{"install":"安装","market":"通过 dsh-market · 推荐","marketHint":"复制市场安装命令","cli":"通过命令行","copy":"复制安装命令","copyLabel":"复制安装命令","dlTitle":"下载量（近 30 天）","items":[{"cat":"security","tag":"安全与权限","dl":11498,"stars":11,"added":"2026-09-03","npm":1,"name":"dsh-vault","owner":"Ox0400","short":"dsh-vault","slug":"Ox0400/dsh-vault","desc":"Harness 的本地加密凭据保险库：Web 设置页与 vault_* 工具，可存取与复制密码、API 密钥、TOTP 与银行卡信息，支持健康审计、到期轮换、导入导出以及只读/询问访问模式。","cmd":"dsh plugin --profile web add dsh-vault","href":"/zh/p/Ox0400/dsh-vault/"},{"cat":"security","tag":"安全与权限","dl":7337,"stars":115,"added":"2026-08-15","npm":1,"name":"dsh-permission-rules","owner":"PerryLink","short":"dsh-permission-rules","slug":"PerryLink/dsh-permission-rules","desc":"Claude Code 风格的声明式权限规则：按序 allow/deny/ask 的 YAML 规则，在 tools/pre-execute 瀑布上匹配工具名、参数、工作区路径与 agent 身份，带完整会话日志审计、干跑模式与热重载。","cmd":"dsh plugin --profile web add dsh-permission-rules","href":"/zh/p/PerryLink/dsh-permission-rules/"},{"cat":"security","tag":"安全与权限","dl":6023,"stars":11,"added":"2026-08-28","npm":1,"name":"dsh-auto-approval-llm","owner":"cuddly-guacamole","short":"dsh-auto-approval-llm","slug":"cuddly-guacamole/dsh-auto-approval-llm","desc":"为 DSH Auto 权限档提供 LLM 辅助自动审批：静态规则、LLM 复审、风险分档、人工倒计时兜底、熔断与文件级审计。","cmd":"dsh plugin --profile web add @quill507/dsh-auto-approval-llm","href":"/zh/p/cuddly-guacamole/dsh-auto-approval-llm/"},{"cat":"security","tag":"安全与权限","dl":5894,"stars":219,"added":"2026-08-15","npm":1,"name":"dsh-auto-review","owner":"PerryLink","short":"dsh-auto-review","slug":"PerryLink/dsh-auto-review","desc":"审批链上的第二模型自动审查：只读审查子代理返回带理由的 allow/deny 结构化裁决，默认 fail-closed。","cmd":"dsh plugin --profile web add dsh-auto-review","href":"/zh/p/PerryLink/dsh-auto-review/"},{"cat":"security","tag":"安全与权限","dl":5383,"stars":83,"added":"2026-08-17","npm":1,"name":"dsh-approval-gate","owner":"moon09300731","short":"dsh-approval-gate","slug":"moon09300731/dsh-approval-gate","desc":"DeepSeek Harness 自动审批门控：Flash 预判写入/命令是否不可回补，安全操作自动批准、危险操作转人工（fail-safe）。另含文件改动对比（unified diff）与一键撤销、按会话隔离的快照管理（v0.5.1：通过工具调用参数回溯精确保存快照，覆盖人工审批场景）。","cmd":"dsh plugin --profile web add dsh-approval-gate","href":"/zh/p/moon09300731/dsh-approval-gate/"},{"cat":"security","tag":"安全与权限","dl":5229,"stars":66,"added":"2026-08-14","npm":1,"name":"dsh-passwords","owner":"slywalker2006","short":"dsh-passwords","slug":"slywalker2006/dsh-passwords","desc":"让 DeepSeek Harness 变成服务器级多租户平台：远程访问 + 自动 HTTPS、子用户权限与配额、沙盒强制、加密认证与审计日志。","cmd":"dsh plugin --profile web add dsh-passwords","href":"/zh/p/slywalker2006/dsh-passwords/"},{"cat":"security","tag":"安全与权限","dl":5174,"stars":1,"added":"2026-09-10","npm":1,"name":"dsh-perm-gate","owner":"drscrewdriver","short":"dsh-perm-gate","slug":"drscrewdriver/dsh-perm-gate","desc":"P0–P4 确定性优先权限门控，含 Permissive 档位、学习沉淀与审批历史 UI；凭据/受保护路径硬拒绝，内部只读工具自动放行。","cmd":"dsh plugin --profile web add dsh-perm-gate","href":"/zh/p/drscrewdriver/dsh-perm-gate/"},{"cat":"security","tag":"安全与权限","dl":4112,"stars":15,"added":"2026-08-16","npm":1,"name":"dsh-auth-gate","owner":"TecFancy","short":"dsh-auth-gate","slug":"TecFancy/dsh-auth-gate","desc":"DSH 网页端登录门插件：账号口令或共享令牌认证、会话 cookie、登录限速，附用户管理 CLI（0.4.1 起声明 dsh.bundle manifest，`dsh plugin add` 一键挂载）。","cmd":"dsh plugin --profile web add dsh-auth-gate","href":"/zh/p/TecFancy/dsh-auth-gate/"},{"cat":"security","tag":"安全与权限","dl":4071,"stars":1,"added":"2026-09-06","npm":1,"name":"user-management","owner":"weibaohui","short":"user-management","slug":"weibaohui/user-management","desc":"用户管理：给 dsh web 加登录门禁，未登录访问弹登录/注册页，首个注册者自动成为管理员；管理员可管理用户/角色，带登录与访问审计。","cmd":"dsh plugin --profile web add @weibaohui/user-management","href":"/zh/p/weibaohui/user-management/"},{"cat":"security","tag":"安全与权限","dl":3896,"stars":1,"added":"2026-09-13","npm":1,"name":"dsh-time-machine","owner":"GooDAnDReaDY","short":"dsh-time-machine","slug":"GooDAnDReaDY/dsh-time-machine","desc":"为 DeepSeek Harness 提供智能检查点、工作区安全防护和即时回滚。","cmd":"dsh plugin --profile web add @goodandready/dsh-time-machine","href":"/zh/p/GooDAnDReaDY/dsh-time-machine/"},{"cat":"security","tag":"安全与权限","dl":3727,"stars":0,"added":"2026-09-04","npm":1,"name":"dsh-shadow-auditor","owner":"GooDAnDReaDY","short":"dsh-shadow-auditor","slug":"GooDAnDReaDY/dsh-shadow-auditor","desc":"DeepSeek Harness 的后台安全审计器：扫描 Agent 输出中的秘密泄漏，在执行前检查命令安全性，并将发现记录到持久化审计日志中。","cmd":"dsh plugin --profile web add @goodandready/dsh-shadow-auditor","href":"/zh/p/GooDAnDReaDY/dsh-shadow-auditor/"},{"cat":"security","tag":"安全与权限","dl":3704,"stars":20,"added":"2026-08-23","npm":1,"name":"dsh-defend","owner":"PerryLink","short":"dsh-defend","slug":"PerryLink/dsh-defend","desc":"在 agent/pre-step、tools/pre-execute、tools/post-execute 三个接缝检测提示词注入、越狱与密钥泄露，按 allow/ask/block 分层拦截，附脱敏 defend/detection 审计事件、defend_report 工具与危险删除命令门禁。","cmd":"dsh plugin --profile web add dsh-defend","href":"/zh/p/PerryLink/dsh-defend/"},{"cat":"security","tag":"安全与权限","dl":3605,"stars":164,"added":"2026-09-15","npm":1,"name":"dsh-auto-mode","owner":"NanmiCoder","short":"dsh-auto-mode","slug":"NanmiCoder/dsh-auto-mode","desc":"在 Workspace Write 与 Full access 之间增加 Auto 权限档：日常操作留在官方 workspace-write 沙箱内，由当前会话模型复核升权与破坏性调用，精确的越界访问按次放行一次，意图不明时询问，命中关键路径则拒绝。","cmd":"dsh plugin --profile web add @nanmicoder/dsh-auto-mode","href":"/zh/p/NanmiCoder/dsh-auto-mode/"},{"cat":"security","tag":"安全与权限","dl":3474,"stars":64,"added":"2026-09-18","npm":1,"name":"dsh-redteam-mode#packages/redteam-bundle","owner":"Jueze-2019","short":"dsh-redteam-mode#packages/redteam-bundle","slug":"Jueze-2019/dsh-redteam-mode--packages-redteam-bundle","desc":"红队作战模式：只发一个靶标单位名称，主会话指挥五个执行角色（信息收集/资产梳理/漏洞发现/漏洞利用/内网渗透）推进演练，并发上限 3 个，开工前先做技能与资源预检、缺 key 或 VPS 一次性向用户要齐（内置首次使用引导技能）；得分严格对齐《突破入侵类得分规则（合并版）》的 8 类 25 项，上限、权限取高只计一次、同一服务只算一次全由服务端判定，自建账号不计分；所有发现落入本机 SQLite 事实库并带发现时间，常驻右侧控制台 12 个页签提供资产测绘（含发现时间线）、智能体名额、会话隧道、五阶段攻击链、得分目标、逐条写明「怎么拿到的」的可复现报告（动作、实际命令、账号密码来源、隧道搭建命令）、按归类组织的跨靶标 POC/EXP 知识库与带可用性判定的技能库；随包 23 个原生技能、53 个 redteam_* 工具与一键自更新。","cmd":"dsh plugin --profile web add dsh-redteam-mode","href":"/zh/p/Jueze-2019/dsh-redteam-mode--packages-redteam-bundle/"},{"cat":"security","tag":"安全与权限","dl":3325,"stars":0,"added":"2026-09-13","npm":1,"name":"dsh-agent-loop-guard","owner":"GooDAnDReaDY","short":"dsh-agent-loop-guard","slug":"GooDAnDReaDY/dsh-agent-loop-guard","desc":"为 DeepSeek Harness 提供故障关闭式运行时工具调用循环防护。","cmd":"dsh plugin --profile web add @goodandready/dsh-agent-loop-guard","href":"/zh/p/GooDAnDReaDY/dsh-agent-loop-guard/"},{"cat":"security","tag":"安全与权限","dl":3258,"stars":0,"added":"2026-08-29","npm":1,"name":"dsh-completion-guard","owner":"GreenLv","short":"dsh-completion-guard","slug":"GreenLv/dsh-completion-guard","desc":"避免 DSH Agent 在长任务中忘记你的要求：它会把重要条件和完成依据保存在本机，在上下文压缩或恢复会话后重新带回，防止漏掉关键限制，或只做完一部分就说整个任务已经完成。","cmd":"dsh plugin --profile web add dsh-completion-guard","href":"/zh/p/GreenLv/dsh-completion-guard/"},{"cat":"security","tag":"安全与权限","dl":2878,"stars":6,"added":"2026-08-27","npm":1,"name":"dsh-automode","owner":"log-li","short":"dsh-automode","slug":"log-li/dsh-automode","desc":"为 