安全与权限
安全与权限类插件为 DeepSeek-Harness(dsh)挡住危险的工具调用和恶意插件。涵盖 allow/deny/ask 分级的策略化工具门禁、面向插件包与 npm tarball 的安装前扫描、提示注入与密钥外泄防护、遥测脱敏,以及哈希链式的审计日志。
共 269 个插件
noatmark-dsh-plugin
ylwl1997/noatmark-dsh-plugin
文本卫生 dsh 插件:净化不可信文本、扫描隐形字符、清洗 LLM 格式、转义 CSV 公式注入。
dsh-escalation-review
trentswd/dsh-escalation-review
Escalation-only LLM reviewer: reviews sandbox escapes only, keeps the sandbox, fails closed.
crwu-ai
mmungdong/crwu-ai
中瑞世联工作台 / CRWU audit workbench for DeepSeek Harness: pick a pending audit report, dispatch one AI audit subagent, watch and stop/restart it, auto-upload deliverables to Aliyun OSS.
dsh-approval-policy
fan56/dsh-approval-policy
dsh plugin: unattended approval gate — subagent/scheduled/cron approval requests get a bounded answer window, then settle with a fail-closed default instead of hanging forever (per origin or per session)
chinese-script-policy
ksf1216/chinese-script-policy
Harness-neutral Traditional Chinese enforcer + offline converter (skill, DSH bundle, CLI). One script axis either way + Cantonese/Japanese-only filters. Converts both ways; optional wording preference. Also: an LLM output guard, cp950/GBK console scan.
dsh-decision-layer
xbzbing/dsh-decision-layer
A structured decision layer for the DeepSeek Harness agent loop: a danger-call gate, output self-check, tool narrowing, and loop guard backed by a pluggable adjudication model.
dsh-opencode-free-tier
docutee/dsh-opencode-free-tier
Make DSH llm-pi-ai opencode routes pass Zen free-tier gate: opencode User-Agent + canonical ses_ session + bash/read tools. Scoped to opencode.ai only.
dsh-approval-gate
goodandready/dsh-approval-gate
Host-only command safety gate for DeepSeek Harness: blocks recognized dangerous operations and requests DSH approval when a command cannot be inspected.
dsh-skill-audit
caesarloo/dsh-skill-audit
Audit DSH skills automatically: a host-layer tools/post-execute plugin that ships both the skill body and the audit engine, runs the engine after skill files change (write/edit/shell) or after a bulk restore/backup (any tool invoked with mode: restore|bac
dsh-keychain-credentials
nengong-ai/dsh-keychain-credentials
纯 JavaScript 实现的 macOS Keychain 凭据提供器,替换 DeepSeek Harness 的明文 .credentials.yaml 存储,完整支持 refs 和 records,无需原生构建、代码签名或 Xcode。
data-asset-inspector
liuhange789/data-asset-inspector
Shared infrastructure for data assetization plugins: business rules loader, file format adapter, report generator, path validator, audit logger Also known as @deepseek-ai/dsh-data-asset-shared.
dsh-fs-allowlist
wzn16/dsh-fs-allowlist
白名单目录写入免审批——write/edit 文件工具直通白名单栅栏,命中白名单的 bash 沙箱升权自动放行,设置页可视化管理目录与开关。
dsh-contract-check
imtokenxinluo/dsh-contract-check
Contract check for DeepSeek Harness plugins: statically verifies that registered tools' output.render() returns ContentBlock[], and warns when a session event type falls outside the kernel vocabulary. Warn-only. 契约体检插件(不检测恶意)。
dsh-cache-guard
loonylabs-dev/dsh-cache-guard
Host- and agent-layer DeepSeek Harness plugin that prices every automatic context rewrite before it lands, asks the human by default, and reports what the provider had to re-read cold.
