 필터링하고, 설치하세요.
플러그인 89개 찾음
nexusclaw-agent-governance
nexusclawhq/nexusclaw-agent-governance
agent-governance 사이드카를 기반으로 한 DeepSeek Harness(dsh) 승인 응답기 — 모든 승인/요청은 기본 거부(deny-by-default) 게이트, L0–L4 규칙 및 조직 감사 체인에 의해 결정됨.
dsh-Almost_Full_Access
alnita-m/dsh-almost_full_access
workspace-write와 full access 사이의 권한 모드: 셸 명령은 결정적 규칙과 서브에이전트 검토로 확인되며, 되돌릴 수 없거나 시스템 수준의 작업은 명시적 승인이 필요함.
super-wechat-bridge
qshuai0213/super-wechat-bridge
WeChat iLink ClawBot 브리지: Tencent 공식 iLink 프로토콜, Web UI 설정(QR 로그인/모델/프리셋/권한/삭제가 포함된 세션 관리), 24시간 자동 갱신으로 만료 전 새 QR 푸시, 무중단.
dsh-perm-guard
a903067276-rgb/dsh-perm-guard
자동 승인 권한 가드: workspace-write와 danger-full-access 사이의 중간 계층 — 신뢰 디렉터리 내 안전한 작업은 자동 허용하고, 파괴적인 작업은 항상 사람에게 확인을 요청합니다. 카테고리별 스위치 11개와 감사 로그를 제공합니다.
dsh-auto-classifier
pakiknowledge/dsh-auto-classifier
auto 프리셋용 자율 권한 분류기: 도구 단위 allow/deny 규칙, LLM 의미 판정, 무인 세션용 git 체크포인트.
dsh-auto-reviewer
antarescorn/dsh-auto-reviewer
Codex 스타일 자동 검토 권한 모드로, 안전한 샌드박스 에스컬레이션은 자동 승인하고 위험하거나 모호한 경우에는 확인을 요청하며 확인되지 않은 중대한 작업은 거부하는 자동 검토 프리셋을 추가합니다.
dsh-sound-lab
miiaowuwu/dsh-sound-lab
DSH용 이벤트 사운드: 세션 종료, 선택지 팝업, 권한 요청, 중지 시 선택한 소리를 재생합니다. AI 생성 캐릭터 음성 대사와 관리 가능한 사운드 라이브러리 포함.
dsh-auto-approval-plugin
styxnether/dsh-auto-approval-plugin
DeepSeek Harness의 workspace-write와 danger-full-access 사이의 중간 권한 등급: 무해한 명령과, 설정된 신뢰 영역(현재 워크스페이스 외부 포함)을 대상으로 하는 작업을 자동 승인
dsh-fleet-audit
lesliewylie/dsh-fleet-audit
읽기 전용 에이전트 플릿 자격 증명 위생 감사: 자격 증명 파일 권한, git 원격에 포함된 자격 증명(출력에서 마스킹), 프로바이더 토큰 리터럴 개수; 의존성 없음, 결정적 동작
dsh-feishu-cui
wanjiaju3108/dsh-feishu-cui
Remote DSH access that needs no hosting of your own — the Feishu DM chat is the interface over the bot's outbound long connection, with cards for workspace, session (switch and rename), model, reasoning effort, permission preset and balance, and tool approvals and agent questions answered in that same chat.
dsh-vscode (dsh-door)
elk-9527/dsh-vscode
Loopback-only ACP door for DeepSeek Harness: attach an external client (such as the DSH Panel VS Code extension) to the kernel you already have running, exposing session listing and permission presets.
dsh-tm-guard
chaojie0/dsh-tm-guard
Zero-intervention permission gate for DSH agents on macOS: auto-allows local writes made reversible by git or Time Machine, blocks network, package installs, process control and sensitive-path reads, with full audit logs.
dsh-almazom-approve-escalate
almazom/dsh-almazom-approve-escalate
One-click Approve & escalate on the approval card: answers the pending request and switches the live session to a permission preset.
dsh-jumpserver
we39/dsh-jumpserver
Query and manage JumpServer through conversation: assets, users, accounts, permissions, sessions, command audit logs, command filters, and RBAC roles, authenticated with an AccessKeyID/AccessKeySecret pair (HTTP Signature).