DeepSeek Harness 提供 Claude Code 式自动审批：确定性 deny/allow 规则 + 两阶段 allow/reject 分类器，内置熔断器与拒绝引导。","cmd":"dsh plugin --profile web add @log.li/dsh-automode","href":"/zh/p/log-li/dsh-automode/"},{"cat":"security","tag":"安全与权限","dl":2799,"stars":12,"added":"2026-08-29","npm":1,"name":"dsh-mask","owner":"PerryLink","short":"dsh-mask","slug":"PerryLink/dsh-mask","desc":"DeepSeek Harness 的 PII 脱敏：请求前匿名化姓名、电话、邮箱、证件与密钥，展示层还原，明文不进入会话日志。","cmd":"dsh plugin --profile web add dsh-mask","href":"/zh/p/PerryLink/dsh-mask/"},{"cat":"security","tag":"安全与权限","dl":2489,"stars":37,"added":"2026-08-28","npm":1,"name":"dsh-pentester","owner":"fb0sh","short":"dsh-pentester","slug":"fb0sh/dsh-pentester","desc":"基于 PTES 的渗透测试插件，采用 Root-Orchestrator 架构，用于 DeepSeek Harness。","cmd":"dsh plugin --profile web add dsh-pentester","href":"/zh/p/fb0sh/dsh-pentester/"},{"cat":"security","tag":"安全与权限","dl":2483,"stars":3,"added":"2026-08-16","npm":1,"name":"dsh-plugin-vet","owner":"wulun811","short":"dsh-plugin-vet","slug":"wulun811/dsh-plugin-vet","desc":"DSH 插件信任流水线：确定性静态扫描判定、可选运行时守卫与蜜罐诱饵、agent 审查协议技能与浏览器盾牌状态灯，只报警不执法。","cmd":"dsh plugin --profile web add @jieai/dsh-plugin-vet","href":"/zh/p/wulun811/dsh-plugin-vet/"},{"cat":"security","tag":"安全与权限","dl":2418,"stars":3,"added":"2026-08-23","npm":1,"name":"dsh-agent-approval","owner":"MoonlitDropOfBlood","short":"dsh-agent-approval","slug":"MoonlitDropOfBlood/dsh-agent-approval","desc":"由独立审批子代理裁决每次沙箱提权，可配置审批模型并带审计记录。","cmd":"dsh plugin --profile web add @duke-dsh-plugins/dsh-agent-approval","href":"/zh/p/MoonlitDropOfBlood/dsh-agent-approval/"},{"cat":"security","tag":"安全与权限","dl":2356,"stars":3,"added":"2026-08-18","npm":1,"name":"dsh-rule-engine","owner":"jilian-dsh","short":"dsh-rule-engine","slug":"jilian-dsh/dsh-rule-engine","desc":"dsh 规则执行引擎：解析 AGENTS.md、硬拦违反规则的工具调用、文本纠察与审计、/guard 命令、版本化文件守卫、自由区域支持（引擎跳过自由区内容）。","cmd":"dsh plugin --profile web add dsh-rule-engine","href":"/zh/p/jilian-dsh/dsh-rule-engine/"},{"cat":"security","tag":"安全与权限","dl":2355,"stars":10,"added":"2026-08-16","npm":1,"name":"dsh-permgate","owner":"MrWeiCodes","short":"dsh-permgate","slug":"MrWeiCodes/dsh-permgate","desc":"细粒度权限网关：按分类（工作区外目录/命令/读写文件/子代理/重复操作）逐项审查工具调用，全局/项目双级白黑名单、快捷工具默认值、自定义规则，中英文审批弹窗（内联 diff 详情、自定义拒绝意见）与底层沙箱升级流程。","cmd":"dsh plugin --profile web add @mrweicodes/dsh-permgate","href":"/zh/p/MrWeiCodes/dsh-permgate/"},{"cat":"security","tag":"安全与权限","dl":2120,"stars":2,"added":"2026-08-28","npm":1,"name":"dsh-trust-check","owner":"liuwenji007","short":"dsh-trust-check","slug":"liuwenji007/dsh-trust-check","desc":"DSH 插件静态能力披露：设置页与 CLI 列出已装插件的权限能力、字面量去向、安装脚本与注入形态（prompt 注册、自带 skill 文本、bundle patch），每条附文件:行号证据。代码判定、可复现、零 token。只做披露，不做安全承诺，不判定恶意。","cmd":"dsh plugin --profile web add dsh-trust-check","href":"/zh/p/liuwenji007/dsh-trust-check/"},{"cat":"security","tag":"安全与权限","dl":2016,"stars":13,"added":"2026-08-17","npm":1,"name":"dsh-auth-gateway","owner":"xbzbing","short":"dsh-auth-gateway","slug":"xbzbing/dsh-auth-gateway","desc":"为 dsh web 提供密码与 TOTP 双因素认证网关：登录前拦截全部 HTTP/WebSocket 请求，含按来源锁定、全局限流与一次性备份代码。","cmd":"dsh plugin --profile web add dsh-auth-gateway","href":"/zh/p/xbzbing/dsh-auth-gateway/"},{"cat":"security","tag":"安全与权限","dl":1883,"stars":12,"added":"2026-08-15","npm":1,"name":"upstream-radar","owner":"MicroMilo","short":"upstream-radar","slug":"MicroMilo/upstream-radar","desc":"持续监控 DSH 与插件发布，在一次性隔离环境中复测精确发布物，发布机器可读的兼容性证据，并在修复后自动核对和关闭受管理的问题。","cmd":"dsh plugin --profile web add upstream-radar","href":"/zh/p/MicroMilo/upstream-radar/"},{"cat":"security","tag":"安全与权限","dl":1777,"stars":3,"added":"2026-08-17","npm":1,"name":"dsh-yolo-mode","owner":"SeverusZh","short":"dsh-yolo-mode","slug":"SeverusZh/dsh-yolo-mode","desc":"沙箱升权申请的 LLM 自动审批：内置预设，fail-closed 兜底。","cmd":"dsh plugin --profile web add dsh-yolo-mode","href":"/zh/p/SeverusZh/dsh-yolo-mode/"},{"cat":"security","tag":"安全与权限","dl":1772,"stars":67,"added":"2026-08-17","npm":1,"name":"dsh-remote","owner":"xgone","short":"dsh-remote","slug":"xgone/dsh-remote","desc":"为 DeepSeek Harness Web UI 提供安全远程访问：登录门禁、MFA/TOTP、签名会话 Cookie、可选的 admin/user/guest 角色、浏览器内工作区选择和按允许目录限制的远程文件预览。","cmd":"dsh plugin --profile web add @xgone/dsh-remote","href":"/zh/p/xgone/dsh-remote/"},{"cat":"security","tag":"安全与权限","dl":1735,"stars":0,"added":"2026-09-18","npm":1,"name":"dsh-approval-review","owner":"LAwLi3tCoding","short":"dsh-approval-review","slug":"LAwLi3tCoding/dsh-approval-review","desc":"新增「替我审批」访问模式：审批请求由独立的复核模型裁决而非人工，复核者可只读工作区，复核跑不起来时把请求交回人工，每次裁决的理由记录在「审批」页签中。","cmd":"dsh plugin --profile web add dsh-approval-review","href":"/zh/p/LAwLi3tCoding/dsh-approval-review/"},{"cat":"security","tag":"安全与权限","dl":1676,"stars":2,"added":"2026-09-13","npm":1,"name":"dsh-auto-approve","owner":"DNAlec","short":"dsh-auto-approve","slug":"DNAlec/dsh-auto-approve","desc":"自动审批 / 自动审核需要审批的工具调用：先用关键词分桶做零上下文红线匹配，再交由审核模型判类别与风险等级， 按命中行与等级那一格决定自动允许、自动拒绝或转人工；判定没跑成固定转人工，自动拒绝会把原因回传给模型。","cmd":"dsh plugin --profile web add @dnalec/dsh-auto-approve","href":"/zh/p/DNAlec/dsh-auto-approve/"},{"cat":"security","tag":"安全与权限","dl":1616,"stars":1,"added":"2026-08-17","npm":1,"name":"dsh-code-security","owner":"STARDUSTLC666","short":"dsh-code-security","slug":"STARDUSTLC666/dsh-code-security","desc":"确定性代码安全审查：40+ 规则、密钥熵检测、staged diff 审查、SARIF 导出、基线接受、SBOM-lite 依赖清单与健康自检。","cmd":"dsh plugin --profile web add dsh-code-security","href":"/zh/p/STARDUSTLC666/dsh-code-security/"},{"cat":"security","tag":"安全与权限","dl":1541,"stars":0,"added":"2026-08-17","npm":1,"name":"dsh-plugin-gate","owner":"863683348","short":"dsh-plugin-gate","slug":"863683348/dsh-plugin-gate","desc":"DSH 插件的安装安全闸门：在 \"dsh plugin add\" 前对本地目录或 npm 包做\"杀毒\"式扫描（安装脚本、权限、密钥、网络回连），给出 BLOCK/WARN/PASS 判定。","cmd":"dsh plugin --profile web add dsh-plugin-gate","href":"/zh/p/863683348/dsh-plugin-gate/"},{"cat":"security","tag":"安全与权限","dl":1434,"stars":1,"added":"2026-09-22","npm":1,"name":"euthyna","owner":"slow-stack","short":"euthyna","slug":"slow-stack/euthyna","desc":"面向 AI 编码代理的确定性安全审计事实与结论门禁：euthyna history 把每行被删代码归因到提交并标记安全修复类删除（--origins 追到最初引入者），euthyna coverage 报告哪些改动符号从未被测试调用，euthyna gate 用六道门禁逐条校验结论，拿不出证据的一律降级为观察。","cmd":"dsh plugin --profile web add euthyna","href":"/zh/p/slow-stack/euthyna/"},{"cat":"security","tag":"安全与权限","dl":1424,"stars":15,"added":"2026-08-15","npm":1,"name":"dsh-auto-approve","owner":"Jiao-XXX","short":"dsh-auto-approve","slug":"Jiao-XXX/dsh-auto-approve","desc":"在 workspace-write 与 danger-full-access 之间增加 `auto` 权限档：分类器一次性放行例行沙箱升级，危险或不确定的操作仍转人工审批。","cmd":"dsh plugin --profile web add dsh-auto-approve","href":"/zh/p/Jiao-XXX/dsh-auto-approve/"},{"cat":"security","tag":"安全与权限","dl":1247,"stars":85,"added":"2026-08-21","npm":1,"name":"dsh-secure-audit","owner":"PensiveFei","short":"dsh-secure-audit","slug":"PensiveFei/dsh-secure-audit","desc":"DSH 只读安全合规插件：提示注入检测、中文 