Plugins
Browse, filter, and install DeepSeek-Harness plugins.
129 plugins found
api-relay-audit
toby-bridges/api-relay-audit
Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.
dsh-redteam-model
seaof0/dsh-redteam-model
Authorized-security DSH collection: nine work modes (redteam coordinator, pentest, code audit, binary analysis, attack-defense, AV evasion, incident response, cloud security, CTF solving) and fifteen runtime plugins, managed from a settings page with one-click deploy, install, update and uninstall.
dsh-bridge
wenbin-wb/dsh-bridge
Remote and mobile access for DeepSeek Harness: provides LAN QR code connection, Cloudflare/custom tunnels, WeChat, QQ, Feishu, Telegram bot integration, and security authentication.
dsh-reverse-skill
dhicoc/dsh-reverse-skill
Complete reverse-skill pack (85 SKILL.md) as a DeepSeek Harness Cordis plugin: reverse engineering, authorized pentesting and security-research skill router.
helm-d (helmd)
adwmc/helm-d
Single-bundle reverse-engineering and pentest security plugin: first-turn tool narrowing, domain routing, and 33 tools covering APK, web, native binary, protocol, malware and LLM samples — with unpacking, license-bypass and anti-analysis case playbooks, an H-CoT evaluation engine (semantic routing, /hcot command), a web workbench with a ledger-driven tool shelf, an on-disk case workflow (auto-persisted evidence chain, E-numbered validated findings, post-compaction resume), GitHub-based external tool discovery, and 361 on-demand reference docs.
dsh-secure-audit
pensivefei/dsh-secure-audit
Read-only security and compliance plugin for DeepSeek Harness: prompt-injection detection, Chinese-PII redaction, and a local configuration audit with redacted, reproducible reports.
dsh-remote
xgone/dsh-remote
Secure remote access for the DeepSeek Harness Web UI: a login gate, MFA/TOTP, signed session cookies, optional admin/user/guest roles, in-browser workspace selection, and allowlisted remote file previews.
dsh-passwords
slywalker2006/dsh-passwords
Turns DeepSeek Harness into a server-grade multi-tenant platform: remote access + auto HTTPS, subuser permissions & token/daily quotas, sandbox enforcement, encrypted auth & audit log.
dsh-redteam-mode (redteam-bundle)
jueze-2019/dsh-redteam-mode
Red-team engagement mode: send one target organization name and a planner session runs a five-role execution team (recon, asset triage, vulnerability discovery, exploitation, internal pivot) at up to three concurrent agents, preflight-checking skills and resources and asking once for any missing key or VPS first, guided by a built-in first-run onboarding skill; scoring follows the merged intrusion scoring rules (8 categories / 25 points) with server-side caps, highest-privilege-wins and per-service dedup, and self-registered accounts never score; findings land in a local SQLite fact base with discovery timestamps, shown in a persistent right-side console of 12 tabs (asset mapping with a discovery timeline, agent roster, session/tunnel state, five-stage attack chain, scoring targets, a report that spells out how each score was obtained — actions, exact commands, credential provenance, tunnel build commands — a category-organised POC/EXP knowledge base and a skill library with per-skill usability verdicts); ships 23 native skills, 53 redteam_* tools and one-command self-update.
dsh-full-remote
juanwang-buaa/dsh-full-remote
Remote DeepSeek Harness with full server-side API access (`settings.*` / `credentials.*` / `host.listDirectory`). Token-gated reverse proxy, per-device sessions, phone invite QR, fence self-check, optional approval / CIDR / idle timeout / local TLS, WebSocket/SSE.
openguardrails
openguardrails/openguardrails
Auto mode for DeepSeek Harness (dsh): an Auto entry in the Permissions selector whose approval prompts are answered by OpenGuardrails policy instead of a human — plus the full OGR guard engine underneath. No core changes.
dsh-remote-mobile
iceapriler/dsh-remote-mobile
Remote & mobile security gateway: zero-modification Tailscale/LAN access with QR pairing, RSA encryption, brute-force defense and mobile style snippets; auto-yields the shared pairing service to other remote plugins so coexistence never crashes startup.
dsh-defend
perrylink/dsh-defend
Detects prompt-injection, jailbreak, and secret-leak patterns on the agent/pre-step, tools/pre-execute, and tools/post-execute seams with allow/ask/block tiers, sanitized defend/detection audit events, a defend_report tool, and a destructive-delete command guard.
dsh-skill-pack-security
perrylink/dsh-skill-pack-security
Security-audit methodology skill pack plus the plugin_vet supply-chain gate: eight agent skills (secret scan, dependency audit, supply-chain review, prompt-injection review, audit orchestration, threat modeling, vuln intel, incident response) in Chinese and English editions, with an npm provider bundle that mounts the skills and registers the automated plugin_vet pre-install scanner.
dsh-chatgpt-bridge
jiezeng2004-design/dsh-chatgpt-bridge
MCP bridge that lets ChatGPT Web create, view, continue, and supervise DeepSeek Harness agent sessions and goals while preserving DSH's native approval, sandbox, and workspace security model.
dsh-auth-gate
tecfancy/dsh-auth-gate
Login gate for the dsh web surface: password or shared-token authentication, session cookies, rate limiting, and a user-management CLI (dsh.bundle manifest since 0.4.1, one-command `dsh plugin add` mounting).
dsh-security-audit
omdsh-dev/dsh-security-audit
Local security audit: config, plugin origins, sessions, network exposure — read-only redacted risk report.
dsh-one-gateway
tiantianflow/dsh-one-gateway
Private loopback DSH Web gateway for Tailscale Serve, Cloudflare Access, and Headscale TCP Serve, with exact principal allowlists and guided fail-closed setup.
dsh-auth-gateway
xbzbing/dsh-auth-gateway
Password + TOTP two-factor authentication gateway for the dsh web UI: every HTTP request and WebSocket upgrade is refused until login, with per-source lockout, global rate limits and one-time backup codes.
dsh-tailscale-gateway
tiantianflow/dsh-tailscale-gateway
Private Tailscale access for DeepSeek Harness Web that allowlists users from the trusted Tailscale-User-Login header that Serve injects, with a loopback-only gateway and guarded Serve setup.
upstream-radar
micromilo/upstream-radar
Watches DSH and plugin releases, retests exact published artifacts in disposable runners, publishes machine-readable compatibility evidence, and reconciles managed issues after fixes.
project-koma
swnotmetal/project-koma
DeepSeek Harness adapter for Koma Miko Agent Specs.
dsh-mask
perrylink/dsh-mask
PII masking for DeepSeek Harness — anonymizes names, phones, emails, ids, and keys before requests and restores them at the display layer, keeping plaintext out of session logs.
dsh-skill-7d-code-reviewer
7dgroup-ai/dsh-skill-7d-code-reviewer
Template-driven code review skill: five-step review flow, critical/medium/minor severity grading, four-dimension scoring (quality, security, performance, maintainability), dual text and HTML report output, and an on-demand reference knowledge base.