{"install":"Install","market":"via dsh-market · recommended","marketHint":"copy the market install command","cli":"via CLI","copy":"copy install","copyLabel":"Copy install command","dlTitle":"Downloads (30d)","items":[{"cat":"security","tag":"Security & Permissions","dl":11498,"stars":11,"added":"2026-09-03","npm":1,"name":"dsh-vault","owner":"Ox0400","short":"dsh-vault","slug":"Ox0400/dsh-vault","desc":"Encrypted local credentials vault for the Harness: a web settings page and vault_* tools to store, search and copy passwords, API keys, TOTP secrets and card data, with health audits, expiry rotation, imports/exports and read-only/ask access modes.","cmd":"dsh plugin --profile web add dsh-vault","href":"/p/Ox0400/dsh-vault/"},{"cat":"security","tag":"Security & Permissions","dl":7337,"stars":115,"added":"2026-08-15","npm":1,"name":"dsh-permission-rules","owner":"PerryLink","short":"dsh-permission-rules","slug":"PerryLink/dsh-permission-rules","desc":"Claude Code-style declarative permission rules: ordered allow/deny/ask YAML rules matching tool names, arguments, workspace paths, and agent identity on the tools/pre-execute waterfall, with full session-log audit, dry-run mode, and hot reload.","cmd":"dsh plugin --profile web add dsh-permission-rules","href":"/p/PerryLink/dsh-permission-rules/"},{"cat":"security","tag":"Security & Permissions","dl":6023,"stars":11,"added":"2026-08-28","npm":1,"name":"dsh-auto-approval-llm","owner":"cuddly-guacamole","short":"dsh-auto-approval-llm","slug":"cuddly-guacamole/dsh-auto-approval-llm","desc":"LLM-assisted auto approval with countdown fallback for the Auto permission preset: static rules, risk tiers, breaker and file audit.","cmd":"dsh plugin --profile web add @quill507/dsh-auto-approval-llm","href":"/p/cuddly-guacamole/dsh-auto-approval-llm/"},{"cat":"security","tag":"Security & Permissions","dl":5894,"stars":219,"added":"2026-08-15","npm":1,"name":"dsh-auto-review","owner":"PerryLink","short":"dsh-auto-review","slug":"PerryLink/dsh-auto-review","desc":"Second-model auto-review on the approval answerer chain: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default.","cmd":"dsh plugin --profile web add dsh-auto-review","href":"/p/PerryLink/dsh-auto-review/"},{"cat":"security","tag":"Security & Permissions","dl":5383,"stars":83,"added":"2026-08-17","npm":1,"name":"dsh-approval-gate","owner":"moon09300731","short":"dsh-approval-gate","slug":"moon09300731/dsh-approval-gate","desc":"Risk-gated approval automation for DeepSeek Harness: flash pre-classifies whether a write/command is irreversible — safe operations are auto-approved, dangerous ones are escalated to human approval (fail-safe). File-diff review with one-click revert and session-scoped snapshots (v0.5.1: precise snapshots via tool-call parameter tracing, incl. human-approval cases).","cmd":"dsh plugin --profile web add dsh-approval-gate","href":"/p/moon09300731/dsh-approval-gate/"},{"cat":"security","tag":"Security & Permissions","dl":5229,"stars":66,"added":"2026-08-14","npm":1,"name":"dsh-passwords","owner":"slywalker2006","short":"dsh-passwords","slug":"slywalker2006/dsh-passwords","desc":"Turns DeepSeek Harness into a server-grade multi-tenant platform: remote access + auto HTTPS, subuser permissions & token/daily quotas, sandbox enforcement, encrypted auth & audit log.","cmd":"dsh plugin --profile web add dsh-passwords","href":"/p/slywalker2006/dsh-passwords/"},{"cat":"security","tag":"Security & Permissions","dl":5174,"stars":1,"added":"2026-09-10","npm":1,"name":"dsh-perm-gate","owner":"drscrewdriver","short":"dsh-perm-gate","slug":"drscrewdriver/dsh-perm-gate","desc":"P0–P4 deterministic-first permission gate with permissive tier, learning sedimentation and approval-history UI; hard-deny credentials and protected paths, auto-allow internal read-only tools.","cmd":"dsh plugin --profile web add dsh-perm-gate","href":"/p/drscrewdriver/dsh-perm-gate/"},{"cat":"security","tag":"Security & Permissions","dl":4112,"stars":15,"added":"2026-08-16","npm":1,"name":"dsh-auth-gate","owner":"TecFancy","short":"dsh-auth-gate","slug":"TecFancy/dsh-auth-gate","desc":"Login gate for the dsh web surface: password or shared-token authentication, session cookies, rate limiting, and a user-management CLI (dsh.bundle manifest since 0.4.1, one-command `dsh plugin add` mounting).","cmd":"dsh plugin --profile web add dsh-auth-gate","href":"/p/TecFancy/dsh-auth-gate/"},{"cat":"security","tag":"Security & Permissions","dl":4071,"stars":1,"added":"2026-09-06","npm":1,"name":"user-management","owner":"weibaohui","short":"user-management","slug":"weibaohui/user-management","desc":"Login gate for the dsh web UI: unauthenticated visitors get a login/register page and the first registrant becomes admin; includes user and role management plus login and access audit logs.","cmd":"dsh plugin --profile web add @weibaohui/user-management","href":"/p/weibaohui/user-management/"},{"cat":"security","tag":"Security & Permissions","dl":3896,"stars":1,"added":"2026-09-13","npm":1,"name":"dsh-time-machine","owner":"GooDAnDReaDY","short":"dsh-time-machine","slug":"GooDAnDReaDY/dsh-time-machine","desc":"Smart checkpoints, workspace safety guards and instant rollback for DeepSeek Harness.","cmd":"dsh plugin --profile web add @goodandready/dsh-time-machine","href":"/p/GooDAnDReaDY/dsh-time-machine/"},{"cat":"security","tag":"Security & Permissions","dl":3727,"stars":0,"added":"2026-09-04","npm":1,"name":"dsh-shadow-auditor","owner":"GooDAnDReaDY","short":"dsh-shadow-auditor","slug":"GooDAnDReaDY/dsh-shadow-auditor","desc":"Background security auditor for DeepSeek Harness: scans agent outputs for secret leakage, checks command safety before execution, and surfaces findings in a persistent audit log.","cmd":"dsh plugin --profile web add @goodandready/dsh-shadow-auditor","href":"/p/GooDAnDReaDY/dsh-shadow-auditor/"},{"cat":"security","tag":"Security & Permissions","dl":3704,"stars":20,"added":"2026-08-23","npm":1,"name":"dsh-defend","owner":"PerryLink","short":"dsh-defend","slug":"PerryLink/dsh-defend","desc":"Detects prompt-injection, jailbreak, and secret-leak patterns on the agent/pre-step, tools/pre-execute, and tools/post-execute seams with allow/ask/block tiers, sanitized defend/detection audit events, a defend_report tool, and a destructive-delete command guard.","cmd":"dsh plugin --profile web add dsh-defend","href":"/p/PerryLink/dsh-defend/"},{"cat":"security","tag":"Security & Permissions","dl":3605,"stars":164,"added":"2026-09-15","npm":1,"name":"dsh-auto-mode","owner":"NanmiCoder","short":"dsh-auto-mode","slug":"NanmiCoder/dsh-auto-mode","desc":"Adds an Auto permission preset between Workspace Write and Full access: routine work stays in the official workspace-write sandbox while the current session model reviews escalation and destructive calls, granting one exact wider access once, asking when the intent is ambiguous, and denying critical paths.","cmd":"dsh plugin --profile web add @nanmicoder/dsh-auto-mode","href":"/p/NanmiCoder/dsh-auto-mode/"},{"cat":"security","tag":"Security & Permissions","dl":3474,"stars":64,"added":"2026-09-18","npm":1,"name":"dsh-redteam-mode#packages/redteam-bundle","owner":"Jueze-2019","short":"dsh-redteam-mode#packages/redteam-bundle","slug":"Jueze-2019/dsh-redteam-mode--packages-redteam-bundle","desc":"Red-team engagement mode: send one target organization name and a planner session runs a five-role execution team (recon, asset triage, vulnerability discovery, exploitation, internal pivot) at up to three concurrent agents, preflight-checking skills and resources and asking once for any missing key or VPS first, guided by a built-in first-run onboarding skill; scoring follows the merged intrusion scoring rules (8 categories / 25 points) with server-side caps, highest-privilege-wins and per-service dedup, and self-registered accounts never score; findings land in a local SQLite fact base with discovery timestamps, shown in a persistent right-side console of 12 tabs (asset mapping with a discovery timeline, agent roster, session/tunnel state, five-stage attack chain, scoring targets, a report that spells out how each score was obtained — actions, exact commands, credential provenance, tunnel build commands — a category-organised POC/EXP knowledge base and a skill library with per-skill usability verdicts); ships 23 native skills, 53 redteam_* tools and one-command self-update.","cmd":"dsh plugin --profile web add dsh-redteam-mode","href":"/p/Jueze-2019/dsh-redteam-mode--packages-redteam-bundle/"},{"cat":"security","tag":"Security & Permissions","dl":3325,"stars":0,"added":"2026-09-13","npm":1,"name":"dsh-agent-loop-guard","owner":"GooDAnDReaDY","short":"dsh-agent-loop-guard","slug":"GooDAnDReaDY/dsh-agent-loop-guard","desc":"Fail-closed runtime tool-call loop guard for DeepSeek Harness.","cmd":"dsh plugin --profile web add @goodandready/dsh-agent-loop-guard","href":"/p/GooDAnDReaDY/dsh-agent-loop-guard/"},{"cat":"security","tag":"Security & Permissions","dl":3258,"stars":0,"added":"2026-08-29","npm":1,"name":"dsh-completion-guard","owner":"GreenLv","short":"dsh-completion-guard","slug":"GreenLv/dsh-completion-guard","desc":"Keeps DSH agents from forgetting your requirements during long tasks. It saves important conditions and completion evidence locally, brings them back after context compaction or session resume, and stops partial work from being reported as the whole task done.","cmd":"dsh plugin --profile web add dsh-completion-guard","href":"/p/GreenLv/dsh-completion-guard/"},{"cat":"security","tag":"Security & Permissions","dl":2878,"stars":6,"added":"2026-08-27","npm":1,"name":"dsh-automode","owner":"log-li","short":"dsh-automode","slug":"log-li/dsh-automode","desc":"CC-style auto-approval for DeepSeek Harness: deterministic deny/allow rules plus a two-stage allow/reject classifier with a circuit breaker and denial guidance.","cmd":"dsh plugin --profile web add @log.li/dsh-automode","href":"/p/log-li/dsh-automode/"},{"cat":"security","tag":"Security & Permissions","dl":2799,"stars":12,"added":"2026-08-29","npm":1,"name":"dsh-mask","owner":"PerryLink","short":"dsh-mask","slug":"PerryLink/dsh-mask","desc":"PII masking for DeepSeek Harness — anonymizes names, phones, emails, ids, and