PII 脱敏、本机配置安全审计，输出脱敏且可复现的报告。","cmd":"dsh plugin --profile web add dsh-secure-audit","href":"/zh/p/PensiveFei/dsh-secure-audit/"},{"cat":"security","tag":"安全与权限","dl":1197,"stars":7,"added":"2026-08-19","npm":1,"name":"dsh-riskproof","owner":"onlyqzq","short":"dsh-riskproof","slug":"onlyqzq/dsh-riskproof","desc":"DSH 实时安全浮标，随工具调用更新防护状态，点击查看调用统计、风险来源链和拦截结果，支持只读任务约束及工具元数据变化检测。","cmd":"dsh plugin --profile web add dsh-riskproof","href":"/zh/p/onlyqzq/dsh-riskproof/"},{"cat":"security","tag":"安全与权限","dl":1191,"stars":10,"added":"2026-08-27","npm":1,"name":"dsh-login","owner":"islibaodong","short":"dsh-login","slug":"islibaodong/dsh-login","desc":"为 DSH Web 界面提供多用户登录网关：首次访问创建管理员账户，管理员在 GUI 设置面板中添加和管理用户，普通用户只能看到自己的会话，未登录访问重定向到 /login。","cmd":"dsh plugin --profile web add @islibaodong/dsh-login","href":"/zh/p/islibaodong/dsh-login/"},{"cat":"security","tag":"安全与权限","dl":1164,"stars":1,"added":"2026-09-06","npm":1,"name":"dsh-semgrep-sast#semgrep-sast","owner":"Baiiduu","short":"dsh-semgrep-sast#semgrep-sast","slug":"Baiiduu/dsh-semgrep-sast--packages-bundle","desc":"面向 DeepSeek Harness 的工作区内 Semgrep SAST 工具，提供托管 Windows x64 运行时、结构化有界结果、取消与超时控制，以及经用户批准的沙箱权限升级。npm 包名为 @aaub-software/dsh-semgrep-sast。","cmd":"dsh plugin --profile web add @aaub-software/dsh-semgrep-sast","href":"/zh/p/Baiiduu/dsh-semgrep-sast--packages-bundle/"},{"cat":"security","tag":"安全与权限","dl":1043,"stars":7,"added":"2026-08-14","npm":1,"name":"dsh-approval-llm","owner":"Letter2025","short":"dsh-approval-llm","slug":"Letter2025/dsh-approval-llm","desc":"基于模型的权限审批：由独立审查模型自动应答 approval 权限请求。","cmd":"dsh plugin --profile web add dsh-approval-llm","href":"/zh/p/Letter2025/dsh-approval-llm/"},{"cat":"security","tag":"安全与权限","dl":1031,"stars":6,"added":"2026-08-28","npm":1,"name":"dsh-ui-auth","owner":"0QwQ0","short":"dsh-ui-auth","slug":"0QwQ0/dsh-ui-auth","desc":"DeepSeek Harness Web UI 认证网关：登录门禁覆盖页面、/api、/plugins 与 WebSocket 升级；PBKDF2 口令哈希、HttpOnly SameSite 会话 Cookie、按源 IP 登录锁定；邀请码注册；两步验证可用 TOTP 动态码或通行密钥（WebAuthn：一个账号可绑定多个密钥，手机可扫码添加，支持免用户名登录，改动登录因子前必须二次验证）；设置面板内置用户管理（普通用户可修改本人资料与密码并管理自己的 TOTP 与通行密钥，管理员可新增/删除用户、重置密码、管理邀请码、清除丢失设备的通行密钥）；模型配置与 API Key 仅管理员可修改；REST/列表接口与 WebSocket 事件流均按用户隔离；会话重启后免登录恢复；JSONL 审计日志；存储故障时保持 fail-closed。同时支持两条 DSH 传输线（0.1.1-rc.2 legacy 与 0.1.2+ modern），无需配置；因浏览器要求安全上下文，通行密钥需通过 localhost 或 HTTPS 访问。","cmd":"dsh plugin --profile web add dsh-ui-auth","href":"/zh/p/0QwQ0/dsh-ui-auth/"},{"cat":"security","tag":"安全与权限","dl":911,"stars":1,"added":"2026-09-06","npm":1,"name":"dsh-kubectl-guard","owner":"gengwg","short":"dsh-kubectl-guard","slug":"gengwg/dsh-kubectl-guard","desc":"按 kubeconfig context 管控 kubectl 调用的策略插件：本地集群外硬拒绝不可逆操作，其余写操作请求人工确认。","cmd":"dsh plugin --profile web add dsh-kubectl-guard","href":"/zh/p/gengwg/dsh-kubectl-guard/"},{"cat":"security","tag":"安全与权限","dl":899,"stars":6,"added":"2026-08-19","npm":1,"name":"dsh-auth","owner":"hxy91819","short":"dsh-auth","slug":"hxy91819/dsh-auth","desc":"通过 Caddy forward_auth 为 DeepSeek Harness Web 提供管理员登录，含 Argon2id 口令、可撤销会话、中英界面和侧栏原生退出。","cmd":"dsh plugin --profile web add dsh-auth","href":"/zh/p/hxy91819/dsh-auth/"},{"cat":"security","tag":"安全与权限","dl":868,"stars":0,"added":"2026-09-21","npm":1,"name":"dsh-jev-guard","owner":"7starsseeker","short":"dsh-jev-guard","slug":"7starsseeker/dsh-jev-guard","desc":"DSH 执行前安全阀门，用 TypeSafe Jev 模型做判定：挂载 tools/pre-execute，对每条 bash/pwsh 调用先过离线静态规则，再向 Jev 模型（TypeSafe 的 System One 模型，返回结构化判定而非散文）提一个是非问句——「这条命令会不可逆地删除或覆盖真实数据吗？」——把答案切成允许／修正／拦截／上报人工四态；修正给模型更安全的写法，上报提供一次性人工令牌；额度耗尽或没有可用密钥时大声降级而非静默失效，缺密钥时会直接在对话里要求录入（录入用 `guard key set`，只从标准输入读）；每条判定写入共享审计日志，面向人的文案中英双语。","cmd":"dsh plugin --profile web add dsh-jev-guard","href":"/zh/p/7starsseeker/dsh-jev-guard/"},{"cat":"security","tag":"安全与权限","dl":848,"stars":2,"added":"2026-09-03","npm":1,"name":"dsh-secret-scrub","owner":"jkt-check","short":"dsh-secret-scrub","slug":"jkt-check/dsh-secret-scrub","desc":"不可逆密钥脱敏守护：在访问密钥、Bearer 令牌、私钥块进入会话日志和模型请求之前，将其改写为 `[REDACTED:<category>]` 占位符。","cmd":"dsh plugin --profile web add dsh-secret-scrub","href":"/zh/p/jkt-check/dsh-secret-scrub/"},{"cat":"security","tag":"安全与权限","dl":834,"stars":1,"added":"2026-08-19","npm":1,"name":"dsh-provenance","owner":"Darren-Tang","short":"dsh-provenance","slug":"Darren-Tang/dsh-provenance","desc":"为 DeepSeek Harness 插件做安装前供应链校验：在代码运行前核对即将安装的包是否与你读到的源码一致。","cmd":"dsh plugin --profile web add dsh-provenance","href":"/zh/p/Darren-Tang/dsh-provenance/"},{"cat":"security","tag":"安全与权限","dl":813,"stars":1,"added":"2026-08-31","npm":1,"name":"dsh-cloudflare-access","owner":"Luawig","short":"dsh-cloudflare-access","slug":"Luawig/dsh-cloudflare-access","desc":"在 DSH Origin 校验 Cloudflare Access JWT，使 Settings、凭据、Agent Preset 管理与模型发现可在远程主机名下使用。","cmd":"dsh plugin --profile web add dsh-cloudflare-access","href":"/zh/p/Luawig/dsh-cloudflare-access/"},{"cat":"security","tag":"安全与权限","dl":777,"stars":2,"added":"2026-08-27","npm":1,"name":"dsh-sonarqube","owner":"maxmilian","short":"dsh-sonarqube","slug":"maxmilian/dsh-sonarqube","desc":"面向 SonarQube Community Build 的只读工具：实例状态、分支或 PR 的项目质量阈、议题与安全热点搜索、单个热点详情，以及覆盖率、重复率或调用方指定的度量项。议题与热点结果附带标准化的位置信息，包含组件 key、文件路径、行号与文本范围。","cmd":"dsh plugin --profile web add dsh-sonarqube","href":"/zh/p/maxmilian/dsh-sonarqube/"},{"cat":"security","tag":"安全与权限","dl":775,"stars":3,"added":"2026-08-14","npm":1,"name":"qiushi-dsh-evidence-audit","owner":"030611","short":"qiushi-dsh-evidence-audit","slug":"030611/qiushi-dsh-evidence-audit","desc":"把工具结果与会话事件的 receipt 写入本地哈希链 JSONL，不保存提示词、工具参数、结果正文或原始会话 ID。","cmd":"dsh plugin --profile web add qiushi-dsh-evidence-audit","href":"/zh/p/030611/qiushi-dsh-evidence-audit/"},{"cat":"security","tag":"安全与权限","dl":748,"stars":2,"added":"2026-08-14","npm":1,"name":"dsh-telemetry-redactor","owner":"030611","short":"dsh-telemetry-redactor","slug":"030611/dsh-telemetry-redactor","desc":"在已配置遥测后端接收前，对 `session-telemetry/record` 导出副本中的已支持秘密模式进行脱敏。","cmd":"dsh plugin --profile web add dsh-telemetry-redactor","href":"/zh/p/030611/dsh-telemetry-redactor/"},{"cat":"security","tag":"安全与权限","dl":718,"stars":0,"added":"2026-09-10","npm":1,"name":"dsh-totp","owner":"SodaZheng","short":"dsh-totp","slug":"SodaZheng/dsh-totp","desc":"面向个人 DeepSeek Harness Web 实例的纯 TOTP 访问验证，支持设置内扫码绑定、一次性恢复码、动态启停保护和撤销所有页面授权。","cmd":"dsh plugin --profile web add dsh-totp","href":"/zh/p/SodaZheng/dsh-totp/"},{"cat":"security","tag":"安全与权限","dl":717,"stars":4,"added":"2026-08-15","npm":1,"name":"dsh-plugin-vetting","owner":"truelove-dreamer","short":"dsh-plugin-vetting","slug":"truelove-dreamer/dsh-plugin-vetting","desc":"为了您的电脑安全，装插件前先体检：静态扫描恶意模式（外传/凭据/混淆/持久化）与高权限误用，覆盖传递依赖与官方包哈希基线（防供应链篡改），可选插件工具调用闸。","cmd":"dsh plugin --profile web add dsh-plugin-vetting","href":"/zh/p/truelove-dreamer/dsh-plugin-vetting/"},{"cat":"security","tag":"安全与权限","dl":699,"stars":1,"added":"2026-08-16","npm":1,"name":"dsh-security-guard","owner":"bigclawd","short":"dsh-security-guard","slug":"bigclawd/dsh-security-guard","desc":"dsh 