跳过主要内容

安全与权限

安全与权限类插件为 DeepSeek-Harness(dsh)挡住危险的工具调用和恶意插件。涵盖 allow/deny/ask 分级的策略化工具门禁、面向插件包与 npm tarball 的安装前扫描、提示注入与密钥外泄防护、遥测脱敏,以及哈希链式的审计日志。

共 269 个插件

G

dsh-agent-loop-guard

goodandready/dsh-agent-loop-guard

为 DeepSeek Harness 提供故障关闭式运行时工具调用循环防护。

03天前安全与权限MIT
Z

dsh-permission-matrix

zhang8019/dsh-permission-matrix

把 DSH 权限拆成 9 个可选预设(3 种沙箱 × 4 种审批),规则 + LLM 双通道四档风险分级,高风险操作需输入批准密码才放行,附 JSONL 审计日志。

022天前安全与权限MIT
L

dsh-risk-gate

leetom314/dsh-risk-gate

语义风险分级与渐进授权:把工具调用分为安全/有风险/红线三档,不可逆操作前先询问,只对「已批准且曾成功」的签名自动放行。

025天前安全与权限MIT
A

dsh-workspace-tools

ahiosuz/dsh-workspace-tools

按工作区规则为新建根会话自动应用 Agent 预设与权限预设(设置 - 工作区默认设置),仅使用官方扩展点。

023天前安全与权限MIT
B

dsh-semgrep-sast

baiiduu/dsh-semgrep-sast

Semgrep SAST bundle and model-facing scan tool for DeepSeek Harness.

022天前安全与权限MIT
S

dsh-totp

sodazheng/dsh-totp

面向个人 DeepSeek Harness Web 实例的纯 TOTP 访问验证,支持设置内扫码绑定、一次性恢复码、动态启停保护和撤销所有页面授权。

010天前安全与权限MIT
C

dsh-dolphin-security

ccr-wer/dsh-dolphin-security

此为 DSH 生态插件。Dolphin - 主动巡检型安全防御插件,支持本地扫描与远程 SSH 巡逻。将渗透测试方法论(信息收集→漏洞探测→利用验证→报告)转化为主动防御巡检流程:基于 Semgrep 的扫描层与基于 SSH 的执行层相融合,可对本地目录做静态扫描,也可将扫描命令经 SSH 下发至远程主机执行并回收结构化结果。

024天前安全与权限
W

dsh-security-guard

weisofns/dsh-security-guard

DSH 插件安全卫士:28 条规则静态扫描、风险评分、白名单/黑名单、本地 Web 仪表盘与 DSH 内风险弹窗。

023天前安全与权限MIT
D

dsh-turn-doctor

d3vmeh/dsh-turn-doctor

Explains which layer killed a failed turn: times every model request (first byte, longest silence, total) and combines that with the error to name the culprit (dsh idle watchdog vs Node undici timers vs SDK timer vs server crash, context overflow, gate queue, tool timeouts, failed compactions) and the exact setting to change; verdicts in the DSH terminal plus a /why command, subagents included.

029天前安全与权限MIT
U

dsh-plugin-cyrene

under-the-ocean/dsh-plugin-cyrene

昔涟 (Cyrene) 主题 + 桌宠 for the dsh web GUI — pearl-white pink theme, Live2D desktop pet, particle background, gradient, and a collapsible config card. Ported from Cyrene-Agent (MIT) with the Live2D model creator's permission.

028天前安全与权限MIT
V

dsh-route-fence-linter

vladimir-kryshchenko/dsh-route-fence-linter

审计 profile 内所有插件 HTTP 路由的浏览器信任围栏:插件路由在 Web 服务器的最长前缀匹配中优先,因此缺少围栏的路由会被静默暴露;逐条给出文件与行号级别的证据。

0上个月安全与权限MIT
R

dsh-security-guard

ruanhaodong-tt/dsh-security-guard

DSH 运行时安全守卫:配置加载导入约束、HTTP Host 头校验、附带 VM 沙箱逃逸源码补丁(4 个 CVE)。AI 辅助制作。

028天前安全与权限MIT
N

dsh-safe-delete

nattocb/dsh-safe-delete

工具守卫将 agent 执行的 rm 目标移入 macOS 废纸篓而非直接删除,shell 感知词法器覆盖复合与伪装命令;设置页通用设置中可随时关闭。

0上个月安全与权限MIT
G

dsh-shadow-auditor

goodandready/dsh-shadow-auditor

DeepSeek Harness 的后台安全审计器:扫描 Agent 输出中的秘密泄漏,在执行前检查命令安全性,并将发现记录到持久化审计日志中。

06天前安全与权限MIT
D

dsh-plugin-guard

dingzhiqi5596/dsh-plugin-guard

DSH Desktop 插件安全防护:崩溃后自我修复 + 8 项核心安全检查(另有 2 项可选:深度组合校验、业务冒烟),写完插件自动提示。非商业源可用。

0上个月安全与权限
L

dsh-edit-guardian

lwlaymh/dsh-edit-guardian

文件修改 diff 栏与保留/撤销汇总,以及对 bash/pwsh 危险命令的审批与标红。

0上个月安全与权限MIT
G

dsh-completion-guard

greenlv/dsh-completion-guard

避免 DSH Agent 在长任务中忘记你的要求:它会把重要条件和完成依据保存在本机,在上下文压缩或恢复会话后重新带回,防止漏掉关键限制,或只做完一部分就说整个任务已经完成。

015小时前安全与权限Apache-2.0
P

dsh-plugin-windows-guard

pasumao/dsh-plugin-windows-guard

DeepSeek Harness (dsh) Windows 环境防坑守则 skill 插件(纯数据):GBK/BOM/UTF-16 编码坑、PowerShell 引号转义、长路径/文件占用/EACCES、进程与端口、CRLF、stderr 误判、乱码识别——预防性规则,无修复工具。纯技能载体,零运行时依赖,零构建。

0上个月安全与权限MIT
G

dsh-checkpoint-memory

gege9527/dsh-checkpoint-memory

Curated file-based long-term memory for DeepSeek Harness — human-readable markdown notes, one plain-file store shared across hosts (git-ignored when it lives inside a project repo), and a deterministic index cap enforced by ctx.tools.guard()

0上个月安全与权限MIT
V

dsh-fs-deny-policy

vladlearns/dsh-fs-deny-policy

为 DSH 提供文件系统根目录拒绝名单:在 tools/pre-execute 拦截落在名单内的读取、写入、搜索与 shell 工具调用,并预先告知模型。

0上个月安全与权限MIT
Y

dsh-webgate

yyyq0325-ai/dsh-webgate

DeepSeek Harness Web GUI 的登录门禁:DeepSeek 风格登录页、12 小时会话令牌与用户管理命令,登出时后台任务照常运行。

0上个月安全与权限MIT
Y

dsh-token-vault

yyfather/dsh-token-vault

DeepSeek Harness 的安全凭证库:保存 GitHub/npm/API token(密钥不出主机),以注入环境变量的方式运行 gh/npm/git。

0上个月安全与权限MIT
D

correctover

dshcorrectover/correctover

AI 智能体运行时授权与证据校验:工具调用护栏、CCS 七维验证标准与 MCP/DSH 安全扫描,拦截 SSRF/命令注入等风险并出具签名回执。

0上个月安全与权限
W

dsh-permission-workspace-write-plus

wonjader/dsh-permission-workspace-write-plus

deepseek harness 中 workspace write 权限的增强插件(工作区外配置写入 + 睡眠守护)。使用前请自行评估风险。

0上个月安全与权限