Plugins
Browse, filter, and install DeepSeek-Harness plugins.
10 plugins found
dsh-auto-review
perrylink/dsh-auto-review
Second-model auto-review on the approval answerer chain: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default.
dsh-permission-rules
perrylink/dsh-permission-rules
Claude Code-style declarative permission rules: ordered allow/deny/ask YAML rules matching tool names, arguments, workspace paths, and agent identity on the tools/pre-execute waterfall, with full session-log audit, dry-run mode, and hot reload.
sofagent (cordis-plugin-sofagent-audit)
kongfangxun/sofagent
Commit-time audit harness for AI coding agents: 24 git-diff rules (secrets, out-of-scope edits, prompt injection), HMAC-signed audit trail, snapshot rollback, and an MCP server with 84 tools. Installable via dsh plugin add.
openguardrails
openguardrails/openguardrails
Auto mode for DeepSeek Harness (dsh): an Auto entry in the Permissions selector whose approval prompts are answered by OpenGuardrails policy instead of a human — plus the full OGR guard engine underneath. No core changes.
dsh-jev-interceptor
asktheway/dsh-jev-interceptor
Classifies pending tool calls with Jev (TypeSafe AI's non-generative decision model) on tools/pre-execute — confident high-risk calls are denied, ambiguous ones escalated to approval — and auto-approves clearly-granted reversible calls on approval/request behind argument-evidence gating. Also subclasses the session-reference resolver so snapshots keep Jev-scored messages instead of dropping oldest-first. Degrades to stock behavior on any provider failure; shadow mode with a /jev-stats command; TypeSafe or OpenRouter endpoints; 64 tests.
dsh-plan-lattice
1052326311/dsh-plan-lattice
Adds persistent execution contracts, recursive work graphs, critical clarification, and evidence gates for long or underspecified Harness tasks.
dsh-approval-review
lawli3tcoding/dsh-approval-review
Adds an "approve for me" access mode whose approval requests are answered by an independent reviewer model instead of a person: the reviewer can read the workspace read-only, a reviewer that cannot run hands the request back to the human, and every decision is recorded with its rationale in an Approvals tab.
dsh-netshell
xgone/dsh-netshell
Local and remote SSH terminals for DeepSeek Harness Web with three permission levels, human approval for risky AI commands, and encrypted credential storage.
solidforge-dsh
maskshell/solidforge-dsh
SolidForge on the DeepSeek Harness — the globally installed plugin face: five skills in every session's catalog plus /solidforge:<skill> colon-gesture injection and the /solidforge, /arm-tools commands.
correctover
dshcorrectover/correctover
AI Agent runtime authorization & evidence verification — tool-call GuardrailProvider, CCS 7-dimension verification standard, MCP/DSH security scanner, SSRF/command-injection/credential-exfil blocking with Ed25519 signed receipts.