dsh-auto-pass
sujingkpo/dsh-auto-pass
A continuation of simon300000/dsh-auto: the Auto Approve permission preset for the DSH Web UI reviews each approval with one single-shot model call instead of a reviewer subagent, auto-approves only the actions that pass and hands the rest to human approval, and remembers confirmed decisions as project- and global-scope allow/deny lists, with an approval timeline in the right sidebar.
dsh-sandbox-arg-guard
apex-mochen/dsh-sandbox-arg-guard
Keeps a redundant sandbox-escalation argument from failing a tool call. Escalating tools (pwsh, bash, write, edit) advertise the full sandbox_permissions enum, but DSH only accepts a level strictly wider than the one already in effect — a check its own source calls 'deliberately not a schema constraint'. A model that reflexively passes the argument therefore picks the level it is already at and the call dies before running with 'sandbox escalation to "workspace-write" is not strictly wider than this call's current "workspace-write" mode', costing some models a whole turn of retries. This plugin registers one tools/execute waterfall listener and, only on that documented rejection and only when the arguments really carried an escalation field, re-issues the identical call once without it. Safe by DSH's own documentation: the rejection precedes any execution ('nothing has run'), and the corrected call cannot match again, so the retry is loop-free. Reproduced and verified end to end — before: isError true, the command never ran; after: the command's real output, isError false, one tool/call and one tool/result. Zero dependencies.
dsh-github-companion
vclike/dsh-github-companion
33 github_* tools covering REST reads, issue writes, Git data writes, private repo creation, and clone; in-process permission gate and cost-discipline companion skill; no gh CLI required.
dsh-git-idea
mays-hi/dsh-git-idea
Git integration for DSH modelled on IDEA's VCS: a git icon beside the permission mode in the composer shows the current branch and the pending-change count, opens a branch switcher on hover and an IDEA-style VCS panel on click (branch tree, commit graph, changes and staging, commit detail, file diff), plus a settings page for commit identity, the git binary and the network flags. Registers no model tools with DSH.
dsh-mac-cua
saunato/dsh-mac-cua
Computer Use for macOS desktop applications: reads any app's accessibility tree as text with element indices, then clicks, types, pastes, scrolls, drags, selects text and sets values through it, plus screenshots read back as images. Driven by a persistent JavaScript REPL — the agent gets two tools (`js`, `js_reset`) and calls an `sky` API inside them, so state survives between calls and the tool schema stays fixed as capabilities grow. Accessibility trees come back as diffs after the first read; actions address elements by index and indices from a stale read are refused rather than misapplied; typing waits for keyboard focus and reads the field back; paste restores the clipboard. Requires macOS 14.4+, Accessibility permission (Screen Recording only for screenshots) and Node 20+; ships a prebuilt native module, so nothing compiles at install time.
dsh-rail-equalizer
yuanyihy/dsh-rail-equalizer
System-audio visualizer for the turn navigator rail: the rail reacts in real time to whatever the default playback device is rendering, with four motion modes (spectrum, pulse, sway, travelling wave), a 16-band logarithmic spectrum from a 2048-point FFT on the host, and live sensitivity, strength, bass-punch and wave-speed controls. Audio is captured host-side through WASAPI loopback, so there is no permission prompt, no microphone and no screen capture. The browser half adds one attribute, one stylesheet, some CSS variables and a sidebar control row, and never patches the official component; switching it off removes the attribute, the stylesheet and the variables, returning the rail to its default styling. Windows only.
dsh-plugin-sage-subagent
gezi-wen/dsh-plugin-sage-subagent
Named, file-defined subagent roles for DeepSeek Harness: persona, subagent-only skills, tool permissions, an ordered model chain with failover, and derived groups.
dsh-bash-escalation-gate
ruby1304/dsh-bash-escalation-gate
Require a real, immediately preceding sandbox denial before DSH Bash can request wider permissions.
dsh-escalation-advisor
zhangqian98/dsh-escalation-advisor
Three-mode visible-session advisor plugin for DeepSeek Harness with configurable tool permissions, local-subagent coverage, and task-tree budgets.
dsh-sub-cli
dingminhua/dsh-sub-cli
Unified management and invocation of external Agent CLIs in DSH, fully isolated from the user's native installs; preset Provider, model, reasoning effort, and permissions per CLI, callable directly or like native subagents.