安全守卫插件：基于规则的静态扫描覆盖恶意代码、提示词注入与令牌浪费，运行时拦截危险工具调用，提供 /scan 命令、plugin_scan 工具、Web 面板与白名单。","cmd":"dsh plugin --profile web add dsh-security-guard","href":"/zh/p/bigclawd/dsh-security-guard/"},{"cat":"security","tag":"安全与权限","dl":686,"stars":3,"added":"2026-09-09","npm":1,"name":"dsh-write-protect","owner":"azazo1","short":"dsh-write-protect","slug":"azazo1/dsh-write-protect","desc":"为 DSH 沙箱增加工作区子路径只读保护 (例如 .git), 支持工作区根下的只读规则文件, 可在 workspace-write 下声明额外可写根, 并允许模型申请本会话的可写授权; 命令沙箱与 write/edit 工具都生效.","cmd":"dsh plugin --profile web add dsh-write-protect","href":"/zh/p/azazo1/dsh-write-protect/"},{"cat":"security","tag":"安全与权限","dl":686,"stars":3,"added":"2026-08-27","npm":1,"name":"dsh-always-require-tools-approval","owner":"J0ss077","short":"dsh-always-require-tools-approval","slug":"J0ss077/dsh-always-require-tools-approval","desc":"在配置的工具（默认 bash、pwsh）执行前要求一次性用户审批：受控工具暂停并询问，其余委托执行，缺少审批渠道时默认拒绝。","cmd":"dsh plugin --profile web add @j0ss077/dsh-always-require-tools-approval","href":"/zh/p/J0ss077/dsh-always-require-tools-approval/"},{"cat":"security","tag":"安全与权限","dl":672,"stars":0,"added":"2026-08-18","npm":1,"name":"dsh-risk-guard","owner":"shuxue6662-a11y","short":"dsh-risk-guard","slug":"shuxue6662-a11y/dsh-risk-guard","desc":"零打扰审计与保险丝拦截：静默记录每次工具调用并做纯规则风险评分（含累积加分、风险等级分布、归档保留期清理），只拦不可逆灾难（受保护路径删除、磁盘擦除、force push 到受保护分支/引用、凭据外发），/risk-guard 输出脱敏操作账单并支持 --since 时间过滤。","cmd":"dsh plugin --profile web add dsh-risk-guard","href":"/zh/p/shuxue6662-a11y/dsh-risk-guard/"},{"cat":"security","tag":"安全与权限","dl":649,"stars":2,"added":"2026-08-17","npm":1,"name":"dsh-web-auth","owner":"SummerSec","short":"dsh-web-auth","slug":"SummerSec/dsh-web-auth","desc":"DeepSeek Harness Web GUI 的传输层认证门禁，提供服务端会话、HttpOnly Cookie、基于 IP 的登录限流及 scrypt 口令 CLI。","cmd":"dsh plugin --profile web add @summersec/dsh-web-auth","href":"/zh/p/SummerSec/dsh-web-auth/"},{"cat":"security","tag":"安全与权限","dl":593,"stars":0,"added":"2026-09-20","npm":1,"name":"dsh-tm-guard","owner":"ChaoJie0","short":"dsh-tm-guard","slug":"ChaoJie0/dsh-tm-guard","desc":"macOS 上 DSH 智能体的零干预权限门：可经本地 git 或时间机器回滚的本地写操作自动放行，拦截网络、装包、进程控制与敏感路径读取，并记录完整审计日志。","cmd":"dsh plugin --profile web add dsh-tm-guard","href":"/zh/p/ChaoJie0/dsh-tm-guard/"},{"cat":"security","tag":"安全与权限","dl":586,"stars":0,"added":"2026-08-13","npm":1,"name":"dsh-tool-approval","owner":"ilharp","short":"dsh-tool-approval","slug":"ilharp/dsh-tool-approval","desc":"手动审批模式（Manual/Ask Mode）。","cmd":"dsh plugin --profile web add dsh-tool-approval","href":"/zh/p/ilharp/dsh-tool-approval/"},{"cat":"security","tag":"安全与权限","dl":584,"stars":1,"added":"2026-08-15","npm":1,"name":"dsh-auto-classifier","owner":"PAKIKNOWLEDGE","short":"dsh-auto-classifier","slug":"PAKIKNOWLEDGE/dsh-auto-classifier","desc":"auto（自主模式）权限分类器：工具作用域的放行/拒绝规则、LLM 语义裁判与 git 快照，面向无人值守会话。","cmd":"dsh plugin --profile web add dsh-auto-classifier","href":"/zh/p/PAKIKNOWLEDGE/dsh-auto-classifier/"},{"cat":"security","tag":"安全与权限","dl":554,"stars":9,"added":"2026-08-21","npm":1,"name":"dshscan","owner":"shaoshi20","short":"dshscan","slug":"shaoshi20/dshscan","desc":"DSH 插件安全扫描器：对插件源码做静态与语义双通道检查，内置 DSH 特有攻击面规则，集成 npm audit，支持批量扫描，输出带严重等级与证据的 HTML 报告。","cmd":"dsh plugin --profile web add @shaoshi/dshscan","href":"/zh/p/shaoshi20/dshscan/"},{"cat":"security","tag":"安全与权限","dl":547,"stars":5,"added":"2026-08-20","npm":1,"name":"dsh-sentinel-scanner","owner":"Eligahyu","short":"dsh-sentinel-scanner","slug":"Eligahyu/dsh-sentinel-scanner","desc":"DSH 插件安全扫描器：只读静态审计（执行、凭据、外传、混淆、安装脚本、bundle 清单），输出 0-100 风险分。","cmd":"dsh plugin --profile web add deepseek-harness-sentinel","href":"/zh/p/Eligahyu/dsh-sentinel-scanner/"},{"cat":"security","tag":"安全与权限","dl":516,"stars":1,"added":"2026-08-19","npm":1,"name":"dsh-almost_full_access","owner":"Alnita-M","short":"dsh-Almost_Full_Access","slug":"Alnita-M/dsh-Almost_Full_Access","desc":"介于 workspace-write 与 Full access 之间的权限模式：命令先经规则与子代理审查，不可逆或系统级操作需人工批准。","cmd":"dsh plugin --profile web add dsh-almost-full-access","href":"/zh/p/Alnita-M/dsh-Almost_Full_Access/"},{"cat":"security","tag":"安全与权限","dl":507,"stars":0,"added":"2026-08-30","npm":1,"name":"dsh-dros-vajraclaw","owner":"Top-Celestial-Company-Ltd","short":"dsh-dros-vajraclaw","slug":"Top-Celestial-Company-Ltd/dsh-dros-vajraclaw","desc":"DSH 本機工具調用防護外掛：攔截高風險 Shell 指令模式與敏感憑證讀取，具備持久化哈希鏈 JSONL 審計記錄，可選配外部 Gateway 集中治理。","cmd":"dsh plugin --profile web add dsh-plugin-vajraclaw","href":"/zh/p/Top-Celestial-Company-Ltd/dsh-dros-vajraclaw/"},{"cat":"security","tag":"安全与权限","dl":501,"stars":14,"added":"2026-08-15","npm":1,"name":"dsh-movein#plugin","owner":"sjh9714","short":"dsh-movein#plugin","slug":"sjh9714/dsh-movein--plugin","desc":"为 DSH 补上按工具粒度的权限规则：在 tools/pre-execute 强制执行 deny/ask 清单，规则语法与 Claude Code 相同，不迁移也能单独用。","cmd":"dsh plugin --profile web add dsh-movein-permissions","href":"/zh/p/sjh9714/dsh-movein--plugin/"},{"cat":"security","tag":"安全与权限","dl":498,"stars":0,"added":"2026-09-15","npm":1,"name":"dsh-redaction#dsh-plugin-redact","owner":"L-ingqin12","short":"dsh-redaction#dsh-plugin-redact","slug":"L-ingqin12/dsh-redaction--packages-dsh-plugin-redact","desc":"会话日志的原地脱敏与按行回退：守住「每行 seq 必须等于它的行号」这一不变式（删中间行会让整份日志打不开）。任何写入前先把原文复制成隔离备份，并以读取端自身的语义作为写前闸门。","cmd":"dsh plugin --profile web add dsh-plugin-redact","href":"/zh/p/L-ingqin12/dsh-redaction--packages-dsh-plugin-redact/"},{"cat":"security","tag":"安全与权限","dl":484,"stars":0,"added":"2026-09-15","npm":1,"name":"dsh-redaction#dsh-plugin-content-policy","owner":"L-ingqin12","short":"dsh-redaction#dsh-plugin-content-policy","slug":"L-ingqin12/dsh-redaction--packages-dsh-plugin-content-policy","desc":"工具结果的预防式内容策略：改写命中文本，并按字段路径整段丢弃或截断，让未经审查的载荷在结果被规范化/渲染/落盘之前就进不去。随包为真空操作，不含任何内置的类别或域名黑名单。","cmd":"dsh plugin --profile web add dsh-plugin-content-policy","href":"/zh/p/L-ingqin12/dsh-redaction--packages-dsh-plugin-content-policy/"},{"cat":"security","tag":"安全与权限","dl":457,"stars":4,"added":"2026-08-14","npm":1,"name":"dsh-verification-receipt","owner":"030611","short":"dsh-verification-receipt","slug":"030611/dsh-verification-receipt","desc":"把每轮工具计数与粗粒度验证信号写入本地 JSONL，不保存提示词、工具参数或结果正文。","cmd":"dsh plugin --profile web add dsh-verification-receipt","href":"/zh/p/030611/dsh-verification-receipt/"},{"cat":"security","tag":"安全与权限","dl":436,"stars":1,"added":"2026-08-17","npm":1,"name":"dsh-poison-guard","owner":"zoahdev","short":"dsh-poison-guard","slug":"zoahdev/dsh-poison-guard","desc":"DSH 插件安装前投毒扫描：AST（JS-X-Ray）+ 去混淆解码 + 正则启发式，发现即非零退出，可作 CI 门禁。","cmd":"dsh plugin --profile web add dsh-poison-guard","href":"/zh/p/zoahdev/dsh-poison-guard/"},{"cat":"security","tag":"安全与权限","dl":404,"stars":22,"added":"2026-09-25","npm":1,"name":"dsh-jev-interceptor","owner":"AskTheWay","short":"dsh-jev-interceptor","slug":"AskTheWay/dsh-jev-interceptor","desc":"在 tools/pre-execute 上用 Jev（TypeSafe AI 的非生成式决策模型）对待执行的工具调用分类——高置信高危拒绝、存疑转审批——并在 approval/request 上对明确授权且可逆的调用做带参数证据门控的自动批准。