Plugins
Browse, filter, and install DeepSeek-Harness plugins.
135 plugins found
dsh-tailscale-gateway
tiantianflow/dsh-tailscale-gateway
Private Tailscale access for DeepSeek Harness Web that allowlists users from the trusted Tailscale-User-Login header that Serve injects, with a loopback-only gateway and guarded Serve setup.
upstream-radar
micromilo/upstream-radar
Watches DSH and plugin releases, retests exact published artifacts in disposable runners, publishes machine-readable compatibility evidence, and reconciles managed issues after fixes.
project-koma
swnotmetal/project-koma
DeepSeek Harness adapter for Koma Miko Agent Specs.
dsh-skill-7d-code-reviewer
7dgroup-ai/dsh-skill-7d-code-reviewer
Template-driven code review skill: five-step review flow, critical/medium/minor severity grading, four-dimension scoring (quality, security, performance, maintainability), dual text and HTML report output, and an on-demand reference knowledge base.
dsh-expert-team
yangdcm/dsh-expert-team
Role-based multi-agent team for DeepSeek Harness. The /team command assembles up to 12 specialist subagents (product, architect, researcher, UI, backend, frontend, database, security, reviewer, QA, DevOps, docs) and runs a nine-phase gated pipeline (clarify, research, design, spec review, plan approval, implement, review, test, deliver) over a shared workspace of artifacts (SPEC, PLAN, TASKS, STATE, REVIEW, TEST). Quality gates are enforced by plugin code rather than requested in prompts: an unfinished task cannot be marked completed, quality findings must be adjudicated by the reviewer or QA role, and coverage gaps or rework over budget appear live in the overlay and in /team status. Ships a live team overlay (phases, roster with per-role models, task DAG, artifact preview, decision buttons), a persistent-team mode that resumes across sessions, and per-run token and time accounting. Zero runtime dependencies, no build step.
dsh-score
perrylink/dsh-score
Multi-dimensional quality scoring for DeepSeek Harness plugins that scores a repo or npm package across install success, maintenance activity, documentation completeness, security scan, and protocol compliance using real CLI evidence, and produces a JSON or Markdown leaderboard report.
agent-useful-skills
azzygoatcoder/agent-useful-skills
Modular AI research/engineering skill pack, installable via dsh plugin add — registers 27 skills (security audit, paper reading/writing, figure drawing, dev workflow, storage analysis) on ctx.skills.
dshscan
shaoshi20/dshscan
Security scanner for DSH plugins: static and semantic passes over plugin source, DSH-specific attack-surface rules, npm audit, batch scanning, and an HTML report with per-finding severity and evidence.
dsh-riskproof
onlyqzq/dsh-riskproof
Live security beacon for DSH that follows tool activity. Click to view call statistics, risk provenance chains and blocked actions, with read-only task restrictions and tool metadata change detection.
dsh-gateway
clarknu/dsh-gateway
HTTPS + login gateway for the DeepSeek Harness web surface: access your DSH Web UI securely from another machine on your LAN, or from the internet via port forwarding. Fail-closed defaults (loopback-only, no accounts until configured); setup and security notes in the README.
dsh-auth
hxy91819/dsh-auth
Caddy forward_auth administrator login for DeepSeek Harness Web, with Argon2id passwords, revocable sessions, bilingual UI, and a native sidebar sign-out action.
npm-safe-fordsh
nisconder/npm-safe-fordsh
DeepSeek Harness plugin that blocks risky npm installs with metadata and deep supply-chain scans
dsh-plugin-audit
jkrandom-sudo/dsh-plugin-audit
Security audit plugin for DeepSeek Harness: static permission profiling and a runtime sentinel for third-party plugins
dsh-sentinel-scanner
eligahyu/dsh-sentinel-scanner
Static security scanner for DSH plugins: read-only audit (exec, credentials, exfiltration, obfuscation, install scripts, bundle manifest) with a 0-100 risk score.
dsh-plugin-security-review
ateen18/dsh-plugin-security-review
Pre-install static security review and runtime guard for dsh plugins: deobfuscation decoding, supply-chain checks, web one-click review/install/uninstall, and optional runtime tool-call guard.
gitee-ai-employee
wangbobo-coder/gitee-ai-employee
Gitee/GitHub AI employee: @ the bot on an issue (Gitee or GitHub), it clones the repo, implements the fix on the branch you name, opens a PR to that branch, and can auto-merge and auto-close the issue. v1.2 adds security scanning: configure scan repos, audit with built-in/custom prompts, deduplicate, and file new findings as issues.
securstack-dsh-plugin
securstack/securstack-dsh-plugin
DeepSeek Harness plugin for SecurStack security scans, policy checks, doctor diagnostics, and JSON CLI results.
DSH-Plugin-Market
nanshan1995/dsh-plugin-market
Alternative plugin market for DSH: curated catalog plus live GitHub browsing, zh/en cross-language search, a fail-closed pre-install static security audit with an install-hook block, and per-plugin README viewing with garbled-encoding repair.
dsh-guardian
cdxiaodong/dsh-guardian
Agent security guardrail: intercepts and audits every tool call, requiring human confirmation on sensitive operations.
dsh-lab
hackerfish/dsh-lab
Tested-curation lab for DSH plugins: every entry passes real install/static-scan gates in an isolated environment, with full logs and reproduction commands (Chinese-first).
dsh-workshop
loguhan/dsh-workshop
Steam Workshop-style plugin store for the DSH Web UI: browse, search, and one-click install community plugins with mirror acceleration, progress UI, security checks, and Chinese descriptions.
dsh-redteam-mode
jueze-2019/dsh-redteam-mode
DSH RedTeam 模式:一句话拉起红队作战智能体(资产测绘 / 攻击链 / 得分目标 / 报告 / POC 知识库),含四个角色、13 个原生技能与常驻右侧控制台
dsh-reach
perrylink/dsh-reach
Pushes DSH approval and question cards to IM channels (WeChat first) and answers them from chat, with a session console, per-channel security, and an open push service.
dsh-secret-scrub
jkt-check/dsh-secret-scrub
Irreversible secret-scrubbing guard: rewrites access keys, bearer tokens, and private key blocks into `[REDACTED:<category>]` placeholders before they reach the session log and the model.