DeepSeek Harness Plugin

Jueze-2019/dsh-redteam-mode#packages/redteam-bundle

Category Security & Permissions Added 2026-09-18

Red-team engagement mode: send one target organization name and a planner session runs a five-role agent team (recon, asset triage, vulnerability discovery, exploitation, internal pivot) at up to three concurrent agents, preflight-checking skills and resources and asking for any missing key or VPS first; findings land in a local SQLite fact base with discovery timestamps, shown in a persistent right-side console (asset mapping with a discovery timeline, agent roster, session/tunnel state, five-stage attack chain, scoring targets, a report that spells out how each score was obtained — actions, exact commands, credential provenance, tunnel build commands — and a category-organised POC/EXP knowledge base); ships 13 native skills, 53 redteam_* tools and one-command self-update.

Install

# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)

dsh plugin --profile web add github:Jueze-2019/dsh-redteam-mode#path:/packages/redteam-bundle

Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).

Links

More in this category

View the whole category →

Community comments

Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.