另子类化 session-reference resolver，让引用快照按 Jev 打分保留消息而非最旧优先丢弃。任何 provider 故障均回退原生行为；提供 shadow 模式与 /jev-stats 统计命令；支持 TypeSafe 或 OpenRouter 入口；64 个测试。","cmd":"dsh plugin --profile web add dsh-jev-interceptor","href":"/zh/p/AskTheWay/dsh-jev-interceptor/"},{"cat":"security","tag":"安全与权限","dl":386,"stars":1,"added":"2026-09-19","npm":1,"name":"dsh-plugin-precheck","owner":"BaqiF2","short":"dsh-plugin-precheck","slug":"BaqiF2/dsh-plugin-precheck","desc":"DSH 插件安装前兼容性门控：锁定解析版本、校验 peer/engines 声明、在隔离 DSH_HOME 中试装并限时试启动，任一失败即阻止；正式安装失败自动还原 profile。可选拦截 dsh-market 的安装/更新点击。","cmd":"dsh plugin --profile web add dsh-plugin-precheck","href":"/zh/p/BaqiF2/dsh-plugin-precheck/"},{"cat":"security","tag":"安全与权限","dl":358,"stars":0,"added":"2026-08-15","npm":1,"name":"dsh-plugin-judge","owner":"pengxuding","short":"dsh-plugin-judge","slug":"pengxuding/dsh-plugin-judge","desc":"插件价值裁判：装前审核（源码静态扫描 + LLM 裁判）与装后审计已装插件，模型切换时弹窗提醒复核；判断插件对当前模型是增强还是压制。","cmd":"dsh plugin --profile web add dsh-plugin-judge","href":"/zh/p/pengxuding/dsh-plugin-judge/"},{"cat":"security","tag":"安全与权限","dl":351,"stars":1,"added":"2026-08-19","npm":1,"name":"dsh-write-gate","owner":"couldbeme","short":"dsh-write-gate","slug":"couldbeme/dsh-write-gate","desc":"承诺写入闸门：由运营者编写的规则在工具调用执行前生效——先是一层确定性守卫，再是一层 LLM 裁判，默认失败即拒绝，每一次拦截都写进矛盾日志。","cmd":"dsh plugin --profile web add dsh-write-gate","href":"/zh/p/couldbeme/dsh-write-gate/"},{"cat":"security","tag":"安全与权限","dl":347,"stars":0,"added":"2026-08-15","npm":1,"name":"dsh-lan-pass","owner":"x2802490130-prog","short":"dsh-lan-pass","slug":"x2802490130-prog/dsh-lan-pass","desc":"Web UI 局域网密码门禁：同网手机/平板输共享密钥登录，会话与电脑实时同步，内置 randomUUID polyfill。","cmd":"dsh plugin --profile web add dsh-lan-pass","href":"/zh/p/x2802490130-prog/dsh-lan-pass/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":865,"added":"2026-08-18","npm":0,"name":"api-relay-audit","owner":"toby-bridges","short":"api-relay-audit","slug":"toby-bridges/api-relay-audit","desc":"从 DeepSeek Harness 对 AI API 中转站和 LLM 代理运行本地安全审计，生成 Markdown 报告，覆盖提示词注入、模型替换信号、工具调用改写、错误泄漏、流完整性和按 profile 启用的 Web3 风险。","cmd":"dsh plugin --profile web add github:toby-bridges/api-relay-audit","href":"/zh/p/toby-bridges/api-relay-audit/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":655,"added":"2026-08-27","npm":0,"name":"dsh-redteam-model","owner":"SeaOf0","short":"dsh-redteam-model","slug":"SeaOf0/dsh-redteam-model","desc":"面向授权安全研究的 DSH 合集：九个工作模式（redteam 总控、渗透测试、代码审计、二进制分析、攻防评估、免杀对抗、应急溯源、云安全攻防、CTF 解题）与十五个运行时插件，设置页管理台支持一键部署、安装、更新与卸载。","cmd":"dsh plugin --profile web add github:SeaOf0/dsh-redteam-model","href":"/zh/p/SeaOf0/dsh-redteam-model/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":571,"added":"2026-08-20","npm":0,"name":"dsh-pentest","owner":"howmp","short":"dsh-pentest","slug":"howmp/dsh-pentest","desc":"面向 DeepSeek Harness 的授权渗透模式：以探索链路记录目标、线索、资产与漏洞，并在 Web 中可视化展示。","cmd":"dsh plugin --profile web add github:howmp/dsh-pentest","href":"/zh/p/howmp/dsh-pentest/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":90,"added":"2026-08-23","npm":0,"name":"helm-d#helmd","owner":"ADWMC","short":"helm-d#helmd","slug":"ADWMC/helm-d--packages-helmd","desc":"单包逆向与渗透测试安全分析插件：首轮工具收敛、领域路由与 33 个工具，覆盖 APK、Web、原生二进制、协议、恶意样本与 LLM 场景的逆向分析、加壳脱壳与 License 破解绕过；内置 H-CoT 评估引擎（语义路由、/hcot 命令）、账本驱动的 Web 工作台与工具货架、磁盘案件工作区（证据链自动存证、E 编号结论校验、上下文压缩后恢复）、GitHub 工具检索与 361 篇按需参考文档。","cmd":"dsh plugin --profile web add github:ADWMC/helm-d#path:/packages/helmd","href":"/zh/p/ADWMC/helm-d--packages-helmd/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":51,"added":"2026-09-02","npm":0,"name":"sofagent#cordis-plugin-sofagent-audit","owner":"KongFangXun","short":"sofagent#cordis-plugin-sofagent-audit","slug":"KongFangXun/sofagent--engine-dsh-plugins-cordis-plugin-sofagent-audit","desc":"面向 AI 编程 agent 的提交时审计 harness——24 条 git diff 规则（密钥泄漏、越界改动、提示注入）、HMAC 签名审计链、快照回滚、84 工具 MCP server；dsh plugin add 即装。","cmd":"dsh plugin --profile web add github:KongFangXun/sofagent#path:/engine/dsh-plugins/cordis-plugin-sofagent-audit","href":"/zh/p/KongFangXun/sofagent--engine-dsh-plugins-cordis-plugin-sofagent-audit/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":47,"added":"2026-08-19","npm":0,"name":"dsh-web-startup-auth","owner":"GDWhisper","short":"dsh-web-startup-auth","slug":"GDWhisper/dsh-web-startup-auth","desc":"替换 dsh web 启动器以允许绑定 0.0.0.0，并以账号密码登录为门槛：签名会话 cookie、/api 路由保护、设置面板认证标签页，以及轮换签名密钥使全部会话失效的重置 CLI。","cmd":"dsh plugin --profile web add github:GDWhisper/dsh-web-startup-auth","href":"/zh/p/GDWhisper/dsh-web-startup-auth/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":17,"added":"2026-08-16","npm":0,"name":"dsh-skill-pack-security","owner":"PerryLink","short":"dsh-skill-pack-security","slug":"PerryLink/dsh-skill-pack-security","desc":"安全审计方法论技能包 + plugin_vet 供应链门禁：八个 agent 技能（密钥扫描、依赖审计、供应链评审、提示注入审查、审计总编排、威胁建模、漏洞情报、事件响应），中英双版本，附 npm provider 包一键挂载并注册自动化 plugin_vet 安装前扫描。","cmd":"dsh plugin --profile web add github:PerryLink/dsh-skill-pack-security","href":"/zh/p/PerryLink/dsh-skill-pack-security/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":14,"added":"2026-08-13","npm":0,"name":"dsh-security-audit","owner":"omdsh-dev","short":"dsh-security-audit","slug":"omdsh-dev/dsh-security-audit","desc":"本机安全审计：配置/插件来源/会话/网络暴露面，只读脱敏风险报告。","cmd":"dsh plugin --profile web add github:omdsh-dev/dsh-security-audit","href":"/zh/p/omdsh-dev/dsh-security-audit/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":14,"added":"2026-08-27","npm":0,"name":"weiwen-law-dsh","owner":"Shaky77","short":"weiwen-law-dsh","slug":"Shaky77/weiwen-law-dsh","desc":"唯稳律白箱因果闸门：每个工具调用执行前沿确定性因果逻辑链裁决——拦截破坏性与凭据文件操作、对反复越界升级止损、故障环节切断至修复验证、不可审计执行给出风险判定；纯本地运行、零 API 成本，附带 6 个白箱自查工具。","cmd":"dsh plugin --profile web add github:Shaky77/weiwen-law-dsh","href":"/zh/p/Shaky77/weiwen-law-dsh/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":8,"added":"2026-08-14","npm":0,"name":"dsh-webui-auth","owner":"Yuuz12","short":"dsh-webui-auth","slug":"Yuuz12/dsh-webui-auth","desc":"WebUI 身份认证：HTTP/传输层强制登录（资源、插件 bundle、/api、WebSocket 四层防护），服务端会话 + HttpOnly Cookie。","cmd":"dsh plugin --profile web add github:Yuuz12/dsh-webui-auth","href":"/zh/p/Yuuz12/dsh-webui-auth/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":7,"added":"2026-08-24","npm":0,"name":"cue-skills#cue-omni-reader-guard","owner":"sensedeal","short":"cue-skills#cue-omni-reader-guard","slug":"sensedeal/cue-skills--dsh-cue-omni-reader-guard","desc":"面向 DeepSeek Harness 的 mcp__omni__parse 加固护栏：tools/pre-execute 监听器拒绝私网/保留主机（SSRF），施加白名单或 ask（同意），allowedRoots 为空时 fail-closed。","cmd":"dsh plugin --profile web add github:sensedeal/cue-skills#path:/dsh/cue-omni-reader-guard","href":"/zh/p/sensedeal/cue-skills--dsh-cue-omni-reader-guard/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":6,"added":"2026-08-23","npm":0,"name":"dsh-approval-mode","owner":"NEVSTOP-LAB","short":"dsh-approval-mode","slug":"NEVSTOP-LAB/dsh-approval-mode","desc":"在权限下拉框旁增加「审批模式」开关：默认审批保留逐次确认，绕过审批自动放行所有工具调用，同时保持 