keys before requests and restores them at the display layer, keeping plaintext out of session logs.","cmd":"dsh plugin --profile web add dsh-mask","href":"/p/PerryLink/dsh-mask/"},{"cat":"security","tag":"Security & Permissions","dl":2489,"stars":37,"added":"2026-08-28","npm":1,"name":"dsh-pentester","owner":"fb0sh","short":"dsh-pentester","slug":"fb0sh/dsh-pentester","desc":"PTES-based penetration testing plugin with Root-Orchestrator architecture for DeepSeek Harness.","cmd":"dsh plugin --profile web add dsh-pentester","href":"/p/fb0sh/dsh-pentester/"},{"cat":"security","tag":"Security & Permissions","dl":2483,"stars":3,"added":"2026-08-16","npm":1,"name":"dsh-plugin-vet","owner":"wulun811","short":"dsh-plugin-vet","slug":"wulun811/dsh-plugin-vet","desc":"Plugin trust pipeline for DeepSeek Harness: deterministic static scan with verdicts, opt-in runtime guard with honeypot lures, agent audit-protocol skill, and a browser shield status light. Alarm-only, never an enforcer.","cmd":"dsh plugin --profile web add @jieai/dsh-plugin-vet","href":"/p/wulun811/dsh-plugin-vet/"},{"cat":"security","tag":"Security & Permissions","dl":2418,"stars":3,"added":"2026-08-23","npm":1,"name":"dsh-agent-approval","owner":"MoonlitDropOfBlood","short":"dsh-agent-approval","slug":"MoonlitDropOfBlood/dsh-agent-approval","desc":"An independent approval subagent judges every sandbox escalation, with a configurable model and an audit log.","cmd":"dsh plugin --profile web add @duke-dsh-plugins/dsh-agent-approval","href":"/p/MoonlitDropOfBlood/dsh-agent-approval/"},{"cat":"security","tag":"Security & Permissions","dl":2356,"stars":3,"added":"2026-08-18","npm":1,"name":"dsh-rule-engine","owner":"jilian-dsh","short":"dsh-rule-engine","slug":"jilian-dsh/dsh-rule-engine","desc":"Rules execution engine for dsh: parses AGENTS.md, hard-blocks rule-violating tool calls, text-based B/D rule auditing, /guard command, version-guard for versioned files, and free-zone support (engine skips free-zone sections).","cmd":"dsh plugin --profile web add dsh-rule-engine","href":"/p/jilian-dsh/dsh-rule-engine/"},{"cat":"security","tag":"Security & Permissions","dl":2355,"stars":10,"added":"2026-08-16","npm":1,"name":"dsh-permgate","owner":"MrWeiCodes","short":"dsh-permgate","slug":"MrWeiCodes/dsh-permgate","desc":"Fine-grained permission gateway: per-category tool-call review (outside-workspace directories, commands, file read/write, subagents, repeated actions) with global & per-project allow/deny exceptions, quick-tool defaults, custom rules, a bilingual approval modal with inline diff details, custom rejection reasons and a sandbox-upgrade flow.","cmd":"dsh plugin --profile web add @mrweicodes/dsh-permgate","href":"/p/MrWeiCodes/dsh-permgate/"},{"cat":"security","tag":"Security & Permissions","dl":2120,"stars":2,"added":"2026-08-28","npm":1,"name":"dsh-trust-check","owner":"liuwenji007","short":"dsh-trust-check","slug":"liuwenji007/dsh-trust-check","desc":"Static capability disclosure for DeepSeek Harness plugins: a Settings page and CLI that list installed plugins' capabilities, literal destinations, install scripts, and injection shapes (prompt registrations, shipped skill text, bundle patch), each with file:line evidence. Code-determined, reproducible, zero-token. Disclosure only — not a security verdict, never a safety claim.","cmd":"dsh plugin --profile web add dsh-trust-check","href":"/p/liuwenji007/dsh-trust-check/"},{"cat":"security","tag":"Security & Permissions","dl":2016,"stars":13,"added":"2026-08-17","npm":1,"name":"dsh-auth-gateway","owner":"xbzbing","short":"dsh-auth-gateway","slug":"xbzbing/dsh-auth-gateway","desc":"Password + TOTP two-factor authentication gateway for the dsh web UI: every HTTP request and WebSocket upgrade is refused until login, with per-source lockout, global rate limits and one-time backup codes.","cmd":"dsh plugin --profile web add dsh-auth-gateway","href":"/p/xbzbing/dsh-auth-gateway/"},{"cat":"security","tag":"Security & Permissions","dl":1883,"stars":12,"added":"2026-08-15","npm":1,"name":"upstream-radar","owner":"MicroMilo","short":"upstream-radar","slug":"MicroMilo/upstream-radar","desc":"Watches DSH and plugin releases, retests exact published artifacts in disposable runners, publishes machine-readable compatibility evidence, and reconciles managed issues after fixes.","cmd":"dsh plugin --profile web add upstream-radar","href":"/p/MicroMilo/upstream-radar/"},{"cat":"security","tag":"Security & Permissions","dl":1777,"stars":3,"added":"2026-08-17","npm":1,"name":"dsh-yolo-mode","owner":"SeverusZh","short":"dsh-yolo-mode","slug":"SeverusZh/dsh-yolo-mode","desc":"LLM auto-approval for sandbox escalation requests, with presets and a fail-closed fallback.","cmd":"dsh plugin --profile web add dsh-yolo-mode","href":"/p/SeverusZh/dsh-yolo-mode/"},{"cat":"security","tag":"Security & Permissions","dl":1772,"stars":67,"added":"2026-08-17","npm":1,"name":"dsh-remote","owner":"xgone","short":"dsh-remote","slug":"xgone/dsh-remote","desc":"Secure remote access for the DeepSeek Harness Web UI: a login gate, MFA/TOTP, signed session cookies, optional admin/user/guest roles, in-browser workspace selection, and allowlisted remote file previews.","cmd":"dsh plugin --profile web add @xgone/dsh-remote","href":"/p/xgone/dsh-remote/"},{"cat":"security","tag":"Security & Permissions","dl":1735,"stars":0,"added":"2026-09-18","npm":1,"name":"dsh-approval-review","owner":"LAwLi3tCoding","short":"dsh-approval-review","slug":"LAwLi3tCoding/dsh-approval-review","desc":"Adds an \"approve for me\" access mode whose approval requests are answered by an independent reviewer model instead of a person: the reviewer can read the workspace read-only, a reviewer that cannot run hands the request back to the human, and every decision is recorded with its rationale in an Approvals tab.","cmd":"dsh plugin --profile web add dsh-approval-review","href":"/p/LAwLi3tCoding/dsh-approval-review/"},{"cat":"security","tag":"Security & Permissions","dl":1676,"stars":2,"added":"2026-09-13","npm":1,"name":"dsh-auto-approve","owner":"DNAlec","short":"dsh-auto-approve","slug":"DNAlec/dsh-auto-approve","desc":"Automatic approval and review for tool calls that need approval: keyword buckets match red lines without context, then a judge model classifies what was requested and sends it to allow, reject or a human according to the matching row and risk level; a judgment that never ran always goes to a human, and rejections tell the model why.","cmd":"dsh plugin --profile web add @dnalec/dsh-auto-approve","href":"/p/DNAlec/dsh-auto-approve/"},{"cat":"security","tag":"Security & Permissions","dl":1616,"stars":1,"added":"2026-08-17","npm":1,"name":"dsh-code-security","owner":"STARDUSTLC666","short":"dsh-code-security","slug":"STARDUSTLC666/dsh-code-security","desc":"Deterministic code security review: 40+ rules, secret entropy detection, staged-diff review, SARIF export, baseline acceptance, SBOM-lite dependency inventory and health self-check.","cmd":"dsh plugin --profile web add dsh-code-security","href":"/p/STARDUSTLC666/dsh-code-security/"},{"cat":"security","tag":"Security & Permissions","dl":1541,"stars":0,"added":"2026-08-17","npm":1,"name":"dsh-plugin-gate","owner":"863683348","short":"dsh-plugin-gate","slug":"863683348/dsh-plugin-gate","desc":"Installation safety gate for DSH plugins: antivirus-style scan of install scripts, permissions, secrets and network callbacks on local directories or npm tarballs, returning a BLOCK/WARN/PASS verdict before \"dsh plugin add\".","cmd":"dsh plugin --profile web add dsh-plugin-gate","href":"/p/863683348/dsh-plugin-gate/"},{"cat":"security","tag":"Security & Permissions","dl":1434,"stars":1,"added":"2026-09-22","npm":1,"name":"euthyna","owner":"slow-stack","short":"euthyna","slug":"slow-stack/euthyna","desc":"Security-audit facts AI coding agents cannot compute, plus a verdict gate: euthyna history attributes deleted lines to commits and flags those from security fixes (--origins finds the first introducer), euthyna coverage reports which changed symbols no test ever invoked, and euthyna gate checks each finding against six gates, downgrading any without evidence to an observation.","cmd":"dsh plugin --profile web add euthyna","href":"/p/slow-stack/euthyna/"},{"cat":"security","tag":"Security & Permissions","dl":1424,"stars":15,"added":"2026-08-15","npm":1,"name":"dsh-auto-approve","owner":"Jiao-XXX","short":"dsh-auto-approve","slug":"Jiao-XXX/dsh-auto-approve","desc":"Adds an `auto` permission preset between workspace-write and danger-full-access: a classifier grants routine sandbox escalations once, while dangerous or uncertain requests still go to a human.","cmd":"dsh plugin --profile web add dsh-auto-approve","href":"/p/Jiao-XXX/dsh-auto-approve/"},{"cat":"security","tag":"Security & Permissions","dl":1247,"stars":85,"added":"2026-08-21","npm":1,"name":"dsh-secure-audit","owner":"PensiveFei","short":"dsh-secure-audit","slug":"PensiveFei/dsh-secure-audit","desc":"Read-only security and compliance plugin for DeepSeek Harness: prompt-injection detection, Chinese-PII redaction, and a local configuration audit with redacted, reproducible reports.","cmd":"dsh plugin --profile web add dsh-secure-audit","href":"/p/PensiveFei/dsh-secure-audit/"},{"cat":"security","tag":"Security & Permissions","dl":1197,"stars":7,"added":"2026-08-19","npm":1,"name":"dsh-riskproof","owner":"onlyqzq","short":"dsh-riskproof","slug":"onlyqzq/dsh-riskproof","desc":"Live security beacon for DSH that follows tool activity. Click to view call statistics, risk provenance chains and blocked actions, with read-only task restrictions and tool metadata change detection.","cmd":"dsh plugin --profile web add dsh-riskproof","href":"/p/onlyqzq/dsh-riskproof/"},{"cat":"security","tag":"Security & Permissions","dl":1191,"stars":10,"added":"2026-08-27","npm":1,"name":"dsh-login","owner":"islibaodong","short":"dsh-login","slug":"islibaodong/dsh-login","desc":"Multi-user login gateway for the DSH web UI: the first visit creates the admin account, admins add and manage users in the GUI settings panel, ordinary users see only their own conversations, and unauthenticated visitors are redirected to /login.","cmd":"dsh plugin --profile web add @islibaodong/dsh-login","href":"/p/islibaodong/dsh-login/"},{"cat":"security","tag":"Security & Permissions","dl":1164,"stars":1,"added":"2026-09-06","npm":1,"name":"dsh-semgrep-sast#semgrep-sast","owner":"Baiiduu","short":"dsh-semgrep-sast#semgrep-sast","slug":"Baiiduu/dsh-semgrep-sast--packages-bundle","desc":"Workspace-scoped Semgrep SAST tool for DeepSeek Harness with a managed Windows x64 runtime, structured bounded findings, cancellation and timeout controls, and user-approved sandbox escalation. Installs from npm as @aaub-software/dsh-semgrep-sast.","cmd":"dsh plugin --profile web add @aaub-software/dsh-semgrep-sast","href":"/p/Baiiduu/dsh-semgrep-sast--packages-bundle/"},{"cat":"security","tag":"Security & Permissions","dl":1043,"stars":7,"added":"2026-08-14","npm":1,"name":"dsh-approval-llm","owner":"Letter2025","short":"dsh-approval-llm","slug":"Letter2025/dsh-approval-llm","desc":"Model-based permission approval: an approval-request answerer backed by a separate reviewer model.","cmd":"dsh plugin --profile web add dsh-approval-llm","href":"/p/Letter2025/dsh-approval-llm/"},{"cat":"security","tag":"Security & Permissions","dl":1031,"stars":6,"added":"2026-08-28","npm":1,"name":"dsh-ui-auth","owner":"0QwQ0","short":"dsh-ui-auth","slug":"0QwQ0/dsh-ui-auth","desc":"Authentication gate for the DeepSeek Harness Web UI: the login gate covers pages, /api, /plugins and WebSocket upgrades; PBKDF2 password hashing, HttpOnly SameSite session cookies and IP-based login lockout; invite-code registration; two-factor login with TOTP or passkeys (WebAuthn: several keys per account, phone enrolment by QR, username-less sign-in, and a password or second-factor step-up before any login factor is added or removed); a user-management settings panel (users edit their own profile and manage their own TOTP and passkeys, admins add or remove users, reset passwords, manage invites and clear the passkeys of a lost device); admin-only model and API-key configuration guards; per-user isolation on the REST/list APIs and on the WebSocket event streams; session persistence across restarts; a JSONL audit log; and a fail-closed gateway. Runs on both DSH transport lines (0.1.1-rc.2 legacy and 0.1.2+ modern) with no configuration; passkey login needs a localhost or HTTPS origin because browsers require a secure context.","cmd":"dsh plugin --profile web add dsh-ui-auth","href":"/p/0QwQ0/dsh-ui-auth/"},{"cat":"security","tag":"Security & Permissions","dl":911,"stars":1,"added":"2026-09-06","npm":1,"name":"dsh-kubectl-guard","owner":"gengwg","short":"dsh-kubectl-guard","slug":"gengwg/dsh-kubectl-guard","desc":"Policy plugin that gates kubectl by kubeconfig context: hard-deny irreversible verbs outside local clusters, ask for the rest.","cmd":"dsh plugin --profile web add dsh-kubectl-guard","href":"/p/gengwg/dsh-kubectl-guard/"},{"cat":"security","tag":"Security & Permissions","dl":899,"stars":6,"added":"2026-08-19","npm":1,"name":"dsh-auth","owner":"hxy91819","short":"dsh-auth","slug":"hxy91819/dsh-auth","desc":"Caddy forward_auth administrator login for DeepSeek Harness Web, with Argon2id passwords, revocable sessions, bilingual UI, and a native sidebar sign-out action.","cmd":"dsh plugin --profile web add dsh-auth","href":"/p/hxy91819/dsh-auth/"},{"cat":"security","tag":"Security & Permissions","dl":868,"stars":0,"added":"2026-09-21","npm":1,"name":"dsh-jev-guard","owner":"7starsseeker","short":"dsh-jev-guard","slug":"7starsseeker/dsh-jev-guard","desc":"Pre-execution safety valve for DSH that judges with TypeSafe Jev: it hooks tools/pre-execute and decides every bash/pwsh call by first applying offline static rules, then by asking the Jev model — the System One model from TypeSafe, which returns a structured decision instead of prose — one yes-no question (\"will this command irreversibly delete or overwrite real data?\"), turning the answer into allow, revise, block or escalate; revise hands the model a safer rewrite, escalate offers a one-shot human token; exhausted credit or a missing API key degrades loudly instead of failing silent, and a missing key is requested in the conversation itself (`guard key set`, read from stdin); every verdict is appended to a shared audit log and the text people read is bilingual zh-CN/en.","cmd":"dsh plugin --profile web add dsh-jev-guard","href":"/p/7starsseeker/dsh-jev-guard/"},{"cat":"security","tag":"Security & Permissions","dl":848,"stars":2,"added":"2026-09-03","npm":1,"name":"dsh-secret-scrub","owner":"jkt-check","short":"dsh-secret-scrub","slug":"jkt-check/dsh-secret-scrub","desc":"Irreversible secret-scrubbing guard: rewrites access keys, bearer tokens, and private key blocks into `[REDACTED:<category>]` placeholders before they reach the session log and the model.","cmd":"dsh plugin --profile web add dsh-secret-scrub","href":"/p/jkt-check/dsh-secret-scrub/"},{"cat":"security","tag":"Security & Permissions","dl":834,"stars":1,"added":"2026-08-19","npm":1,"name":"dsh-provenance","owner":"Darren-Tang","short":"dsh-provenance","slug":"Darren-Tang/dsh-provenance","desc":"Pre-install supply-chain checks for DeepSeek Harness plugins: verify the tarball you are about to install matches the source you read, before any code runs.","cmd":"dsh plugin --profile web add dsh-provenance","href":"/p/Darren-Tang/dsh-provenance/"},{"cat":"security","tag":"Security & Permissions","dl":813,"stars":1,"added":"2026-08-31","npm":1,"name":"dsh-cloudflare-access","owner":"Luawig","short":"dsh-cloudflare-access","slug":"Luawig/dsh-cloudflare-access","desc":"Re-validates Cloudflare Access JWTs at the DSH origin so Settings, Credentials, Agent Preset management, and model discovery work from a remote hostname.","cmd":"dsh plugin --profile web add dsh-cloudflare-access","href":"/p/Luawig/dsh-cloudflare-access/"},{"cat":"security","tag":"Security & Permissions","dl":777,"stars":2,"added":"2026-08-27","npm":1,"name":"dsh-sonarqube","owner":"maxmilian","short":"dsh-sonarqube","slug":"maxmilian/dsh-sonarqube","desc":"Read-only SonarQube Community Build tools: instance status, project Quality Gate for a branch or pull request, issue and Security Hotspot search, single hotspot detail, and coverage, duplication or caller-selected measures. Issue and hotspot results carry a normalized location with component key, file path, line and text range.","cmd":"dsh plugin --profile web add dsh-sonarqube","href":"/p/maxmilian/dsh-sonarqube/"},{"cat":"security","tag":"Security & Permissions","dl":775,"stars":3,"added":"2026-08-14","npm":1,"name":"qiushi-dsh-evidence-audit","owner":"030611","short":"qiushi-dsh-evidence-audit","slug":"030611/qiushi-dsh-evidence-audit","desc":"Appends local hash-chained JSONL receipts for tool results and session events without storing prompts, tool arguments, result text, or raw session IDs.","cmd":"dsh plugin --profile web add qiushi-dsh-evidence-audit","href":"/p/030611/qiushi-dsh-evidence-audit/"},{"cat":"security","tag":"Security & Permissions","dl":748,"stars":2,"added":"2026-08-14","npm":1,"name":"dsh-telemetry-redactor","owner":"030611","short":"dsh-telemetry-redactor","slug":"030611/dsh-telemetry-redactor","desc":"Redacts supported secret patterns from the `session-telemetry/record` export copy before configured telemetry backends receive it.","cmd":"dsh plugin --profile web add dsh-telemetry-redactor","href":"/p/030611/dsh-telemetry-redactor/"},{"cat":"security","tag":"Security & Permissions","dl":718,"stars":0,"added":"2026-09-10","npm":1,"name":"dsh-totp","owner":"SodaZheng","short":"dsh-totp","slug":"SodaZheng/dsh-totp","desc":"TOTP-only access control for personal DeepSeek Harness Web instances, with in-app QR enrollment, single-use recovery codes, live protection controls and lock-all revocation of page access.","cmd":"dsh plugin --profile web add dsh-totp","href":"/p/SodaZheng/dsh-totp/"},{"cat":"security","tag":"Security & Permissions","dl":717,"stars":4,"added":"2026-08-15","npm":1,"name":"dsh-plugin-vetting","owner":"truelove-dreamer","short":"dsh-plugin-vetting","slug":"truelove-dreamer/dsh-plugin-vetting","desc":"Vets third-party plugins before you trust them: static scan for malicious patterns (exfiltration, credential access, obfuscation, persistence) and over-privileged path use, transitive-dependency coverage, official-package hash baseline for supply-chain tamper detection, and an optional plugin-tool call gate.","cmd":"dsh plugin --profile web add dsh-plugin-vetting","href":"/p/truelove-dreamer/dsh-plugin-vetting/"},{"cat":"security","tag":"Security & Permissions","dl":699,"stars":1,"added":"2026-08-16","npm":1,"name":"dsh-security-guard","owner":"bigclawd","short":"dsh-security-guard","slug":"bigclawd/dsh-security-guard","desc":"Static and runtime security guard for dsh: rule-based scans for malicious code, prompt injection and token waste, runtime interception of dangerous tool calls, /scan command, plugin_scan tool, web panel, and allowlist.","cmd":"dsh plugin --profile web add dsh-security-guard","href":"/p/bigclawd/dsh-security-guard/"},{"cat":"security","tag":"Security & Permissions","dl":686,"stars":3,"added":"2026-09-09","npm":1,"name":"dsh-write-protect","owner":"azazo1","short":"dsh-write-protect","slug":"azazo1/dsh-write-protect","desc":"Keep declared workspace subpaths (e.g. .git) read-only, honor a read-only rules file at the workspace root, grant extra writable roots under workspace-write, and let the model request session-scoped write access; enforced for sandboxed CLI commands and the write/edit tools.","cmd":"dsh plugin --profile web add dsh-write-protect","href":"/p/azazo1/dsh-write-protect/"},{"cat":"security","tag":"Security & Permissions","dl":686,"stars":3,"added":"2026-08-27","npm":1,"name":"dsh-always-require-tools-approval","owner":"J0ss077","short":"dsh-always-require-tools-approval","slug":"J0ss077/dsh-always-require-tools-approval","desc":"Requires one-shot user approval before configured tools (default bash, pwsh) execute — gated tools pause and ask, everything else delegates, and a missing approval channel fails closed.","cmd":"dsh plugin --profile web add @j0ss077/dsh-always-require-tools-approval","href":"/p/J0ss077/dsh-always-require-tools-approval/"},{"cat":"security","tag":"Security & Permissions","dl":672,"stars":0,"added":"2026-08-18","npm":1,"name":"dsh-risk-guard","owner":"shuxue6662-a11y","short":"dsh-risk-guard","slug":"shuxue6662-a11y/dsh-risk-guard","desc":"Zero-interruption audit and fuse blocking for DeepSeek Harness: silently records every tool call with deterministic risk scoring, cumulative-risk bonuses, risk-level breakdowns and retention-based cleanup; blocks irreversible catastrophes (protected-path deletion, disk wipe, force-push to protected branches/refs, credential exfiltration), and renders a redacted /risk-guard operation bill with --since filtering.","cmd":"dsh plugin --profile web add dsh-risk-guard","href":"/p/shuxue6662-a11y/dsh-risk-guard/"},{"cat":"security","tag":"Security & Permissions","dl":649,"stars":2,"added":"2026-08-17","npm":1,"name":"dsh-web-auth","owner":"SummerSec","short":"dsh-web-auth","slug":"SummerSec/dsh-web-auth","desc":"Transport-level authentication gate for the DeepSeek Harness Web GUI with server-side sessions, HttpOnly cookies, IP-based login throttling, and an scrypt password CLI.","cmd":"dsh plugin --profile web add @summersec/dsh-web-auth","href":"/p/SummerSec/dsh-web-auth/"},{"cat":"security","tag":"Security & Permissions","dl":593,"stars":0,"added":"2026-09-20","npm":1,"name":"dsh-tm-guard","owner":"ChaoJie0","short":"dsh-tm-guard","slug":"ChaoJie0/dsh-tm-guard","desc":"Zero-intervention permission gate for DSH agents on macOS: auto-allows local writes made reversible by git or Time Machine, blocks network, package installs, process control and sensitive-path reads, with full audit logs.","cmd":"dsh plugin --profile web add dsh-tm-guard","href":"/p/ChaoJie0/dsh-tm-guard/"},{"cat":"security","tag":"Security & Permissions","dl":586,"stars":0,"added":"2026-08-13","npm":1,"name":"dsh-tool-approval","owner":"ilharp","short":"dsh-tool-approval","slug":"ilharp/dsh-tool-approval","desc":"Manual approval mode (\"Manual Mode\" / \"Ask Mode\").","cmd":"dsh plugin --profile web add dsh-tool-approval","href":"/p/ilharp/dsh-tool-approval/"},{"cat":"security","tag":"Security & Permissions","dl":584,"stars":1,"added":"2026-08-15","npm":1,"name":"dsh-auto-classifier","owner":"PAKIKNOWLEDGE","short":"dsh-auto-classifier","slug":"PAKIKNOWLEDGE/dsh-auto-classifier","desc":"Autonomous permission classifier for the auto preset: tool-scoped allow/deny rules, an LLM semantic judge, and git checkpointing for unattended sessions.","cmd":"dsh plugin --profile web add dsh-auto-classifier","href":"/p/PAKIKNOWLEDGE/dsh-auto-classifier/"},{"cat":"security","tag":"Security & Permissions","dl":554,"stars":9,"added":"2026-08-21","npm":1,"name":"dshscan","owner":"shaoshi20","short":"dshscan","slug":"shaoshi20/dshscan","desc":"Security scanner for DSH plugins: static and semantic passes over plugin source, DSH-specific attack-surface rules, npm audit, batch scanning, and an HTML report with per-finding severity and evidence.","cmd":"dsh plugin --profile web add @shaoshi/dshscan","href":"/p/shaoshi20/dshscan/"},{"cat":"security","tag":"Security & Permissions","dl":547,"stars":5,"added":"2026-08-20","npm":1,"name":"dsh-sentinel-scanner","owner":"Eligahyu","short":"dsh-sentinel-scanner","slug":"Eligahyu/dsh-sentinel-scanner","desc":"Static security scanner for DSH plugins: read-only audit (exec, credentials, exfiltration, obfuscation, install scripts, bundle manifest) with a 0-100 risk score.","cmd":"dsh plugin --profile web add deepseek-harness-sentinel","href":"/p/Eligahyu/dsh-sentinel-scanner/"},{"cat":"security","tag":"Security & Permissions","dl":516,"stars":1,"added":"2026-08-19","npm":1,"name":"dsh-almost_full_access","owner":"Alnita-M","short":"dsh-Almost_Full_Access","slug":"Alnita-M/dsh-Almost_Full_Access","desc":"Permission mode between workspace-write and full access: shell commands are checked by deterministic rules and a subagent review; irreversible or system-level actions require explicit approval.","cmd":"dsh plugin --profile web add dsh-almost-full-access","href":"/p/Alnita-M/dsh-Almost_Full_Access/"},{"cat":"security","tag":"Security & Permissions","dl":507,"stars":0,"added":"2026-08-30","npm":1,"name":"dsh-dros-vajraclaw","owner":"Top-Celestial-Company-Ltd","short":"dsh-dros-vajraclaw","slug":"Top-Celestial-Company-Ltd/dsh-dros-vajraclaw","desc":"Local tool-call failsafe for DSH: blocks a fixed list of high-risk shell patterns and credential-file reads before execution, with a per-session hash-linked JSONL audit log, and an optional external Gateway for centralized policy.","cmd":"dsh plugin --profile web add dsh-plugin-vajraclaw","href":"/p/Top-Celestial-Company-Ltd/dsh-dros-vajraclaw/"},{"cat":"security","tag":"Security & Permissions","dl":501,"stars":14,"added":"2026-08-15","npm":1,"name":"dsh-movein#plugin","owner":"sjh9714","short":"dsh-movein#plugin","slug":"sjh9714/dsh-movein--plugin","desc":"Fine grained per tool permission rules for DSH at the tools/pre-execute gate, deny and ask lists in Claude Code rule syntax (`Bash(rm -rf:*), Read(_secrets_), mcp__server__tool`), works standalone without migrating.","cmd":"dsh plugin --profile web add dsh-movein-permissions","href":"/p/sjh9714/dsh-movein--plugin/"},{"cat":"security","tag":"Security & Permissions","dl":498,"stars":0,"added":"2026-09-15","npm":1,"name":"dsh-redaction#dsh-plugin-redact","owner":"L-ingqin12","short":"dsh-redaction#dsh-plugin-redact","slug":"L-ingqin12/dsh-redaction--packages-dsh-plugin-redact","desc":"In-place redaction and row-level rollback for session logs, preserving the seq-equals-row-index invariant that makes deleting a middle row corrupt the entire log. Originals are copied to a quarantine sibling before any write, and the reader's own semantics are replayed as a pre-write gate.","cmd":"dsh plugin --profile web add dsh-plugin-redact","href":"/p/L-ingqin12/dsh-redaction--packages-dsh-plugin-redact/"},{"cat":"security","tag":"Security & Permissions","dl":484,"stars":0,"added":"2026-09-15","npm":1,"name":"dsh-redaction#dsh-plugin-content-policy","owner":"L-ingqin12","short":"dsh-redaction#dsh-plugin-content-policy","slug":"L-ingqin12/dsh-redaction--packages-dsh-plugin-content-policy","desc":"Preventive content policy for tool results: rewrites matched text, and drops or truncates whole fields by path before a result is normalised, rendered or persisted, so an unreviewed payload never enters it. Ships inert with no built-in category or domain blocklist.","cmd":"dsh plugin --profile web add dsh-plugin-content-policy","href":"/p/L-ingqin12/dsh-redaction--packages-dsh-plugin-content-policy/"},{"cat":"security","tag":"Security & Permissions","dl":457,"stars":4,"added":"2026-08-14","npm":1,"name":"dsh-verification-receipt","owner":"030611","short":"dsh-verification-receipt","slug":"030611/dsh-verification-receipt","desc":"Writes local JSONL summaries of per-turn tool counts and coarse verification signals without storing prompts, tool arguments, or result text.","cmd":"dsh plugin --profile web add dsh-verification-receipt","href":"/p/030611/dsh-verification-receipt/"},{"cat":"security","tag":"Security & Permissions","dl":436,"stars":1,"added":"2026-08-17","npm":1,"name":"dsh-poison-guard","owner":"zoahdev","short":"dsh-poison-guard","slug":"zoahdev/dsh-poison-guard","desc":"Pre-install supply-chain poison scanner for DSH plugins: AST (JS-X-Ray) + deobfuscation + regex heuristics, exits non-zero on findings for CI gating.","cmd":"dsh plugin --profile web add dsh-poison-guard","href":"/p/zoahdev/dsh-poison-guard/"},{"cat":"security","tag":"Security & Permissions","dl":404,"stars":22,"added":"2026-09-25","npm":1,"name":"dsh-jev-interceptor","owner":"AskTheWay","short":"dsh-jev-interceptor","slug":"AskTheWay/dsh-jev-interceptor","desc":"Classifies pending tool calls with Jev (TypeSafe AI's non-generative decision model) on tools/pre-execute — confident high-risk calls are denied, ambiguous ones escalated to approval — and auto-approves clearly-granted reversible calls on approval/request behind argument-evidence gating. Also subclasses the session-reference resolver so snapshots keep Jev-scored messages instead of dropping oldest-first. Degrades to stock behavior on any provider failure; shadow mode with a /jev-stats command; TypeSafe or OpenRouter endpoints; 64 tests.","cmd":"dsh plugin --profile web add dsh-jev-interceptor","href":"/p/AskTheWay/dsh-jev-interceptor/"},{"cat":"security","tag":"Security & Permissions","dl":386,"stars":1,"added":"2026-09-19","npm":1,"name":"dsh-plugin-precheck","owner":"BaqiF2","short":"dsh-plugin-precheck","slug":"BaqiF2/dsh-plugin-precheck","desc":"Pre-install compatibility gate for DSH plugins: locks the resolved version, checks peer/engines declarations, dry-installs into an isolated DSH_HOME and boots it with a timeout, blocks on any failure, and restores the profile if the real install fails. Optionally intercepts dsh-market install/update clicks.","cmd":"dsh plugin --profile web add dsh-plugin-precheck","href":"/p/BaqiF2/dsh-plugin-precheck/"},{"cat":"security","tag":"Security & Permissions","dl":358,"stars":0,"added":"2026-08-15","npm":1,"name":"dsh-plugin-judge","owner":"pengxuding","short":"dsh-plugin-judge","slug":"pengxuding/dsh-plugin-judge","desc":"Plugin value auditor: pre-install review (source scan + LLM judge) and post-install audit of installed bundles, with model-switch re-audit reminders.","cmd":"dsh plugin --profile web add dsh-plugin-judge","href":"/p/pengxuding/dsh-plugin-judge/"},{"cat":"security","tag":"Security & Permissions","dl":351,"stars":1,"added":"2026-08-19","npm":1,"name":"dsh-write-gate","owner":"couldbeme","short":"dsh-write-gate","slug":"couldbeme/dsh-write-gate","desc":"Commitment write-gate: operator-authored rules enforced before a tool call runs — a deterministic guard tier plus an LLM-judge tier, fail-closed by default, every block written to a contradictions log.","cmd":"dsh plugin --profile web add dsh-write-gate","href":"/p/couldbeme/dsh-write-gate/"},{"cat":"security","tag":"Security & Permissions","dl":347,"stars":0,"added":"2026-08-15","npm":1,"name":"dsh-lan-pass","owner":"x2802490130-prog","short":"dsh-lan-pass","slug":"x2802490130-prog/dsh-lan-pass","desc":"A LAN password gate for the Web UI: phones and tablets on the same network log in with a shared key and see the same sessions in real time, with a