Plugins
Browse, filter, and install DeepSeek-Harness plugins.
19 plugins found
api-relay-audit
toby-bridges/api-relay-audit
Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.
dsh-plugin-gating-hub
noob-stupid/dsh-plugin-gating-hub
Framework-upgrade safety and plugin gating for DSH: a pre-upgrade session-format contract preflight that adapts incompatible plugins and agent presets before you upgrade, automatic rollback on failure, auto-quarantine of plugins that broke a boot, plus environment fingerprinting and a public contract-rule pack. The built-in multi-source marketplace is a discovery layer only.
dsh-harbor
zseven-w/dsh-harbor
A read-only mirror for installed DeepSeek Harness plugins: capability inventory with evidence, cross-plugin conflicts, and a diff of what changed since the last scan
dsh-skill-pack-security
perrylink/dsh-skill-pack-security
Security-audit methodology skill pack plus the plugin_vet supply-chain gate: eight agent skills (secret scan, dependency audit, supply-chain review, prompt-injection review, audit orchestration, threat modeling, vuln intel, incident response) in Chinese and English editions, with an npm provider bundle that mounts the skills and registers the automated plugin_vet pre-install scanner.
upstream-radar
micromilo/upstream-radar
Watches DSH and plugin releases, retests exact published artifacts in disposable runners, publishes machine-readable compatibility evidence, and reconciles managed issues after fixes.
dsh-score
perrylink/dsh-score
Multi-dimensional quality scoring for DeepSeek Harness plugins that scores a repo or npm package across install success, maintenance activity, documentation completeness, security scan, and protocol compliance using real CLI evidence, and produces a JSON or Markdown leaderboard report.
dshscan
shaoshi20/dshscan
Security scanner for DSH plugins: static and semantic passes over plugin source, DSH-specific attack-surface rules, npm audit, batch scanning, and an HTML report with per-finding severity and evidence.
npm-safe-fordsh
nisconder/npm-safe-fordsh
DeepSeek Harness plugin that blocks risky npm installs with metadata and deep supply-chain scans
dsh-sentinel-scanner
eligahyu/dsh-sentinel-scanner
Static security scanner for DSH plugins: read-only audit (exec, credentials, exfiltration, obfuscation, install scripts, bundle manifest) with a 0-100 risk score.
dsh-plugin-security-review
ateen18/dsh-plugin-security-review
Pre-install static security review and runtime guard for dsh plugins: deobfuscation decoding, supply-chain checks, web one-click review/install/uninstall, and optional runtime tool-call guard.
dsh-plugin-vetting
truelove-dreamer/dsh-plugin-vetting
Vets third-party plugins before you trust them: static scan for malicious patterns (exfiltration, credential access, obfuscation, persistence) and over-privileged path use, transitive-dependency coverage, official-package hash baseline for supply-chain tamper detection, and an optional plugin-tool call gate.
dsh-cve-audit
sarthak2511/dsh-cve-audit
Live CVE/supply-chain audit for your workspace's own project dependencies (npm/pip/go), backed by OSV.dev, with a `cve_audit` tool plus optional automatic re-scan on lockfile changes.
dsh-vet
rogerdigital/dsh-vet
Pre-install static audits for npm-installable DSH plugins; emits and validates the open `dsh-vet/v1` report with severity, confidence, evidence, derived grades, a CI Action, and auditable badges.
cn-intel-mcp-dsh
lory69060/cn-intel-mcp-dsh
China hard-tech supply chain intelligence: 33-signal board, H1 earnings tracker, hit-rate track record and Q&A, via a remote MCP (mcp__cn_intel__*).
dsh-plugin-guard
taxueseek/dsh-plugin-guard
Static-only plugin gate and clinic for DSH: audit before install, hash-and-capability lock after install, local fingerprint peer search over GitHub topic:dsh-plugin, and mechanical detox. Never executes the target plugin.
dsh-dep-audit
zoahdev/dsh-dep-audit
Dependency supply-chain hygiene audit for dsh projects and profiles: peer-range resolvability, broken dist-tag detection (#2763 class), stale / missing-license / non-registry dependencies, and installed-vs-declared drift — CLI plus an agent-callable dep_audit tool.
dsh-provenance
darren-tang/dsh-provenance
Pre-install supply-chain checks for DeepSeek Harness plugins: verify the tarball you are about to install matches the source you read, before any code runs.
dsh-poison-guard
zoahdev/dsh-poison-guard
Pre-install supply-chain poison scanner for DSH plugins: AST (JS-X-Ray) + deobfuscation + regex heuristics, exits non-zero on findings for CI gating.
dsh-cert-mcp
perrylink/dsh-cert-mcp
Read-only MCP server over the DSH plugin-certification registry, exposing a plugin certification grade, its snapshot and the five-dimension evidence behind it.