Workspace Write 权限。","cmd":"dsh plugin --profile web add github:NEVSTOP-LAB/dsh-approval-mode","href":"/zh/p/NEVSTOP-LAB/dsh-approval-mode/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":6,"added":"2026-08-14","npm":0,"name":"dsh-auto","owner":"simon300000","short":"dsh-auto","slug":"simon300000/dsh-auto","desc":"为 WebUI 增加 Auto Approve 权限档位，由全新且受限的审查 Agent 逐次允许或拒绝审批请求。","cmd":"dsh plugin --profile web add github:simon300000/dsh-auto","href":"/zh/p/simon300000/dsh-auto/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":4,"added":"2026-08-23","npm":0,"name":"dsh-plugin-security-review","owner":"ateen18","short":"dsh-plugin-security-review","slug":"ateen18/dsh-plugin-security-review","desc":"DSH 插件安全审查与运行时守卫：安装前静态审查（反混淆解码、供应链检测）、Web 一键审查/安装/卸载，以及可选的运行时工具调用拦截。","cmd":"dsh plugin --profile web add github:ateen18/dsh-plugin-security-review","href":"/zh/p/ateen18/dsh-plugin-security-review/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":4,"added":"2026-09-08","npm":0,"name":"dsh-workspace-write-plus","owner":"yzxxy010","short":"dsh-workspace-write-plus","slug":"yzxxy010/dsh-workspace-write-plus","desc":"增加工作区修改++权限档，文件工具仍锁在工作区，可用通配符放行 Git Bash 等程序以跳过 Windows 进程沙箱。","cmd":"dsh plugin --profile web add github:yzxxy010/dsh-workspace-write-plus","href":"/zh/p/yzxxy010/dsh-workspace-write-plus/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":3,"added":"2026-08-16","npm":0,"name":"dsh-guardian","owner":"cdxiaodong","short":"dsh-guardian","slug":"cdxiaodong/dsh-guardian","desc":"Agent 安全护栏：拦截并审计所有工具调用，命中敏感操作就要求人工确认。","cmd":"dsh plugin --profile web add github:cdxiaodong/dsh-guardian","href":"/zh/p/cdxiaodong/dsh-guardian/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":3,"added":"2026-08-13","npm":0,"name":"sandbox-micro","owner":"omdsh-dev","short":"sandbox-micro","slug":"omdsh-dev/sandbox-micro","desc":"microsandbox 沙箱支持。","cmd":"dsh plugin --profile web add github:omdsh-dev/sandbox-micro","href":"/zh/p/omdsh-dev/sandbox-micro/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":2,"added":"2026-08-26","npm":0,"name":"dsh-repeat-stop","owner":"173787247","short":"dsh-repeat-stop","slug":"173787247/dsh-repeat-stop","desc":"在可配置次数后硬拦截连续相同的工具调用，避免 Agent 原地空转。","cmd":"dsh plugin --profile web add github:173787247/dsh-repeat-stop","href":"/zh/p/173787247/dsh-repeat-stop/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":2,"added":"2026-08-16","npm":0,"name":"dsh-permissions","owner":"940842546","short":"dsh-permissions","slug":"940842546/dsh-permissions","desc":"Claude Code 风格权限规则引擎：hard/deny/ask/allow 四级规则（hard 高于全访问、不可豁免）、workspace 作用域、通配符路径保护、可视化草稿式编辑器，规则持久化于 settings.yaml。","cmd":"dsh plugin --profile web add github:940842546/dsh-permissions","href":"/zh/p/940842546/dsh-permissions/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":2,"added":"2026-08-23","npm":0,"name":"dsh-guardwall","owner":"iiiweiii","short":"dsh-guardwall","slug":"iiiweiii/dsh-guardwall","desc":"在安装前体检本地、npm 与 GitHub 插件源码，运行时拦截命中配置阈值的高风险工具调用，审计输出中的密钥模式，并写入 HMAC 链式本地审计日志。","cmd":"dsh plugin --profile web add github:iiiweiii/dsh-guardwall","href":"/zh/p/iiiweiii/dsh-guardwall/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":2,"added":"2026-09-20","npm":0,"name":"dsh-action-outbox","owner":"JimChen-g","short":"dsh-action-outbox","slug":"JimChen-g/dsh-action-outbox","desc":"暂存精确的 DSH 工具调用而不执行，在持久化批量审查收件箱中展示完整规范参数；编辑或重启后审批失效，仅允许携带匹配 SHA-256 摘要与一次性 nonce 的批次通过 DSH 正常工具管线提交。","cmd":"dsh plugin --profile web add github:JimChen-g/dsh-action-outbox","href":"/zh/p/JimChen-g/dsh-action-outbox/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":2,"added":"2026-08-27","npm":0,"name":"dsh-guardrail","owner":"jypjypjypjyp","short":"dsh-guardrail","slug":"jypjypjypjyp/dsh-guardrail","desc":"对 agent 工具调用输入参数做字符串匹配，命中危险行为则拦截（deny）或放行但注入警告（warn），附规则管理面板。","cmd":"dsh plugin --profile web add github:jypjypjypjyp/dsh-guardrail","href":"/zh/p/jypjypjypjyp/dsh-guardrail/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":2,"added":"2026-08-13","npm":0,"name":"sandbox-nono","owner":"omdsh-dev","short":"sandbox-nono","slug":"omdsh-dev/sandbox-nono","desc":"nono 沙盒支持。","cmd":"dsh plugin --profile web add github:omdsh-dev/sandbox-nono","href":"/zh/p/omdsh-dev/sandbox-nono/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":2,"added":"2026-08-17","npm":0,"name":"dsh-cve-audit","owner":"SARTHAK2511","short":"dsh-cve-audit","slug":"SARTHAK2511/dsh-cve-audit","desc":"面向你自己项目依赖（npm/pip/go）的实时 CVE/供应链审计，基于 OSV.dev，提供 `cve_audit` 工具，并支持在 lockfile 变化时自动重新扫描。","cmd":"dsh plugin --profile web add github:SARTHAK2511/dsh-cve-audit","href":"/zh/p/SARTHAK2511/dsh-cve-audit/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":2,"added":"2026-09-22","npm":0,"name":"kiss_law-dsh","owner":"Shaky77","short":"KISS_Law-DSH","slug":"Shaky77/KISS_Law-DSH","desc":"唯稳律（KISS's Law）英文版：业界首个且唯一的领域无关白箱因果裁决中间件。与领域特定的因果推断工具（统计/经济/机器学习）或「需提供因果证据」的代理防火墙不同，它在执行前对*每个*工具调用沿确定性结构因果链（R->S->D->H->M）裁决——适用任意领域，无需训练或按领域调参。拦截破坏性与凭据文件操作、对反复越界升级止损、故障环节切断至修复验证、不可审计执行给出风险判定；纯本地运行、零 API 成本。","cmd":"dsh plugin --profile web add github:Shaky77/KISS_Law-DSH","href":"/zh/p/Shaky77/KISS_Law-DSH/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":2,"added":"2026-08-25","npm":0,"name":"dsh-full-with-approval","owner":"zjuhbh","short":"dsh-full-with-approval","slug":"zjuhbh/dsh-full-with-approval","desc":"dsh 第四个权限预设：进程全权限（GPU 可用），同时工作区外与受保护文件（.git/**、.env*）的写入逐次向用户审批；纯插件实现，零核心改动。","cmd":"dsh plugin --profile web add github:zjuhbh/dsh-full-with-approval","href":"/zh/p/zjuhbh/dsh-full-with-approval/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-30","npm":0,"name":"dsh-tool-budget","owner":"173787247","short":"dsh-tool-budget","slug":"173787247/dsh-tool-budget","desc":"在达到可配置的会话级工具调用次数上限后，硬拦截后续工具调用。","cmd":"dsh plugin --profile web add github:173787247/dsh-tool-budget","href":"/zh/p/173787247/dsh-tool-budget/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-19","npm":0,"name":"dsh-perm-guard","owner":"a903067276-rgb","short":"dsh-perm-guard","slug":"a903067276-rgb/dsh-perm-guard","desc":"自动审批权限守卫：介于 workspace-write 与 danger-full-access 之间的中间档——信任目录内安全操作自动放行，危险操作一律人工确认；11 个分类开关可调，自带审计记录。","cmd":"dsh plugin --profile web add github:a903067276-rgb/dsh-perm-guard","href":"/zh/p/a903067276-rgb/dsh-perm-guard/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-09-19","npm":0,"name":"dsh-auto-review","owner":"accpowered","short":"dsh-auto-review","slug":"accpowered/dsh-auto-review","desc":"沙箱越权审批的 LLM 应答器：先过确定性正则过滤，再交给干净上下文的审核模型；拿不准才转人工。