built-in randomUUID polyfill for plain-HTTP origins.","cmd":"dsh plugin --profile web add dsh-lan-pass","href":"/p/x2802490130-prog/dsh-lan-pass/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":865,"added":"2026-08-18","npm":0,"name":"api-relay-audit","owner":"toby-bridges","short":"api-relay-audit","slug":"toby-bridges/api-relay-audit","desc":"Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.","cmd":"dsh plugin --profile web add github:toby-bridges/api-relay-audit","href":"/p/toby-bridges/api-relay-audit/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":655,"added":"2026-08-27","npm":0,"name":"dsh-redteam-model","owner":"SeaOf0","short":"dsh-redteam-model","slug":"SeaOf0/dsh-redteam-model","desc":"Authorized-security DSH collection: nine work modes (redteam coordinator, pentest, code audit, binary analysis, attack-defense, AV evasion, incident response, cloud security, CTF solving) and fifteen runtime plugins, managed from a settings page with one-click deploy, install, update and uninstall.","cmd":"dsh plugin --profile web add github:SeaOf0/dsh-redteam-model","href":"/p/SeaOf0/dsh-redteam-model/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":571,"added":"2026-08-20","npm":0,"name":"dsh-pentest","owner":"howmp","short":"dsh-pentest","slug":"howmp/dsh-pentest","desc":"Authorized pentest mode for DeepSeek Harness — exploration chain, assets and findings with a Web view.","cmd":"dsh plugin --profile web add github:howmp/dsh-pentest","href":"/p/howmp/dsh-pentest/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":90,"added":"2026-08-23","npm":0,"name":"helm-d#helmd","owner":"ADWMC","short":"helm-d#helmd","slug":"ADWMC/helm-d--packages-helmd","desc":"Single-bundle reverse-engineering and pentest security plugin: first-turn tool narrowing, domain routing, and 33 tools covering APK, web, native binary, protocol, malware and LLM samples — with unpacking, license-bypass and anti-analysis case playbooks, an H-CoT evaluation engine (semantic routing, /hcot command), a web workbench with a ledger-driven tool shelf, an on-disk case workflow (auto-persisted evidence chain, E-numbered validated findings, post-compaction resume), GitHub-based external tool discovery, and 361 on-demand reference docs.","cmd":"dsh plugin --profile web add github:ADWMC/helm-d#path:/packages/helmd","href":"/p/ADWMC/helm-d--packages-helmd/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":51,"added":"2026-09-02","npm":0,"name":"sofagent#cordis-plugin-sofagent-audit","owner":"KongFangXun","short":"sofagent#cordis-plugin-sofagent-audit","slug":"KongFangXun/sofagent--engine-dsh-plugins-cordis-plugin-sofagent-audit","desc":"Commit-time audit harness for AI coding agents: 24 git-diff rules (secrets, out-of-scope edits, prompt injection), HMAC-signed audit trail, snapshot rollback, and an MCP server with 84 tools. Installable via dsh plugin add.","cmd":"dsh plugin --profile web add github:KongFangXun/sofagent#path:/engine/dsh-plugins/cordis-plugin-sofagent-audit","href":"/p/KongFangXun/sofagent--engine-dsh-plugins-cordis-plugin-sofagent-audit/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":47,"added":"2026-08-19","npm":0,"name":"dsh-web-startup-auth","owner":"GDWhisper","short":"dsh-web-startup-auth","slug":"GDWhisper/dsh-web-startup-auth","desc":"Replaces the dsh web startup to allow binding 0.0.0.0, gated by username/password login: signed session cookies, /api route protection, an auth tab in the settings panel, and a reset CLI that rotates the signing key to invalidate all sessions.","cmd":"dsh plugin --profile web add github:GDWhisper/dsh-web-startup-auth","href":"/p/GDWhisper/dsh-web-startup-auth/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":17,"added":"2026-08-16","npm":0,"name":"dsh-skill-pack-security","owner":"PerryLink","short":"dsh-skill-pack-security","slug":"PerryLink/dsh-skill-pack-security","desc":"Security-audit methodology skill pack plus the plugin_vet supply-chain gate: eight agent skills (secret scan, dependency audit, supply-chain review, prompt-injection review, audit orchestration, threat modeling, vuln intel, incident response) in Chinese and English editions, with an npm provider bundle that mounts the skills and registers the automated plugin_vet pre-install scanner.","cmd":"dsh plugin --profile web add github:PerryLink/dsh-skill-pack-security","href":"/p/PerryLink/dsh-skill-pack-security/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":14,"added":"2026-08-13","npm":0,"name":"dsh-security-audit","owner":"omdsh-dev","short":"dsh-security-audit","slug":"omdsh-dev/dsh-security-audit","desc":"Local security audit: config, plugin origins, sessions, network exposure — read-only redacted risk report.","cmd":"dsh plugin --profile web add github:omdsh-dev/dsh-security-audit","href":"/p/omdsh-dev/dsh-security-audit/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":14,"added":"2026-08-27","npm":0,"name":"weiwen-law-dsh","owner":"Shaky77","short":"weiwen-law-dsh","slug":"Shaky77/weiwen-law-dsh","desc":"White-box causal guardrail for dsh: every tool call is adjudicated before execution along a deterministic causal logic chain — blocks destructive and credential-file operations, escalates repeated boundary violations, cuts faulting links until verified-fixed, and gives risk verdicts on un-auditable execution; runs fully local with zero API cost, plus 6 white-box self-check tools.","cmd":"dsh plugin --profile web add github:Shaky77/weiwen-law-dsh","href":"/p/Shaky77/weiwen-law-dsh/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":8,"added":"2026-08-14","npm":0,"name":"dsh-webui-auth","owner":"Yuuz12","short":"dsh-webui-auth","slug":"Yuuz12/dsh-webui-auth","desc":"WebUI authentication enforced at the HTTP/transport layer: four-layer login gate (resources, plugin bundles, /api, WebSocket), server-side sessions with HttpOnly cookies.","cmd":"dsh plugin --profile web add github:Yuuz12/dsh-webui-auth","href":"/p/Yuuz12/dsh-webui-auth/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":7,"added":"2026-08-24","npm":0,"name":"cue-skills#cue-omni-reader-guard","owner":"sensedeal","short":"cue-skills#cue-omni-reader-guard","slug":"sensedeal/cue-skills--dsh-cue-omni-reader-guard","desc":"Hardening guard for mcp__omni__parse in DeepSeek Harness: a tools/pre-execute listener that denies private/reserved host URLs (SSRF), enforces an allow-list or ask (consent), and is fail-closed when allowedRoots is empty.","cmd":"dsh plugin --profile web add github:sensedeal/cue-skills#path:/dsh/cue-omni-reader-guard","href":"/p/sensedeal/cue-skills--dsh-cue-omni-reader-guard/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":6,"added":"2026-08-23","npm":0,"name":"dsh-approval-mode","owner":"NEVSTOP-LAB","short":"dsh-approval-mode","slug":"NEVSTOP-LAB/dsh-approval-mode","desc":"Adds an approval-mode toggle next to the permission selector: default approval keeps per-call confirmation, bypass approval auto-approves every tool call while staying in Workspace Write.","cmd":"dsh plugin --profile web add github:NEVSTOP-LAB/dsh-approval-mode","href":"/p/NEVSTOP-LAB/dsh-approval-mode/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":6,"added":"2026-08-14","npm":0,"name":"dsh-auto","owner":"simon300000","short":"dsh-auto","slug":"simon300000/dsh-auto","desc":"Adds an Auto Approve permission preset to the Web UI, using a fresh restricted Reviewer Agent to allow or deny each approval request.","cmd":"dsh plugin --profile web add github:simon300000/dsh-auto","href":"/p/simon300000/dsh-auto/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":4,"added":"2026-08-23","npm":0,"name":"dsh-plugin-security-review","owner":"ateen18","short":"dsh-plugin-security-review","slug":"ateen18/dsh-plugin-security-review","desc":"Pre-install static security review and runtime guard for dsh plugins: deobfuscation decoding, supply-chain checks, web one-click review/install/uninstall, and optional runtime tool-call guard.","cmd":"dsh plugin --profile web add github:ateen18/dsh-plugin-security-review","href":"/p/ateen18/dsh-plugin-security-review/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":4,"added":"2026-09-08","npm":0,"name":"dsh-workspace-write-plus","owner":"yzxxy010","short":"dsh-workspace-write-plus","slug":"yzxxy010/dsh-workspace-write-plus","desc":"Adds a workspace-write++ permission that keeps file tools inside the workspace while skipping the Windows process sandbox for wildcard-allowlisted executables such as Git Bash.","cmd":"dsh plugin --profile web add github:yzxxy010/dsh-workspace-write-plus","href":"/p/yzxxy010/dsh-workspace-write-plus/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":3,"added":"2026-08-16","npm":0,"name":"dsh-guardian","owner":"cdxiaodong","short":"dsh-guardian","slug":"cdxiaodong/dsh-guardian","desc":"Agent security guardrail: intercepts and audits every tool call, requiring human confirmation on sensitive operations.","cmd":"dsh plugin --profile web add github:cdxiaodong/dsh-guardian","href":"/p/cdxiaodong/dsh-guardian/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":3,"added":"2026-08-13","npm":0,"name":"sandbox-micro","owner":"omdsh-dev","short":"sandbox-micro","slug":"omdsh-dev/sandbox-micro","desc":"Support for the microsandbox backend.","cmd":"dsh plugin --profile web add github:omdsh-dev/sandbox-micro","href":"/p/omdsh-dev/sandbox-micro/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":2,"added":"2026-08-26","npm":0,"name":"dsh-repeat-stop","owner":"173787247","short":"dsh-repeat-stop","slug":"173787247/dsh-repeat-stop","desc":"Hard-stop consecutive identical tool calls after a configurable streak so the agent cannot spin in place.","cmd":"dsh plugin --profile web add github:173787247/dsh-repeat-stop","href":"/p/173787247/dsh-repeat-stop/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":2,"added":"2026-08-16","npm":0,"name":"dsh-permissions","owner":"940842546","short":"dsh-permissions","slug":"940842546/dsh-permissions","desc":"Claude Code-style permission rules engine: hard/deny/ask/allow tiers with a hard tier above full access, workspace-scoped rules, wildcard path protection, and a visual staged editor; rules persist in settings.yaml.","cmd":"dsh plugin --profile web add