插件
浏览、筛选并安装 DeepSeek-Harness 插件。
共 129 个插件
dsh-hawkeye-scan (npm)
liuqingman/dsh-hawkeye-scan
AI 驱动的源代码安全扫描工作台:5 个模型工具(start/finding/status/report/list)、/hawkeye Web UI 和 JSON/Markdown/HTML 漏洞报告;零依赖 Cordis 插件,可作 agent preset 或 npm 包安装。
dsh-plugin-guard
taxueseek/dsh-plugin-guard
DSH 插件的静态安全闸门与诊所:安装前静态审计、安装后哈希与能力锁定、本机指纹库与 GitHub dsh-plugin 主题的同类搜索、机械式剥离清理;永不执行目标插件。
dsh-skill-security-inspector
kakapengta/dsh-skill-security-inspector
可连接 DSH Web profile 的独立安全检查插件:安装/使用不受信任的 Skill 前先本地粗检,再由用户决定是否模型复核。
dsh-dep-audit
zoahdev/dsh-dep-audit
dsh 项目与 profile 的依赖供应链卫生审计:peer 范围可解析性、坏 dist-tag 检测(#2763 类)、过期/缺许可证/非注册表来源依赖与安装版本漂移——CLI + agent 可调用 dep_audit 工具。
skill-security-guard
rrrrrredy/skill-security-guard
skill-security-guard 静态扫描器的 DSH 社区 Bundle:对技能包做 7 维确定性扫描、A-F 风险评级并给出修复建议。
riskproof
onlyqzq/riskproof
来源感知的执行安全插件:追踪敏感数据在工具调用间的流转,在副作用发生前阻止高风险执行。
find-dsh-plugins
jazzulu/find-dsh-plugins
对话式查找 DSH 插件的增强版 skill:四源聚合统一索引,BM25 粗筛 + LLM 语义精排,候选表带证据分级与本地静态安全审计,安装走安全确认流程并自动验证。
dsh-plugin-audit
863683348/dsh-plugin-audit
插件生态体检:将 dsh-plugin 话题同步为本地评分目录(维护/文档/npm+周下载/生态四维,0-100 分 A-D 级),静态安全扫描高危一票否决,支持 star 历史快照、Web 榜单与 Agent 工具。
dsh-insight
863683348/dsh-insight
插件评测中心:一个答案回答"哪些值得装"——plugin_guide 按需求推荐插件、recipe 安装整套环境、plugin_rank 健康评分(0-100)、plugin_audit 静态安全扫描本地目录、plugin_verdict 给出 install / caution / research / avoid 结论。
dsh-poison-guard
zoahdev/dsh-poison-guard
DSH 插件安装前投毒扫描:AST(JS-X-Ray)+ 去混淆解码 + 正则启发式,发现即非零退出,可作 CI 门禁。
dsh-egress-guard
tancheng33/dsh-egress-guard
工具管线上的运行时安全网关:拦截出站白名单之外的主机调用,在 canonical value(而非仅渲染内容)层面脱敏结果中的凭据,每个决策写入 JSONL 审计日志;默认仅监控不拦截。
dsh-code-security
stardustlc666/dsh-code-security
确定性代码安全审查:40+ 规则、密钥熵检测、staged diff 审查、SARIF 导出、基线接受、SBOM-lite 依赖清单与健康自检。
dsh-plugin-sentinel
botonj/dsh-plugin-sentinel
插件安装前静态安全审计:生命周期脚本、动态执行、凭据外传组合特征与 patch 层风险;零依赖,tar 包全程内存解析不落盘。
dsh-security-guard
bigclawd/dsh-security-guard
dsh 安全守卫插件:基于规则的静态扫描覆盖恶意代码、提示词注入与令牌浪费,运行时拦截危险工具调用,提供 /scan 命令、plugin_scan 工具、Web 面板与白名单。
skill-bartender
akqwpeter-prog/skill-bartender
任务到技能配对元技能:懒人阶梯最小化加载、可编辑路由表、隔离-SkillSpector 扫描-人工确认的安装流程。
dsh-plugin-code-review
yytbit/dsh-plugin-code-review
DeepSeek Harness 结构化代码评审技能:覆盖 bug、安全、性能与代码风格
dsh-guardian
lonelymoon87/dsh-guardian
增加危险操作策略检查、输出脱敏和安全审查工作流。
dsh-mcpguard
chenlaoshiyf/dsh-mcpguard
扫描 skill 与 MCP 配置中的提示注入、同形字、Unicode 隐形字符、危险 shell 与凭据泄露。
dsh-fleet-audit
lesliewylie/dsh-fleet-audit
只读的 agent 机群凭据卫生审计:检查凭据文件权限、git remote 内嵌凭据(输出脱敏)与 provider token 字面量计数;零依赖、确定性。
deskpet-guard
cny1230/deskpet-guard
Agent 行为守护桌宠:跨 agent 监控可疑外传(加密打包直传对象存储 / DNS 外泄线索 / 敏感密钥被读),发现即告警,明确确认后按「一次一个」终止目标 agent;事件写入只追加 guard-events.jsonl,并通过 DSH host 工具 + MCP(stdio) 供其它 agent 查询
dsh-privacy-guard
amwangfan/dsh-privacy-guard
DeepSeek Harness 本地凭据脱敏网关的控制面板:网关与小模型健康状态、审计指标、泄密探测沙箱、豁免白名单、加密密钥管理、凭据保护模型入口与部署控制。
dsh-approval-review
lawli3tcoding/dsh-approval-review
新增「替我审批」访问模式:审批请求由独立的复核模型裁决而非人工,复核者可只读工作区,复核跑不起来时把请求交回人工,每次裁决的理由记录在「审批」页签中。
dsh-hidden-paths
gabrip780/dsh-hidden-paths
Deny an AI agent access to .env files, credential stores, keys and any path you hide — across file tools, shell commands, search selectors and run_code. A DeepSeek Harness (dsh) plugin.
dsh-eslint-security-sast
baiiduu/dsh-eslint-security-sast
ESLint Security SAST bundle and model-facing scan tool for DeepSeek Harness.