需要随附的核心补丁。","cmd":"dsh plugin --profile web add github:accpowered/dsh-auto-review","href":"/zh/p/accpowered/dsh-auto-review/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-09-19","npm":0,"name":"dsh-credential-manager","owner":"accpowered","short":"dsh-credential-manager","slug":"accpowered/dsh-credential-manager","desc":"具名凭据按引用使用：秘密值在「设置 → 凭据」页录入，按次注入 shell 执行环境的 DSH_CM_* 变量而不打印进对话，credential_read 是文档化的最后手段。","cmd":"dsh plugin --profile web add github:accpowered/dsh-credential-manager","href":"/zh/p/accpowered/dsh-credential-manager/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-27","npm":0,"name":"dsh-llm-approve-for-me","owner":"alaxrpg","short":"dsh-llm-approve-for-me","slug":"alaxrpg/dsh-llm-approve-for-me","desc":"使用隔离的 LLM 审查来批准或拒绝 DSH 沙箱权限请求。","cmd":"dsh plugin --profile web add github:alaxrpg/dsh-llm-approve-for-me","href":"/zh/p/alaxrpg/dsh-llm-approve-for-me/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-18","npm":0,"name":"dsh-auto-reviewer","owner":"AntaresCorn","short":"dsh-auto-reviewer","slug":"AntaresCorn/dsh-auto-reviewer","desc":"Codex 风格自动审查权限模式：新增 auto-review 权限档，自动放行安全沙箱提权，危险或模糊操作转人工确认，未确认的致命操作直接拒绝。","cmd":"dsh plugin --profile web add github:AntaresCorn/dsh-auto-reviewer","href":"/zh/p/AntaresCorn/dsh-auto-reviewer/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-14","npm":0,"name":"dsh-turn-approval","owner":"arrow949","short":"dsh-turn-approval","slug":"arrow949/dsh-turn-approval","desc":"DSH「允许本次任务」临时授权：仅在当前任务内自动放行同类 `danger-full-access` 请求，任务结束自动失效。","cmd":"dsh plugin --profile web add github:arrow949/dsh-turn-approval","href":"/zh/p/arrow949/dsh-turn-approval/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-15","npm":0,"name":"dsh-plugin-sentinel","owner":"BotonJ","short":"dsh-plugin-sentinel","slug":"BotonJ/dsh-plugin-sentinel","desc":"插件安装前静态安全审计：生命周期脚本、动态执行、凭据外传组合特征与 patch 层风险；零依赖，tar 包全程内存解析不落盘。","cmd":"dsh plugin --profile web add github:BotonJ/dsh-plugin-sentinel","href":"/zh/p/BotonJ/dsh-plugin-sentinel/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-14","npm":0,"name":"dsh-mcpguard","owner":"ChenLaoshiYF","short":"dsh-mcpguard","slug":"ChenLaoshiYF/dsh-mcpguard","desc":"扫描 skill 与 MCP 配置中的提示注入、同形字、Unicode 隐形字符、危险 shell 与凭据泄露。","cmd":"dsh plugin --profile web add github:ChenLaoshiYF/dsh-mcpguard","href":"/zh/p/ChenLaoshiYF/dsh-mcpguard/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-17","npm":0,"name":"dsh-plugins#dsh-approve-for-me","owner":"DamonKoy","short":"dsh-plugins#dsh-approve-for-me","slug":"DamonKoy/dsh-plugins--packages-dsh-approve-for-me","desc":"自动化审批审核：只读工具自动放行、危险命令自动拒绝，策略引擎 fail-closed。","cmd":"dsh plugin --profile web add github:DamonKoy/dsh-plugins#path:/packages/dsh-approve-for-me","href":"/zh/p/DamonKoy/dsh-plugins--packages-dsh-approve-for-me/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-17","npm":0,"name":"dsh-plugins#dsh-secret-redactor","owner":"DamonKoy","short":"dsh-plugins#dsh-secret-redactor","slug":"DamonKoy/dsh-plugins--packages-dsh-secret-redactor","desc":"工具结果敏感信息自动脱敏：模型看到前掩码 API key / token / JWT / 私钥与配置密钥。","cmd":"dsh plugin --profile web add github:DamonKoy/dsh-plugins#path:/packages/dsh-secret-redactor","href":"/zh/p/DamonKoy/dsh-plugins--packages-dsh-secret-redactor/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-09-21","npm":0,"name":"dsh-allow","owner":"DWJZ","short":"dsh-allow","slug":"DWJZ/dsh-allow","desc":"按路径与能力（read / write / create / delete / execute）授予 shell 调用的文件权限，而不是按命令名判断。命令行的文件效果由解析得出，缺哪个能力就出审批卡片而不是一律拒绝，同一套规则还会编译成进程、它的子进程、以及命令行根本没露出来的代码共同运行其下的 macOS Seatbelt profile。会话里的「审批」标签页把审计日志读回来，显示每次判定是规则、自动复核还是人拍的板。","cmd":"dsh plugin --profile web add github:DWJZ/dsh-allow","href":"/zh/p/DWJZ/dsh-allow/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-09-13","npm":0,"name":"dsh-dsml-artifact-guard","owner":"GooDAnDReaDY","short":"dsh-dsml-artifact-guard","slug":"GooDAnDReaDY/dsh-dsml-artifact-guard","desc":"清理模型文本流中泄漏的 DeepSeek DSML 闭合标签。","cmd":"dsh plugin --profile web add github:GooDAnDReaDY/dsh-dsml-artifact-guard","href":"/zh/p/GooDAnDReaDY/dsh-dsml-artifact-guard/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-16","npm":0,"name":"safety-net","owner":"JohnXu22786","short":"safety-net","slug":"JohnXu22786/safety-net","desc":"dsh 破坏性命令拦截闸门：解析 shell 语义、依据 41 条内置规则判定风险，将 rm -rf、git reset --hard、git push --force 等不可逆命令挡在确认关卡之前。","cmd":"dsh plugin --profile web add github:JohnXu22786/safety-net","href":"/zh/p/JohnXu22786/safety-net/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-16","npm":0,"name":"secret-guard","owner":"JohnXu22786","short":"secret-guard","slug":"JohnXu22786/secret-guard","desc":"拦截 agent 对敏感文件（.env、凭据、密钥材料）的读写，对工具结果中泄露的机密形状内容做掩码兜底，记录审计日志，并提供永不输出原始值的 sg_* 安全检查工具。","cmd":"dsh plugin --profile web add github:JohnXu22786/secret-guard","href":"/zh/p/JohnXu22786/secret-guard/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-19","npm":0,"name":"faultseed#dsh","owner":"JW53222","short":"faultseed#dsh","slug":"JW53222/faultseed--adapters-dsh","desc":"工具流水线上的诚实性护栏：阻止编码 agent 弱化测试、吞掉错误、用桩替换类型检查或通过 shell 删除测试——九个确定性 hook，每个都配有植入失败的测试，证明该护栏确实会触发。","cmd":"dsh plugin --profile web add github:JW53222/faultseed#path:/adapters/dsh","href":"/zh/p/JW53222/faultseed--adapters-dsh/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-14","npm":0,"name":"dsh-fleet-audit","owner":"LeslieWylie","short":"dsh-fleet-audit","slug":"LeslieWylie/dsh-fleet-audit","desc":"只读的 agent 机群凭据卫生审计：检查凭据文件权限、git remote 内嵌凭据（输出脱敏）与 provider token 字面量计数；零依赖、确定性。","cmd":"dsh plugin --profile web add github:LeslieWylie/dsh-fleet-audit","href":"/zh/p/LeslieWylie/dsh-fleet-audit/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-27","npm":0,"name":"dsh-hawkeye-scan#npm","owner":"liuqingman","short":"dsh-hawkeye-scan#npm","slug":"liuqingman/dsh-hawkeye-scan--npm","desc":"AI 驱动的源代码安全扫描工作台：5 个模型工具（start/finding/status/report/list）、/hawkeye Web UI 和 JSON/Markdown/HTML 漏洞报告；零依赖 Cordis 插件，可作 agent preset 或 npm 包安装。","cmd":"dsh plugin --profile web add github:liuqingman/dsh-hawkeye-scan#path:/npm","href":"/zh/p/liuqingman/dsh-hawkeye-scan--npm/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-14","npm":0,"name":"dsh-guardian","owner":"lonelymoon87","short":"dsh-guardian","slug":"lonelymoon87/dsh-guardian","desc":"增加危险操作策略检查、输出脱敏和安全审查工作流。","cmd":"dsh plugin --profile web add github:lonelymoon87/dsh-guardian","href":"/zh/p/lonelymoon87/dsh-guardian/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-09-22","npm":0,"name":"dsh-approval-explain","owner":"Martlet-Tech","short":"dsh-approval-explain","slug":"Martlet-Tech/dsh-approval-explain","desc":"在审批卡片上加一个「解释」按钮：一次模型调用返回固定三行解读——做什么、读写改了什么、是否安全（风险等级加一句理由）。