github:940842546/dsh-permissions","href":"/p/940842546/dsh-permissions/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":2,"added":"2026-08-23","npm":0,"name":"dsh-guardwall","owner":"iiiweiii","short":"dsh-guardwall","slug":"iiiweiii/dsh-guardwall","desc":"Vets local, npm, and GitHub plugin source before installation, blocks configured high-risk tool calls at runtime, audits output secret patterns, and writes HMAC-chained local audit logs.","cmd":"dsh plugin --profile web add github:iiiweiii/dsh-guardwall","href":"/p/iiiweiii/dsh-guardwall/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":2,"added":"2026-09-20","npm":0,"name":"dsh-action-outbox","owner":"JimChen-g","short":"dsh-action-outbox","slug":"JimChen-g/dsh-action-outbox","desc":"Stages exact DSH tool calls without dispatch, presents complete canonical arguments in a durable Batch Review Inbox, invalidates approvals after edits or restarts, and commits only a matching SHA-256 digest plus single-use nonce through the normal DSH tool pipeline.","cmd":"dsh plugin --profile web add github:JimChen-g/dsh-action-outbox","href":"/p/JimChen-g/dsh-action-outbox/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":2,"added":"2026-08-27","npm":0,"name":"dsh-guardrail","owner":"jypjypjypjyp","short":"dsh-guardrail","slug":"jypjypjypjyp/dsh-guardrail","desc":"String-matches tool-call input arguments, blocks dangerous tool calls (deny) or allows them with an injected warning (warn), and ships a full rules-management panel.","cmd":"dsh plugin --profile web add github:jypjypjypjyp/dsh-guardrail","href":"/p/jypjypjypjyp/dsh-guardrail/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":2,"added":"2026-08-13","npm":0,"name":"sandbox-nono","owner":"omdsh-dev","short":"sandbox-nono","slug":"omdsh-dev/sandbox-nono","desc":"Support for the nono sandbox backend.","cmd":"dsh plugin --profile web add github:omdsh-dev/sandbox-nono","href":"/p/omdsh-dev/sandbox-nono/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":2,"added":"2026-08-17","npm":0,"name":"dsh-cve-audit","owner":"SARTHAK2511","short":"dsh-cve-audit","slug":"SARTHAK2511/dsh-cve-audit","desc":"Live CVE/supply-chain audit for your workspace's own project dependencies (npm/pip/go), backed by OSV.dev, with a `cve_audit` tool plus optional automatic re-scan on lockfile changes.","cmd":"dsh plugin --profile web add github:SARTHAK2511/dsh-cve-audit","href":"/p/SARTHAK2511/dsh-cve-audit/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":2,"added":"2026-09-22","npm":0,"name":"kiss_law-dsh","owner":"Shaky77","short":"KISS_Law-DSH","slug":"Shaky77/KISS_Law-DSH","desc":"English edition of Weiwen's Law (KISS's Law): the first and only domain-agnostic white-box causal adjudication middleware for AI agents. Unlike domain-specific causal-inference tooling (statistics/economics/ML) or evidence-gated agent firewalls, it adjudicates *every* tool call along a deterministic structural causal chain (R->S->D->H->M) before execution - across any domain, with no training or per-domain tuning. It blocks destructive and credential-file operations, escalates repeated boundary violations, cuts faulting links until verified-fixed, and gives risk verdicts on un-auditable execution; runs fully local with zero API cost.","cmd":"dsh plugin --profile web add github:Shaky77/KISS_Law-DSH","href":"/p/Shaky77/KISS_Law-DSH/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":2,"added":"2026-08-25","npm":0,"name":"dsh-full-with-approval","owner":"zjuhbh","short":"dsh-full-with-approval","slug":"zjuhbh/dsh-full-with-approval","desc":"Fourth permission preset for dsh: unconfined, GPU-capable sessions (danger-full-access) with per-operation user approval for writes outside the workspace or to protected paths (.git/**, .env*); implemented purely as a bundle over the official tools/pre-execute ask hook, no core edits.","cmd":"dsh plugin --profile web add github:zjuhbh/dsh-full-with-approval","href":"/p/zjuhbh/dsh-full-with-approval/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-30","npm":0,"name":"dsh-tool-budget","owner":"173787247","short":"dsh-tool-budget","slug":"173787247/dsh-tool-budget","desc":"Hard-stops further tool calls after a configurable per-session budget is reached.","cmd":"dsh plugin --profile web add github:173787247/dsh-tool-budget","href":"/p/173787247/dsh-tool-budget/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-19","npm":0,"name":"dsh-perm-guard","owner":"a903067276-rgb","short":"dsh-perm-guard","slug":"a903067276-rgb/dsh-perm-guard","desc":"Auto-approval permission guard: a middle tier between workspace-write and danger-full-access — auto-allows safe operations inside trust directories, always asks a human for destructive ones, with 11 per-category switches and an audit trail.","cmd":"dsh plugin --profile web add github:a903067276-rgb/dsh-perm-guard","href":"/p/a903067276-rgb/dsh-perm-guard/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-09-19","npm":0,"name":"dsh-auto-review","owner":"accpowered","short":"dsh-auto-review","slug":"accpowered/dsh-auto-review","desc":"LLM approval answerer for sandbox escalations beyond workspace-write: a deterministic regex filter first, then a clean-context reviewer model; humans are asked only when it is unsure. Requires the bundled core patches.","cmd":"dsh plugin --profile web add github:accpowered/dsh-auto-review","href":"/p/accpowered/dsh-auto-review/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-09-19","npm":0,"name":"dsh-credential-manager","owner":"accpowered","short":"dsh-credential-manager","slug":"accpowered/dsh-credential-manager","desc":"Named user credentials the model uses by reference: values are entered on a Settings → Credentials page and injected into each shell execution as DSH_CM_* variables instead of being printed into the transcript, with credential_read as the documented last resort.","cmd":"dsh plugin --profile web add github:accpowered/dsh-credential-manager","href":"/p/accpowered/dsh-credential-manager/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-27","npm":0,"name":"dsh-llm-approve-for-me","owner":"alaxrpg","short":"dsh-llm-approve-for-me","slug":"alaxrpg/dsh-llm-approve-for-me","desc":"Uses an isolated LLM review to approve or reject DSH sandbox permission requests.","cmd":"dsh plugin --profile web add github:alaxrpg/dsh-llm-approve-for-me","href":"/p/alaxrpg/dsh-llm-approve-for-me/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-18","npm":0,"name":"dsh-auto-reviewer","owner":"AntaresCorn","short":"dsh-auto-reviewer","slug":"AntaresCorn/dsh-auto-reviewer","desc":"Codex-style auto-review permission mode: adds an auto-review preset that auto-approves safe sandbox escalations, asks on risky or ambiguous ones, and rejects critical unconfirmed operations.","cmd":"dsh plugin --profile web add github:AntaresCorn/dsh-auto-reviewer","href":"/p/AntaresCorn/dsh-auto-reviewer/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-14","npm":0,"name":"dsh-turn-approval","owner":"arrow949","short":"dsh-turn-approval","slug":"arrow949/dsh-turn-approval","desc":"Turn-scoped “Allow for this task” approvals: automatically allow matching `danger-full-access` escalations only for the current task, then expire.","cmd":"dsh plugin --profile web add github:arrow949/dsh-turn-approval","href":"/p/arrow949/dsh-turn-approval/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-15","npm":0,"name":"dsh-plugin-sentinel","owner":"BotonJ","short":"dsh-plugin-sentinel","slug":"BotonJ/dsh-plugin-sentinel","desc":"Static pre-install security auditor for plugin bundles: lifecycle scripts, dynamic execution, credential-exfiltration combos, and patch-layer hazards, with zero dependencies and in-memory tar parsing.","cmd":"dsh plugin --profile web add github:BotonJ/dsh-plugin-sentinel","href":"/p/BotonJ/dsh-plugin-sentinel/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-14","npm":0,"name":"dsh-mcpguard","owner":"ChenLaoshiYF","short":"dsh-mcpguard","slug":"ChenLaoshiYF/dsh-mcpguard","desc":"Scans skills and MCP configs for prompt injection, homoglyphs, hidden Unicode, dangerous shell, and credential leaks.","cmd":"dsh plugin --profile web add github:ChenLaoshiYF/dsh-mcpguard","href":"/p/ChenLaoshiYF/dsh-mcpguard/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-17","npm":0,"name":"dsh-plugins#dsh-approve-for-me","owner":"DamonKoy","short":"dsh-plugins#dsh-approve-for-me","slug":"DamonKoy/dsh-plugins--packages-dsh-approve-for-me","desc":"Automated approval review: auto-approve read-only tools, auto-deny dangerous commands, fail-closed policy engine.","cmd":"dsh plugin --profile web add github:DamonKoy/dsh-plugins#path:/packages/dsh-approve-for-me","href":"/p/DamonKoy/dsh-plugins--packages-dsh-approve-for-me/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-17","npm":0,"name":"dsh-plugins#dsh-secret-redactor","owner":"DamonKoy","short":"dsh-plugins#dsh-secret-redactor","slug":"DamonKoy/dsh-plugins--packages-dsh-secret-redactor","desc":"Automatic secret redaction in tool results: masks API keys, tokens, JWTs, private keys and configured secrets before the model sees them.","cmd":"dsh plugin --profile web add github:DamonKoy/dsh-plugins#path:/packages/dsh-secret-redactor","href":"/p/DamonKoy/dsh-plugins--packages-dsh-secret-redactor/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-09-21","npm":0,"name":"dsh-allow","owner":"DWJZ","short":"dsh-allow","slug":"DWJZ/dsh-allow","desc":"Filesystem permissions for shell calls, granted per path and capability rather than per command name. The command line is parsed for the read, write, create, delete and execute effects it needs, a capability it lacks raises the approval card instead of a flat refusal, and the same rules are compiled into the macOS Seatbelt profile the process, its children and the code its arguments never showed all run under. An Approvals tab in the conversation reads the audit log back and shows which rule, automatic reviewer or person answered each call.","cmd":"dsh plugin --profile web add github:DWJZ/dsh-allow","href":"/p/DWJZ/dsh-allow/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-09-13","npm":0,"name":"dsh-dsml-artifact-guard","owner":"GooDAnDReaDY","short":"dsh-dsml-artifact-guard","slug":"GooDAnDReaDY/dsh-dsml-artifact-guard","desc":"Sanitizes leaked DeepSeek DSML closing tags