Skip to main content

Plugins

Browse, filter, and install DeepSeek-Harness plugins.

31 plugins found

S

dsh-passwords

slywalker2006/dsh-passwords

Turns DeepSeek Harness into a server-grade multi-tenant platform: remote access + auto HTTPS, subuser permissions & token/daily quotas, sandbox enforcement, encrypted auth & audit log.

654 days agoSecurity & PermissionsGPL-3.0
A

dsh-computer-use

anionex/dsh-computer-use

Accessibility-first macOS computer use: fresh observations, stale-state rejection, scoped permissions, and safe input.

492 days agoTools & CapabilitiesMIT
O

openguardrails

openguardrails/openguardrails

Auto mode for DeepSeek Harness (dsh): an Auto entry in the Permissions selector whose approval prompts are answered by OpenGuardrails policy instead of a human — plus the full OGR guard engine underneath. No core changes.

272 months agoSecurity & PermissionsApache-2.0
T

dsh-minecraft-ui

tfboy1/dsh-minecraft-ui

Presents DSH Web as a playable, full-screen first-person Minecraft-style voxel interface—not a color-only skin: users walk through a persistent Three.js block world and access native workspaces, sessions, conversations, tools, model selection, permissions, context information, and the composer through in-world facilities and a workbench.

19last monthThemes & AppearanceMIT
S

dsh-plugin-product-subagents

shaokeyibb/dsh-plugin-product-subagents

Role-based Codex / Claude Code / ACP subagent providers for the DeepSeek Harness — continuable children, durable session recovery, per-role product permissions, and delegation with a permission ceiling.

182 months agoIntegrations & RemoteMIT
N

oh-my-dsh-slim

ninipa/oh-my-dsh-slim

Match your models and token budgets to each role, then let DSH delegate specialized subagents by task type. Covers architecture analysis, UI/UX, code implementation, codebase exploration, and documentation research, with automatic setup plus per-role reasoning effort and tool permissions.

144 days agoWorkflow & Automation
M

dsh-permgate

mrweicodes/dsh-permgate

Fine-grained permission gateway: per-category tool-call review (outside-workspace directories, commands, file read/write, subagents, repeated actions) with global & per-project allow/deny exceptions, quick-tool defaults, custom rules, a bilingual approval modal with inline diff details, custom rejection reasons and a sandbox-upgrade flow.

107 days agoSecurity & PermissionsMIT
A

dsh-multi-folder

angeloszou/dsh-multi-folder

Secondary working directories for a DSH project: the agent keeps the primary workspace as cwd and gains equal read/write/exec permissions on configured secondary directories, configurable from the session header and the new-session page.

103 days agoTools & CapabilitiesMIT
B

dsh-cc-ecosystem

bcy2020/dsh-cc-ecosystem

Load Claude Code assets into DSH at runtime — skills, slash commands, rules, permission rules (deny/ask/allow), subagents and hooks from .claude/ plus Claude Code plugins (plugin.json / marketplace / skills / agents / MCP), via a memory-IR parse layer that keeps .claude as the source of truth with no writes back. Six installable packages: loader, skills, permissions, agents, hooks, mcp.

58 days agoDev & Plugin Tools
L

dsh-mcp-lazy

leaforbook/dsh-mcp-lazy

Lazy-loading router for MCP servers: auto-discovers compatible MCPs and keeps only a shared router in the tool catalog, revealing a server's schemas when a turn needs them and hiding them again at turn end, so many installed MCPs stop costing context on every request. Falls open to normal visibility on any uncertainty, and the original MCP keeps ownership of execution, permissions and process lifecycle. Also supports explicit lazy connections with warm reuse, bounded reconnection, stdio and Streamable HTTP.

4last monthTools & CapabilitiesMIT
A

dsh-python-env

angeloszou/dsh-python-env

Wraps Python virtual environment management commands: reduces the network and permission problems agents hit when managing environments through terminal commands, works across operating systems, and routes installs automatically through mirrors and local proxies. The tools are strictly confined by the granted read/write permissions.

412 days agoDev & Plugin ToolsMIT
2

feishu-dsh-plugin

2286893544/feishu-dsh-plugin

Feishu (Lark) integration for DeepSeek Harness: 25 tools for chat messages and history, cloud documents (including knowledge-base pages, generated charts and images), bitable records, spreadsheet ranges and drive permissions, using your own enterprise self-built Feishu app.

