Plugins
Browse, filter, and install DeepSeek-Harness plugins.
12 plugins found
upstream-radar
micromilo/upstream-radar
Watches DSH and plugin releases, retests exact published artifacts in disposable runners, publishes machine-readable compatibility evidence, and reconciles managed issues after fixes.
dsh-riskproof
onlyqzq/dsh-riskproof
Live security beacon for DSH that follows tool activity. Click to view call statistics, risk provenance chains and blocked actions, with read-only task restrictions and tool metadata change detection.
dsh-acp-plugin
agentic-control-plane/dsh-acp-plugin
Agentic Control Plane for DeepSeek Harness — check every tool call against your policies before it runs, and keep a durable record of what was allowed and why.
dsh-file-shield
yazzyk/dsh-file-shield
Blocks an agent from reading, searching, writing, or editing chosen files and directories, keeping their contents out of the conversation — including sensitive-word files whose text can make later provider requests fail with a 400. Rules are picked from a file/directory browser on the plugin page.
dsh-auto-review
jhckevin/dsh-auto-review
Native Auto Review for DeepSeek Harness with automatic host compatibility selection
dsh-skill-security-inspector
kakapengta/dsh-skill-security-inspector
一个可直接链接到 DeepSeek Harness(DSH)Web profile 的独立安全检查插件。在安装或使用不受信任的 Skill 前,先执行浏览器本地粗检,再由用户决定是否调用 DSH 已配置的大模型进行结构化复核。
skill-security-guard
rrrrrredy/skill-security-guard
DeepSeek Harness community Bundle for the skill-security-guard static scanner
deskpet-guard
cny1230/deskpet-guard
Agent 行为守护桌宠:跨 agent 监控可疑外传(加密打包直传对象存储 / DNS 外泄线索 / 敏感密钥被读),发现即告警,明确确认后按「一次一个」终止目标 agent;事件写入只追加 guard-events.jsonl,并通过 DSH host 工具 + MCP(stdio) 供其它 agent 查询
correctover
dshcorrectover/correctover
AI Agent runtime authorization & evidence verification — tool-call GuardrailProvider, CCS 7-dimension verification standard, MCP/DSH security scanner, SSRF/command-injection/credential-exfil blocking with Ed25519 signed receipts.
dsh-agentvalet
agentvalet/dsh-agentvalet
Governed platform access for DeepSeek Harness — no credential on the machine
dsh-dros-vajraclaw
top-celestial-company-ltd/dsh-dros-vajraclaw
Local tool-call failsafe for DSH: blocks a fixed list of high-risk shell patterns and credential-file reads before execution, with a per-session hash-linked JSONL audit log, and an optional external Gateway for centralized policy.
dsh-taintguard
sashankh/dsh-taintguard
Taints the agent when tool results carry untrusted content, gates the privileged calls that follow, and refuses credentials passed to network-capable tools in every mode.