from model text streams.","cmd":"dsh plugin --profile web add github:GooDAnDReaDY/dsh-dsml-artifact-guard","href":"/p/GooDAnDReaDY/dsh-dsml-artifact-guard/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-16","npm":0,"name":"safety-net","owner":"JohnXu22786","short":"safety-net","slug":"JohnXu22786/safety-net","desc":"Destructive-command interception gate for dsh: parses shell semantics, judges risk against 41 built-in rules, and holds irreversible rm -rf, git reset --hard, and git push --force style commands at a confirmation gate.","cmd":"dsh plugin --profile web add github:JohnXu22786/safety-net","href":"/p/JohnXu22786/safety-net/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-16","npm":0,"name":"secret-guard","owner":"JohnXu22786","short":"secret-guard","slug":"JohnXu22786/secret-guard","desc":"Blocks agents from reading or writing sensitive files (.env, credentials, key material), masks leaked secret-shaped values in tool results, keeps an audit journal, and exposes safe sg_* inspection tools that never print raw values.","cmd":"dsh plugin --profile web add github:JohnXu22786/secret-guard","href":"/p/JohnXu22786/secret-guard/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-19","npm":0,"name":"faultseed#dsh","owner":"JW53222","short":"faultseed#dsh","slug":"JW53222/faultseed--adapters-dsh","desc":"Honesty guardrails on the tool pipeline: blocks a coding agent from weakening tests, swallowing errors, stubbing type checks, or deleting tests through the shell — nine deterministic hooks, each backed by a planted-failure test proving the guard can fail.","cmd":"dsh plugin --profile web add github:JW53222/faultseed#path:/adapters/dsh","href":"/p/JW53222/faultseed--adapters-dsh/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-14","npm":0,"name":"dsh-fleet-audit","owner":"LeslieWylie","short":"dsh-fleet-audit","slug":"LeslieWylie/dsh-fleet-audit","desc":"Read-only agent-fleet credential hygiene audit: credential-file permissions, embedded credentials in git remotes (masked in output), and provider token literal counts; zero-dependency and deterministic.","cmd":"dsh plugin --profile web add github:LeslieWylie/dsh-fleet-audit","href":"/p/LeslieWylie/dsh-fleet-audit/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-27","npm":0,"name":"dsh-hawkeye-scan#npm","owner":"liuqingman","short":"dsh-hawkeye-scan#npm","slug":"liuqingman/dsh-hawkeye-scan--npm","desc":"AI-driven source-code security scanning workbench: 5 model tools (start/finding/status/report/list) plus a /hawkeye web UI and JSON/Markdown/HTML vulnerability reports; zero-dependency Cordis plugin, installable as agent preset or npm package.","cmd":"dsh plugin --profile web add github:liuqingman/dsh-hawkeye-scan#path:/npm","href":"/p/liuqingman/dsh-hawkeye-scan--npm/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-14","npm":0,"name":"dsh-guardian","owner":"lonelymoon87","short":"dsh-guardian","slug":"lonelymoon87/dsh-guardian","desc":"Adds dangerous-operation policy checks, output redaction, and a security-review workflow.","cmd":"dsh plugin --profile web add github:lonelymoon87/dsh-guardian","href":"/p/lonelymoon87/dsh-guardian/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-09-22","npm":0,"name":"dsh-approval-explain","owner":"Martlet-Tech","short":"dsh-approval-explain","slug":"Martlet-Tech/dsh-approval-explain","desc":"Adds an Explain button to the approval card: one model call returns exactly three lines reading the pending operation, covering what it does, which files or system state it reads, writes, modifies or executes, and a risky/attention/safe verdict with a one-sentence justification. It also renders the detail area for `write` and `edit` calls, which the shipped renderer leaves blank because it only reads a `command` field.","cmd":"dsh plugin --profile web add github:Martlet-Tech/dsh-approval-explain","href":"/p/Martlet-Tech/dsh-approval-explain/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-28","npm":0,"name":"dsh-plugin-trustlens","owner":"Mengshang-spec","short":"dsh-plugin-trustlens","slug":"Mengshang-spec/dsh-plugin-trustlens","desc":"Read-only DSH plugin auditor with static scanning, current-session model review, and confirmation gates.","cmd":"dsh plugin --profile web add github:Mengshang-spec/dsh-plugin-trustlens","href":"/p/Mengshang-spec/dsh-plugin-trustlens/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-13","npm":0,"name":"sandbox-mxc","owner":"omdsh-dev","short":"sandbox-mxc","slug":"omdsh-dev/sandbox-mxc","desc":"Microsoft cross-platform sandbox support.","cmd":"dsh plugin --profile web add github:omdsh-dev/sandbox-mxc","href":"/p/omdsh-dev/sandbox-mxc/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-31","npm":0,"name":"dsh-prompt-antivirus","owner":"QinpanWan","short":"dsh-prompt-antivirus","slug":"QinpanWan/dsh-prompt-antivirus","desc":"Global prompt-injection / context-virus defense for DeepSeek Harness: scans tool arguments, tool results, pre-model messages and the outbound stream; quarantine/block/monitor modes, canary trap, and an evolvable on-disk signature library with learn/import/export.","cmd":"dsh plugin --profile web add github:QinpanWan/dsh-prompt-antivirus","href":"/p/QinpanWan/dsh-prompt-antivirus/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-15","npm":0,"name":"dsh-egress-guard","owner":"tancheng33","short":"dsh-egress-guard","slug":"tancheng33/dsh-egress-guard","desc":"Runtime security gate on the tool pipeline: denies calls naming hosts outside an egress allowlist, redacts credentials from results at the canonical value rather than only the rendered content, and appends every decision to a JSONL audit log; ships in monitor-only mode.","cmd":"dsh plugin --profile web add github:tancheng33/dsh-egress-guard","href":"/p/tancheng33/dsh-egress-guard/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-24","npm":0,"name":"dsh-plugin-guard","owner":"taxueseek","short":"dsh-plugin-guard","slug":"taxueseek/dsh-plugin-guard","desc":"Static-only plugin gate and clinic for DSH: audit before install, hash-and-capability lock after install, local fingerprint peer search over GitHub topic:dsh-plugin, and mechanical detox. Never executes the target plugin.","cmd":"dsh plugin --profile web add github:taxueseek/dsh-plugin-guard","href":"/p/taxueseek/dsh-plugin-guard/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-27","npm":0,"name":"dsh-feishu-channel","owner":"WyattJHayes","short":"dsh-feishu-channel","slug":"WyattJHayes/dsh-feishu-channel","desc":"Security-focused Feishu (Lark) channel for DeepSeek Harness: allowlisted remote-agent access with workspace-scoped paths, symlink checks, risk-based approvals, session isolation, redacted logs, and bounded message queues.","cmd":"dsh plugin --profile web add github:WyattJHayes/dsh-feishu-channel","href":"/p/WyattJHayes/dsh-feishu-channel/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-27","npm":0,"name":"dsh-full-access-switch","owner":"xtd1145","short":"dsh-full-access-switch","slug":"xtd1145/dsh-full-access-switch","desc":"One-time Full access switch for DeepSeek Harness: new sessions (workspaces and conversations) start with danger-full-access and skip the per-session Full access confirmation; installable as a dsh bundle or via patch scripts.","cmd":"dsh plugin --profile web add github:xtd1145/dsh-full-access-switch","href":"/p/xtd1145/dsh-full-access-switch/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-09-21","npm":0,"name":"dsh-file-shield","owner":"Yazzyk","short":"dsh-file-shield","slug":"Yazzyk/dsh-file-shield","desc":"Blocks an agent from reading, searching, writing, or editing chosen files and directories, keeping their contents out of the conversation — including sensitive-word files whose text can make later provider requests fail with a 400. Rules are picked from a file/directory browser on the plugin page.","cmd":"dsh plugin --profile web add github:Yazzyk/dsh-file-shield","href":"/p/Yazzyk/dsh-file-shield/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":1,"added":"2026-08-14","npm":0,"name":"noatmark-dsh-plugin","owner":"ylwl1997","short":"noatmark-dsh-plugin","slug":"ylwl1997/noatmark-dsh-plugin","desc":"Text hygiene as a dsh plugin: sanitize untrusted text, scan invisible characters, clean LLM formatting, and escape CSV formula injection.","cmd":"dsh plugin --profile web add github:ylwl1997/noatmark-dsh-plugin","href":"/p/ylwl1997/noatmark-dsh-plugin/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-08-17","npm":0,"name":"dsh-gov","owner":"863683348","short":"dsh-gov","slug":"863683348/dsh-gov","desc":"Agent governance suite: policy-based tool gating (allow/deny/ask with wildcards and priorities), a structured JSONL audit trail, and per-agent token quotas against the host token meter, with state under $DSH_HOME/gov.","cmd":"dsh plugin --profile web add github:863683348/dsh-gov","href":"/p/863683348/dsh-gov/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-09-11","npm":0,"name":"dsh-workspace-tools","owner":"AHIOSUZ","short":"dsh-workspace-tools","slug":"AHIOSUZ/dsh-workspace-tools","desc":"Applies per-workspace default Agent and permission presets to new root sessions automatically (Settings - Workspace defaults), using only official extension points.","cmd":"dsh plugin --profile web add github:AHIOSUZ/dsh-workspace-tools","href":"/p/AHIOSUZ/dsh-workspace-tools/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-09-19","npm":0,"name":"dsh-almazom-approve-escalate","owner":"almazom","short":"dsh-almazom-approve-escalate","slug":"almazom/dsh-almazom-approve-escalate","desc":"One-click Approve & escalate on the approval card: answers the pending request and switches the live session to a permission preset.","cmd":"dsh plugin --profile web add github:almazom/dsh-almazom-approve-escalate","href":"/p/almazom/dsh-almazom-approve-escalate/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-09-18","npm":0,"name":"dsh-privacy-guard","owner":"amwangfan","short":"dsh-privacy-guard","slug":"amwangfan/dsh-privacy-guard","desc":"Control panel for a local credential-redaction gateway in DeepSeek Harness: gateway and model health, audit metrics, a dry-run leak tester, an exemption whitelist, encrypted key management, credential-protected model entries and deployment