Plugins
Browse, filter, and install DeepSeek-Harness plugins.
11 plugins found
dsh-auto-mode
nanmicoder/dsh-auto-mode
Adds an Auto permission preset between Workspace Write and Full access: routine work stays in the official workspace-write sandbox while the current session model reviews escalation and destructive calls, granting one exact wider access once, asking when the intent is ambiguous, and denying critical paths.
dsh-win32
sjh9714/dsh-win32
Diagnoses and repairs DeepSeek Harness on native Windows around the official persistent PowerShell and Workspace Write stack, creates the desktop shortcut, and keeps earlier Git Bash and BusyBox presets behind an explicit legacy setup. No WSL.
dsh-auto-approve
jiao-xxx/dsh-auto-approve
Adds an `auto` permission preset between workspace-write and danger-full-access: a classifier grants routine sandbox escalations once, while dangerous or uncertain requests still go to a human.
dsh-workspace-write-plus
yzxxy010/dsh-workspace-write-plus
Adds a workspace-write++ permission that keeps file tools inside the workspace while skipping the Windows process sandbox for wildcard-allowlisted executables such as Git Bash.
dsh-write-protect
azazo1/dsh-write-protect
Keep declared workspace subpaths (e.g. .git) read-only, honor a read-only rules file at the workspace root, grant extra writable roots under workspace-write, and let the model request session-scoped write access; enforced for sandboxed CLI commands and the write/edit tools.
dsh-auto-review
accpowered/dsh-auto-review
LLM approval answerer for sandbox escalations beyond workspace-write: a deterministic regex filter first, then a clean-context reviewer model; humans are asked only when it is unsure. Requires the bundled core patches.
dsh-Almost_Full_Access
alnita-m/dsh-almost_full_access
Permission mode between workspace-write and full access: shell commands are checked by deterministic rules and a subagent review; irreversible or system-level actions require explicit approval.
dsh-perm-guard
a903067276-rgb/dsh-perm-guard
Auto-approval permission guard: a middle tier between workspace-write and danger-full-access — auto-allows safe operations inside trust directories, always asks a human for destructive ones, with 11 per-category switches and an audit trail.
dsh-auto-approval-plugin
styxnether/dsh-auto-approval-plugin
A middle permission tier for DeepSeek Harness between workspace-write and danger-full-access: auto-approves harmless commands and operations targeting configured trusted areas, beyond the current workspace.
dsh-sandbox-arg-guard
apex-mochen/dsh-sandbox-arg-guard
Keeps a redundant sandbox-escalation argument from failing a tool call. Escalating tools (pwsh, bash, write, edit) advertise the full sandbox_permissions enum, but DSH only accepts a level strictly wider than the one already in effect — a check its own source calls 'deliberately not a schema constraint'. A model that reflexively passes the argument therefore picks the level it is already at and the call dies before running with 'sandbox escalation to "workspace-write" is not strictly wider than this call's current "workspace-write" mode', costing some models a whole turn of retries. This plugin registers one tools/execute waterfall listener and, only on that documented rejection and only when the arguments really carried an escalation field, re-issues the identical call once without it. Safe by DSH's own documentation: the rejection precedes any execution ('nothing has run'), and the corrected call cannot match again, so the retry is loop-free. Reproduced and verified end to end — before: isError true, the command never ran; after: the command's real output, isError false, one tool/call and one tool/result. Zero dependencies.
dsh-permission-workspace-write-plus
wonjader/dsh-permission-workspace-write-plus
deepseek harness中workspace write权限的增强插件。使用前请自行评估风险。