dsh-approval-gate
iamnewhands/dsh-approval-gate
dsh-approval-gate 的维护中 fork。判定器不可用时,确认次数已达阈值的中立操作直接自动放行,不再重复弹人工审批;审批说明由真实的沙箱模式、命令与路径生成中文。另含凭据外泄与系统路径销毁的确定性硬拒、判定输入脱敏、判定模型候选链、带操作指纹的放行规则,以及可查看 unified diff 与一键撤销的审批视图。
dsh-jev-guard
7starsseeker/dsh-jev-guard
DSH 执行前安全阀门,用 TypeSafe Jev 模型做判定:挂载 tools/pre-execute,对每条 bash/pwsh 调用先过离线静态规则,再向 Jev 模型(TypeSafe 的 System One 模型,返回结构化判定而非散文)提一个是非问句——「这条命令会不可逆地删除或覆盖真实数据吗?」——把答案切成允许/修正/拦截/上报人工四态;修正给模型更安全的写法,上报提供一次性人工令牌;额度耗尽或没有可用密钥时大声降级而非静默失效,缺密钥时会直接在对话里要求录入(录入用 `guard key set`,只从标准输入读);每条判定写入共享审计日志,面向人的文案中英双语。
dsh-theme-studio
hj01857655/dsh-theme-studio
Customize the dsh UI theme: 12 accent presets, dark-mode aware accents with a contrast guard, density, font family, animation toggle, and raw design-token overrides.
dsh-tm-guard
chaojie0/dsh-tm-guard
macOS 上 DSH 智能体的零干预权限门:可经本地 git 或时间机器回滚的本地写操作自动放行,拦截网络、装包、进程控制与敏感路径读取,并记录完整审计日志。
dsh-unsandboxed-winbash
xswt442-cmd/dsh-unsandboxed-winbash
让 dsh 在 Windows 上使用用户自安装的 Git Bash,并绕过其沙箱限制 | Enable dsh to use a user-installed Git Bash on Windows by bypassing its sandbox restrictions.
dsh-almazom-approve-escalate
almazom/dsh-almazom-approve-escalate
审批卡片上的「批准并升级」一键操作:既应答当前待批请求,又把当前会话切换到指定的权限预设。
dsh-jumpserver
we39/dsh-jumpserver
通过对话查询与管理 JumpServer:资产、用户、账号、授权、会话、命令审计、命令过滤与 RBAC 角色,使用 AccessKeyID/AccessKeySecret(HTTP 签名)鉴权。
dsh-fs-allowlist
wangzhaonan16/dsh-fs-allowlist
白名单目录写入免审批——write/edit 文件工具直通白名单栅栏,命中白名单的 bash 沙箱升权自动放行,设置页可视化管理目录与开关。
dsh-auto-pass
sujingkpo/dsh-auto-pass
延续 simon300000/dsh-auto 的 DSH WebUI 自动审批权限档位:每次审批只走一次单轮模型审查、不再起审查子代理,只自动放行审查通过的动作、其余全部转回人工审批;并会把用户确认过的决定记成项目级与全局级的允许/拒绝名单,右侧栏另有审批时间线。
dsh-sandbox-arg-guard
apex-mochen/dsh-sandbox-arg-guard
让「同级或更窄的 sandbox_permissions」不再让工具调用直接失败。会升级的工具(pwsh、bash、write、edit)都广告完整的 sandbox_permissions 枚举,但 DSH 只接受严格更宽于当前生效级别的请求——其源码自称这是「deliberately not a schema constraint」。于是反射式带上该参数的模型往往填它已经在的那个级别,调用在执行前就死掉:"sandbox escalation to \"workspace-write\" is not strictly wider than this call's current \"workspace-write\" mode",某些模型还会为此烧掉一整轮重试。本插件只注册一个 tools/execute waterfall 监听器,且仅在那一条文档化拒绝上、且参数里确实带了升级字段时,把同一个调用去掉该参数重投一次。安全性由 DSH 自己的文档保证:拒绝发生在任何执行之前("nothing has run"),且改过的参数无法再次匹配,因此重投在结构上不成环。已端到端复现并验证——改造前 isError 为 true 且命令从未执行;改造后拿到命令的真实输出、isError 为 false,会话里只有一个 tool/call 与一个 tool/result。零依赖。