controls.","cmd":"dsh plugin --profile web add github:amwangfan/dsh-privacy-guard","href":"/p/amwangfan/dsh-privacy-guard/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-09-18","npm":0,"name":"dsh-sandbox-arg-guard","owner":"apex-mochen","short":"dsh-sandbox-arg-guard","slug":"apex-mochen/dsh-sandbox-arg-guard","desc":"Keeps a redundant sandbox-escalation argument from failing a tool call. Escalating tools (pwsh, bash, write, edit) advertise the full sandbox_permissions enum, but DSH only accepts a level strictly wider than the one already in effect — a check its own source calls 'deliberately not a schema constraint'. A model that reflexively passes the argument therefore picks the level it is already at and the call dies before running with 'sandbox escalation to \"workspace-write\" is not strictly wider than this call's current \"workspace-write\" mode', costing some models a whole turn of retries. This plugin registers one tools/execute waterfall listener and, only on that documented rejection and only when the arguments really carried an escalation field, re-issues the identical call once without it. Safe by DSH's own documentation: the rejection precedes any execution ('nothing has run'), and the corrected call cannot match again, so the retry is loop-free. Reproduced and verified end to end — before: isError true, the command never ran; after: the command's real output, isError false, one tool/call and one tool/result. Zero dependencies.","cmd":"dsh plugin --profile web add github:apex-mochen/dsh-sandbox-arg-guard","href":"/p/apex-mochen/dsh-sandbox-arg-guard/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-08-30","npm":0,"name":"dsh-plugin-guard","owner":"DingZhiQi5596","short":"dsh-plugin-guard","slug":"DingZhiQi5596/dsh-plugin-guard","desc":"DSH Desktop plugin safety guard: self-repairs plugin load crashes and runs 8 core safety checks (2 optional: deep-config & smoke), prompting you when a plugin changes. Non-commercial source-available.","cmd":"dsh plugin --profile web add github:DingZhiQi5596/dsh-plugin-guard","href":"/p/DingZhiQi5596/dsh-plugin-guard/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-09-22","npm":0,"name":"dsh-approval-gate","owner":"IamNewHands","short":"dsh-approval-gate","slug":"IamNewHands/dsh-approval-gate","desc":"Maintained fork of dsh-approval-gate. A neutral operation whose confirmation count has reached the threshold auto-approves when the judge is unavailable, instead of prompting a human again; approver-facing explanations are generated in Chinese from the real sandbox mode, command and paths. Also carries deterministic hard-deny for credential exfiltration and system-path destruction, judge-input redaction, a judge model candidate chain, fingerprint-scoped allow rules, and an approval view with unified diff and one-click revert.","cmd":"dsh plugin --profile web add github:IamNewHands/dsh-approval-gate","href":"/p/IamNewHands/dsh-approval-gate/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-09-09","npm":0,"name":"dsh-risk-gate","owner":"leetom314","short":"dsh-risk-gate","slug":"leetom314/dsh-risk-gate","desc":"Semantic risk grading and progressive authorization: classifies tool calls into safe/risky/redline, asks before irreversible actions, auto-allows only approved-and-succeeded signatures.","cmd":"dsh plugin --profile web add github:leetom314/dsh-risk-gate","href":"/p/leetom314/dsh-risk-gate/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-08-29","npm":0,"name":"dsh-edit-guardian","owner":"LWLAymh","short":"dsh-edit-guardian","slug":"LWLAymh/dsh-edit-guardian","desc":"File-change diff bar with keep/undo summary, plus dangerous-command approval and red highlighting for bash/pwsh.","cmd":"dsh plugin --profile web add github:LWLAymh/dsh-edit-guardian","href":"/p/LWLAymh/dsh-edit-guardian/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-09-03","npm":0,"name":"dsh-safe-delete","owner":"NattoCB","short":"dsh-safe-delete","slug":"NattoCB/dsh-safe-delete","desc":"Tools guard that moves agent-issued `rm` targets to the macOS Trash instead of deleting, with a shell-aware lexer covering compound and disguised commands; a switch in Settings → General turns it off.","cmd":"dsh plugin --profile web add github:NattoCB/dsh-safe-delete","href":"/p/NattoCB/dsh-safe-delete/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-09-24","npm":0,"name":"dsh-keychain-credentials","owner":"nengong-ai","short":"dsh-keychain-credentials","slug":"nengong-ai/dsh-keychain-credentials","desc":"Pure JavaScript macOS Keychain credentials provider for DeepSeek Harness, replacing plaintext .credentials.yaml storage and fully supporting both refs and records without native builds, signing, or Xcode.","cmd":"dsh plugin --profile web add github:nengong-ai/dsh-keychain-credentials","href":"/p/nengong-ai/dsh-keychain-credentials/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-09-05","npm":0,"name":"dsh-security-guard","owner":"ruanhaodong-tt","short":"dsh-security-guard","slug":"ruanhaodong-tt/dsh-security-guard","desc":"Runtime security guard for DSH: loader import confinement, HTTP Host header validation, and source patch for VM sandbox escapes (4 CVEs). AI-assisted.","cmd":"dsh plugin --profile web add github:ruanhaodong-tt/dsh-security-guard","href":"/p/ruanhaodong-tt/dsh-security-guard/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-08-18","npm":0,"name":"dsh-taintguard","owner":"sashankh","short":"dsh-taintguard","slug":"sashankh/dsh-taintguard","desc":"Taints the agent when tool results carry untrusted content, gates the privileged calls that follow, and refuses credentials passed to network-capable tools in every mode.","cmd":"dsh plugin --profile web add github:sashankh/dsh-taintguard","href":"/p/sashankh/dsh-taintguard/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-09-18","npm":0,"name":"dsh-auto-pass","owner":"sujingkpo","short":"dsh-auto-pass","slug":"sujingkpo/dsh-auto-pass","desc":"A continuation of simon300000/dsh-auto: the Auto Approve permission preset for the DSH Web UI reviews each approval with one single-shot model call instead of a reviewer subagent, auto-approves only the actions that pass and hands the rest to human approval, and remembers confirmed decisions as project- and global-scope allow/deny lists, with an approval timeline in the right sidebar.","cmd":"dsh plugin --profile web add github:sujingkpo/dsh-auto-pass","href":"/p/sujingkpo/dsh-auto-pass/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-08-16","npm":0,"name":"dsh-code-runtime-container","owner":"tancheng33","short":"dsh-code-runtime-container","slug":"tancheng33/dsh-code-runtime-container","desc":"Container-isolated backend for the `ctx.codeRuntime` seam: each Code Mode program runs in a fresh container with no network, a read-only rootfs, dropped capabilities, and kernel-enforced memory, CPU and pid ceilings.","cmd":"dsh plugin --profile web add github:tancheng33/dsh-code-runtime-container","href":"/p/tancheng33/dsh-code-runtime-container/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-08-16","npm":0,"name":"dsh-credentials-vault","owner":"tancheng33","short":"dsh-credentials-vault","slug":"tancheng33/dsh-credentials-vault","desc":"HashiCorp Vault backend for the credential seam: KV v2/v1, AppRole machine auth, per-operation reads so rotation needs no restart, and compare-and-swap writes.","cmd":"dsh plugin --profile web add github:tancheng33/dsh-credentials-vault","href":"/p/tancheng33/dsh-credentials-vault/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-08-21","npm":0,"name":"dsh-route-fence-linter","owner":"Vladimir-Kryshchenko","short":"dsh-route-fence-linter","slug":"Vladimir-Kryshchenko/dsh-route-fence-linter","desc":"Audits every plugin HTTP route in a profile for a browser-trust fence: plugin routes win the web server's longest-prefix match ahead of the /api gateway, so they never see its trust check and must pin the Host to loopback themselves. Grades PASS/WARN/FAIL per route and fails a fence that compares Origin to Host without pinning it (bypassable by DNS rebinding). Ships as a CLI for CI and a route_fence_scan tool.","cmd":"dsh plugin --profile web add github:Vladimir-Kryshchenko/dsh-route-fence-linter","href":"/p/Vladimir-Kryshchenko/dsh-route-fence-linter/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-09-18","npm":0,"name":"dsh-jumpserver","owner":"we39","short":"dsh-jumpserver","slug":"we39/dsh-jumpserver","desc":"Query and manage JumpServer through conversation: assets, users, accounts, permissions, sessions, command audit logs, command filters, and RBAC roles, authenticated with an AccessKeyID/AccessKeySecret pair (HTTP Signature).","cmd":"dsh plugin --profile web add github:we39/dsh-jumpserver","href":"/p/we39/dsh-jumpserver/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-09-07","npm":0,"name":"dsh-security-guard","owner":"weisofns","short":"dsh-security-guard","slug":"weisofns/dsh-security-guard","desc":"DSH plugin security guard: 28-rule static scanner, risk scoring, whitelist/blacklist policy, local web dashboard and in-DSH risk popups.","cmd":"dsh plugin --profile web add github:weisofns/dsh-security-guard","href":"/p/weisofns/dsh-security-guard/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-09-18","npm":0,"name":"dsh-fs-allowlist","owner":"wzn16","short":"dsh-fs-allowlist","slug":"wzn16/dsh-fs-allowlist","desc":"Approval-free writes into whitelisted directories — wraps the filesystem fence for write/edit tools and auto-answers bash sandbox escalations that touch whitelisted paths, with a settings GUI.","cmd":"dsh plugin --profile web add github:wzn16/dsh-fs-allowlist","href":"/p/wzn16/dsh-fs-allowlist/"},{"cat":"security","tag":"Security & Permissions","dl":null,"stars":0,"added":"2026-09-09","npm":0,"name":"dsh-permission-matrix","owner":"zhang8019","short":"dsh-permission-matrix","slug":"zhang8019/dsh-permission-matrix","desc":"Turns DSH permissions into 9 selectable presets (3 sandbox modes x 4 approval tiers), with rule plus LLM risk classification across four risk levels, password-gated approval for high-risk operations, and a JSONL audit log.","cmd":"dsh plugin --profile web add github:zhang8019/dsh-permission-matrix","href":"/p/zhang8019/dsh-permission-matrix/"}]}