Plugins
Browse, filter, and install DeepSeek-Harness plugins.
129 plugins found
dsh-gamepad-approval
goldgish/dsh-gamepad-approval
Xbox 手柄硬件审批 dsh 插件 — Agent 高危工具调用需物理按键确认(A 批准 / B 驳回)
dsh-cert-mcp
perrylink/dsh-cert-mcp
Read-only MCP server over the DSH plugin-certification registry, exposing a plugin certification grade, its snapshot and the five-dimension evidence behind it.
dsh-semgrep-sast
baiiduu/dsh-semgrep-sast
Semgrep SAST bundle and model-facing scan tool for DeepSeek Harness.
dsh-dolphin-security
ccr-wer/dsh-dolphin-security
此为 DSH 生态插件。Dolphin - 主动巡检型安全防御插件,支持本地扫描与远程 SSH 巡逻。将渗透测试方法论(信息收集→漏洞探测→利用验证→报告)转化为主动防御巡检流程:基于 Semgrep 的扫描层与基于 SSH 的执行层相融合,可对本地目录做静态扫描,也可将扫描命令经 SSH 下发至远程主机执行并回收结构化结果。
dsh-memory-nexus
frank-nf/dsh-memory-nexus
Integrated memory and context management plugin: four-layer memory system (L2-L4), context compression/trimming/freezing, prompt orchestration, input box UI buttons, and enterprise security with role-based access control.
dsh-security-guard
weisofns/dsh-security-guard
DSH plugin security guard: 28-rule static scanner, risk scoring, whitelist/blacklist policy, local web dashboard and in-DSH risk popups.
dsh-route-fence-linter
vladimir-kryshchenko/dsh-route-fence-linter
Audits every plugin HTTP route in a profile for a browser-trust fence: plugin routes win the web server's longest-prefix match ahead of the /api gateway, so they never see its trust check and must pin the Host to loopback themselves. Grades PASS/WARN/FAIL per route and fails a fence that compares Origin to Host without pinning it (bypassable by DNS rebinding). Ships as a CLI for CI and a route_fence_scan tool.
dsh-security-guard
ruanhaodong-tt/dsh-security-guard
Runtime security guard for DSH: loader import confinement, HTTP Host header validation, and source patch for VM sandbox escapes (4 CVEs). AI-assisted.
dsh-shadow-auditor
goodandready/dsh-shadow-auditor
Background security auditor for DeepSeek Harness: scans agent outputs for secret leakage, checks command safety before execution, and surfaces findings in a persistent audit log.
dsh-malware-audit
rand0wn/dsh-malware-audit
Real AST-based scan of installed plugins for malicious-intent patterns (dynamic eval, cross-plugin writes, exfiltration-shaped network calls), with an optional periodic schedule and auto-quarantine on critical findings.
dsh-plus-plus
limlnx523/dsh-plus-plus
Adds a /dshpp slash command that reports session and token usage, cache-hit rate, and estimated cost from harness session logs; the repo also ships a CLI and local web console for lifecycle, provider, session, and plugin-security management.
dsh-tu4-inline-images
zehenk/dsh-tu4-inline-images
对话内联图片 DSH 插件 — 在 DeepSeek Harness (DSH) Web GUI 的对话中,出现本地图片路径即直接渲染为图片。 A DSH plugin that renders local image paths as inline images in DeepSeek Harness (DSH) web conversations. Security-first: loopback-only route, strong per-process token, multi-root realpath whitelist.
dsh-plugin-recommender
mimosa776/dsh-plugin-recommender
Role-based plugin recommender for DSH: asks the user's role (developer, designer, writer, researcher, ops, student...), recommends suitable plugins, and audits each with a local static security scan (dangerous code patterns + 0-100 risk score) and a reputation check (npm downloads / GitHub stars).
dsh-token-vault
yyfather/dsh-token-vault
Secure credential vault for DeepSeek Harness: store GitHub/npm/API tokens (secrets never leave the host), run gh/npm/npx/node/git with the token injected in the environment, and manage tokens from a Settings page.
correctover
dshcorrectover/correctover
AI Agent runtime authorization & evidence verification — tool-call GuardrailProvider, CCS 7-dimension verification standard, MCP/DSH security scanner, SSRF/command-injection/credential-exfil blocking with Ed25519 signed receipts.
dsh-agentvalet
agentvalet/dsh-agentvalet
Governed platform access for DeepSeek Harness — no credential on the machine
dsh-dros-vajraclaw
top-celestial-company-ltd/dsh-dros-vajraclaw
Local tool-call failsafe for DSH: blocks a fixed list of high-risk shell patterns and credential-file reads before execution, with a per-session hash-linked JSONL audit log, and an optional external Gateway for centralized policy.
capmark
taltara/capmark
Hold a DeepSeek Harness agent to a capmark capability manifest: mask its tools and judge every call.
dsh-plugin-scorecard
863683348/dsh-plugin-scorecard
Quality & security scorecard for the DSH plugin ecosystem: sync the dsh-plugin topic catalog, audit any plugin (0-100, A-D, security veto), rankings, search, and historical score curves with a workspace-persisted catalog.
dsh-taintguard
sashankh/dsh-taintguard
Taints the agent when tool results carry untrusted content, gates the privileged calls that follow, and refuses credentials passed to network-capable tools in every mode.
dsh-managed-approval
jalllychun/dsh-managed-approval
Codex-inspired managed approval for DeepSeek Harness: risk-based MCP review, one-time grants, explicit denials, and human fallback on reviewer failure.
dsh-plugin-browser-use
coderdailyone/dsh-plugin-browser-use
Browser-automation tools for DeepSeek Harness (dsh): Chromium via playwright-core behind a security-first navigation policy re-checked on every action
dsh-lan-gate
maxesisnclaw/dsh-lan-gate
Password + CIDR gate for DeepSeek Harness web / DeepSeek Harness 局域网密码门禁
dsh-credentials-vault
tancheng33/dsh-credentials-vault
HashiCorp Vault backend for the credential seam: KV v2/v1, AppRole machine auth, per-operation reads so rotation needs no restart, and compare-and-swap writes.