221 days agoTools & CapabilitiesMIT
9

dsh-permissions

940842546/dsh-permissions

Claude Code-style permission rules engine: hard/deny/ask/allow tiers with a hard tier above full access, workspace-scoped rules, wildcard path protection, and a visual staged editor; rules persist in settings.yaml.

211 days agoSecurity & PermissionsMIT
D

dsh-allow

dwjz/dsh-allow

Filesystem permissions for shell calls, granted per path and capability rather than per command name. The command line is parsed for the read, write, create, delete and execute effects it needs, a capability it lacks raises the approval card instead of a flat refusal, and the same rules are compiled into the macOS Seatbelt profile the process, its children and the code its arguments never showed all run under. An Approvals tab in the conversation reads the audit log back and shows which rule, automatic reviewer or person answered each call.

17 days agoSecurity & PermissionsMIT
S

dsh-guild

seolhw/dsh-guild

Discord-like communities in DSH with channels, roles and permissions, message search, and sharing or cloning of DSH sessions.

110 days agoIntegrations & RemoteMIT
P

dsh-pocket-console

picsky/dsh-pocket-console

Forwards an unattended DeepSeek Harness run's tool-call approvals and ask_user_question prompts to Feishu cards on your phone. The desktop GUI answers first — a card is only sent after `delaySeconds` (120 by default) with no answer there — and a phone approval grants `allowed-once`, so no authority accumulates on the phone. One outbound WebSocket long connection to Feishu: no public IP, domain, tunnel or relay.

118 hours agoIntegrations & RemoteMIT
N

dsh-tui

nexlineai/dsh-tui

A full-screen interactive terminal UI for the DeepSeek Harness agent runtime — live streaming, reasoning blocks, tool cards, sessions, permissions, plan mode, and a full slash-command suite. The web UI, reimagined for the terminal.

1last monthUI EnhancementsMIT
N

nexusclaw-agent-governance

nexusclawhq/nexusclaw-agent-governance

DeepSeek Harness (dsh) approval answerer backed by the agent-governance sidecar — every approval/request is decided by the deny-by-default gate, L0–L4 rules and the organizational audit chain.

1last monthSecurity & PermissionsApache-2.0
Q

super-wechat-bridge

qshuai0213/super-wechat-bridge

WeChat iLink ClawBot bridge: official Tencent iLink protocol, Web UI settings (QR login / model / preset / permissions / session management with delete), 24h auto-renewal pushes a fresh QR before expiry, zero downtime.

12 months agoIntegrations & RemoteMIT
L

dsh-fleet-audit

lesliewylie/dsh-fleet-audit

Read-only agent-fleet credential hygiene audit: credential-file permissions, embedded credentials in git remotes (masked in output), and provider token literal counts; zero-dependency and deterministic.

12 months agoSecurity & PermissionsMIT
W

dsh-jumpserver

we39/dsh-jumpserver

Query and manage JumpServer through conversation: assets, users, accounts, permissions, sessions, command audit logs, command filters, and RBAC roles, authenticated with an AccessKeyID/AccessKeySecret pair (HTTP Signature).

019 days agoSecurity & Permissions
A

dsh-sandbox-arg-guard

apex-mochen/dsh-sandbox-arg-guard

Keeps a redundant sandbox-escalation argument from failing a tool call. Escalating tools (pwsh, bash, write, edit) advertise the full sandbox_permissions enum, but DSH only accepts a level strictly wider than the one already in effect — a check its own source calls 'deliberately not a schema constraint'. A model that reflexively passes the argument therefore picks the level it is already at and the call dies before running with 'sandbox escalation to "workspace-write" is not strictly wider than this call's current "workspace-write" mode', costing some models a whole turn of retries. This plugin registers one tools/execute waterfall listener and, only on that documented rejection and only when the arguments really carried an escalation field, re-issues the identical call once without it. Safe by DSH's own documentation: the rejection precedes any execution ('nothing has run'), and the corrected call cannot match again, so the retry is loop-free. Reproduced and verified end to end — before: isError true, the command never ran; after: the command's real output, isError false, one tool/call and one tool/result. Zero dependencies.

013 days agoSecurity & PermissionsMIT
G

dsh-plugin-sage-subagent

gezi-wen/dsh-plugin-sage-subagent

Named, file-defined subagent roles for DeepSeek Harness: persona, subagent-only skills, tool permissions, an ordered model chain with failover, and derived groups.

017 days agoSecurity & PermissionsApache-2.0
R

dsh-bash-escalation-gate

ruby1304/dsh-bash-escalation-gate

Require a real, immediately preceding sandbox denial before DSH Bash can request wider permissions.

022 days agoSecurity & PermissionsMIT