同时补上 `write`/`edit` 类调用详情区留白的问题——官方渲染器只读 `command` 字段，那两类调用没有该字段。","cmd":"dsh plugin --profile web add github:Martlet-Tech/dsh-approval-explain","href":"/zh/p/Martlet-Tech/dsh-approval-explain/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-28","npm":0,"name":"dsh-plugin-trustlens","owner":"Mengshang-spec","short":"dsh-plugin-trustlens","slug":"Mengshang-spec/dsh-plugin-trustlens","desc":"只读 DSH 插件审查器：静态扫描、当前会话模型审查和启用前确认。","cmd":"dsh plugin --profile web add github:Mengshang-spec/dsh-plugin-trustlens","href":"/zh/p/Mengshang-spec/dsh-plugin-trustlens/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-13","npm":0,"name":"sandbox-mxc","owner":"omdsh-dev","short":"sandbox-mxc","slug":"omdsh-dev/sandbox-mxc","desc":"微软跨平台沙盒支持。","cmd":"dsh plugin --profile web add github:omdsh-dev/sandbox-mxc","href":"/zh/p/omdsh-dev/sandbox-mxc/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-31","npm":0,"name":"dsh-prompt-antivirus","owner":"QinpanWan","short":"dsh-prompt-antivirus","slug":"QinpanWan/dsh-prompt-antivirus","desc":"全局提示注入 / 上下文病毒防御：扫描工具参数、工具结果、进模型前消息与出站流；隔离/阻断/监控三模式、金丝雀陷阱、可演进磁盘签名库（学习/导入/导出）。","cmd":"dsh plugin --profile web add github:QinpanWan/dsh-prompt-antivirus","href":"/zh/p/QinpanWan/dsh-prompt-antivirus/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-15","npm":0,"name":"dsh-egress-guard","owner":"tancheng33","short":"dsh-egress-guard","slug":"tancheng33/dsh-egress-guard","desc":"工具管线上的运行时安全网关：拦截出站白名单之外的主机调用，在 canonical value（而非仅渲染内容）层面脱敏结果中的凭据，每个决策写入 JSONL 审计日志；默认仅监控不拦截。","cmd":"dsh plugin --profile web add github:tancheng33/dsh-egress-guard","href":"/zh/p/tancheng33/dsh-egress-guard/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-24","npm":0,"name":"dsh-plugin-guard","owner":"taxueseek","short":"dsh-plugin-guard","slug":"taxueseek/dsh-plugin-guard","desc":"DSH 插件的静态安全闸门与诊所：安装前静态审计、安装后哈希与能力锁定、本机指纹库与 GitHub dsh-plugin 主题的同类搜索、机械式剥离清理；永不执行目标插件。","cmd":"dsh plugin --profile web add github:taxueseek/dsh-plugin-guard","href":"/zh/p/taxueseek/dsh-plugin-guard/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-27","npm":0,"name":"dsh-feishu-channel","owner":"WyattJHayes","short":"dsh-feishu-channel","slug":"WyattJHayes/dsh-feishu-channel","desc":"面向安全的 DeepSeek Harness 飞书通道：提供白名单远程 Agent 访问、工作区路径与符号链接边界校验、风险分级审批、会话隔离、日志脱敏和有界消息队列。","cmd":"dsh plugin --profile web add github:WyattJHayes/dsh-feishu-channel","href":"/zh/p/WyattJHayes/dsh-feishu-channel/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-27","npm":0,"name":"dsh-full-access-switch","owner":"xtd1145","short":"dsh-full-access-switch","slug":"xtd1145/dsh-full-access-switch","desc":"给 DeepSeek Harness 加 Full access 一次性开关：新工作区与新对话默认 danger-full-access 并跳过逐个确认；可作为 dsh bundle 安装，也可用脚本打补丁。","cmd":"dsh plugin --profile web add github:xtd1145/dsh-full-access-switch","href":"/zh/p/xtd1145/dsh-full-access-switch/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-09-21","npm":0,"name":"dsh-file-shield","owner":"Yazzyk","short":"dsh-file-shield","slug":"Yazzyk/dsh-file-shield","desc":"屏蔽 agent 对指定文件或目录的读取、搜索、写入与编辑，使其内容不进入对话——含敏感词的文件也在其中，避免它们的文字让之后的 provider 请求以 400 失败。规则在插件页面上点选。","cmd":"dsh plugin --profile web add github:Yazzyk/dsh-file-shield","href":"/zh/p/Yazzyk/dsh-file-shield/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":1,"added":"2026-08-14","npm":0,"name":"noatmark-dsh-plugin","owner":"ylwl1997","short":"noatmark-dsh-plugin","slug":"ylwl1997/noatmark-dsh-plugin","desc":"文本卫生 dsh 插件：净化不可信文本、扫描隐形字符、清洗 LLM 格式、转义 CSV 公式注入。","cmd":"dsh plugin --profile web add github:ylwl1997/noatmark-dsh-plugin","href":"/zh/p/ylwl1997/noatmark-dsh-plugin/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-08-17","npm":0,"name":"dsh-gov","owner":"863683348","short":"dsh-gov","slug":"863683348/dsh-gov","desc":"Agent 治理套件：基于策略的工具门禁（allow/deny/ask，支持通配符与优先级）、结构化 JSONL 审计日志、基于宿主 token 计量的按 agent 配额，状态存于 $DSH_HOME/gov。","cmd":"dsh plugin --profile web add github:863683348/dsh-gov","href":"/zh/p/863683348/dsh-gov/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-09-11","npm":0,"name":"dsh-workspace-tools","owner":"AHIOSUZ","short":"dsh-workspace-tools","slug":"AHIOSUZ/dsh-workspace-tools","desc":"按工作区规则为新建根会话自动应用 Agent 预设与权限预设（设置 - 工作区默认设置），仅使用官方扩展点。","cmd":"dsh plugin --profile web add github:AHIOSUZ/dsh-workspace-tools","href":"/zh/p/AHIOSUZ/dsh-workspace-tools/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-09-19","npm":0,"name":"dsh-almazom-approve-escalate","owner":"almazom","short":"dsh-almazom-approve-escalate","slug":"almazom/dsh-almazom-approve-escalate","desc":"审批卡片上的「批准并升级」一键操作：既应答当前待批请求，又把当前会话切换到指定的权限预设。","cmd":"dsh plugin --profile web add github:almazom/dsh-almazom-approve-escalate","href":"/zh/p/almazom/dsh-almazom-approve-escalate/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-09-18","npm":0,"name":"dsh-privacy-guard","owner":"amwangfan","short":"dsh-privacy-guard","slug":"amwangfan/dsh-privacy-guard","desc":"DeepSeek Harness 本地凭据脱敏网关的控制面板：网关与小模型健康状态、审计指标、泄密探测沙箱、豁免白名单、加密密钥管理、凭据保护模型入口与部署控制。","cmd":"dsh plugin --profile web add github:amwangfan/dsh-privacy-guard","href":"/zh/p/amwangfan/dsh-privacy-guard/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-09-18","npm":0,"name":"dsh-sandbox-arg-guard","owner":"apex-mochen","short":"dsh-sandbox-arg-guard","slug":"apex-mochen/dsh-sandbox-arg-guard","desc":"让「同级或更窄的 sandbox_permissions」不再让工具调用直接失败。会升级的工具（pwsh、bash、write、edit）都广告完整的 sandbox_permissions 枚举，但 DSH 只接受严格更宽于当前生效级别的请求——其源码自称这是「deliberately not a schema constraint」。于是反射式带上该参数的模型往往填它已经在的那个级别，调用在执行前就死掉：\"sandbox escalation to \\\"workspace-write\\\" is not strictly wider than this call's current \\\"workspace-write\\\" mode\"，某些模型还会为此烧掉一整轮重试。本插件只注册一个 tools/execute waterfall 监听器，且仅在那一条文档化拒绝上、且参数里确实带了升级字段时，把同一个调用去掉该参数重投一次。安全性由 DSH 自己的文档保证：拒绝发生在任何执行之前（\"nothing has run\"），且改过的参数无法再次匹配，因此重投在结构上不成环。已端到端复现并验证——改造前 isError 为 true 且命令从未执行；改造后拿到命令的真实输出、isError 为 false，会话里只有一个 tool/call 与一个 tool/result。零依赖。","cmd":"dsh plugin --profile web add github:apex-mochen/dsh-sandbox-arg-guard","href":"/zh/p/apex-mochen/dsh-sandbox-arg-guard/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-08-30","npm":0,"name":"dsh-plugin-guard","owner":"DingZhiQi5596","short":"dsh-plugin-guard","slug":"DingZhiQi5596/dsh-plugin-guard","desc":"DSH Desktop 插件安全防护：崩溃后自我修复 + 8 项核心安全检查（另有 2 项可选：深度组合校验、业务冒烟），写完插件自动提示。非商业源可用。","cmd":"dsh plugin --profile web add github:DingZhiQi5596/dsh-plugin-guard","href":"/zh/p/DingZhiQi5596/dsh-plugin-guard/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-09-22","npm":0,"name":"dsh-approval-gate","owner":"IamNewHands","short":"dsh-approval-gate","slug":"IamNewHands/dsh-approval-gate","desc":"dsh-approval-gate 的维护中 fork。判定器不可用时，确认次数已达阈值的中立操作直接自动放行，不再重复弹人工审批；审批说明由真实的沙箱模式、命令与路径生成中文。另含凭据外泄与系统路径销毁的确定性硬拒、判定输入脱敏、判定模型候选链、带操作指纹的放行规则，以及可查看 unified diff 与一键撤销的审批视图。","cmd":"dsh plugin --profile web add github:IamNewHands/dsh-approval-gate","href":"/zh/p/IamNewHands/dsh-approval-gate/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-09-09","npm":0,"name":"dsh-risk-gate","owner":"leetom314","short":"dsh-risk-gate","slug":"leetom314/dsh-risk-gate","desc":"语义风险分级与渐进授权：把工具调用分为安全／有风险／红线三档，不可逆操作前先询问，只对「已批准且曾成功」的签名自动放行。","cmd":"dsh plugin --profile web add github:leetom314/dsh-risk-gate","href":"/zh/p/leetom314/dsh-risk-gate/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-08-29","npm":0,"name":"dsh-edit-guardian","owner":"LWLAymh","short":"dsh-edit-guardian","slug":"LWLAymh/dsh-edit-guardian","desc":"文件修改 diff 栏与保留/撤销汇总，以及对 bash/pwsh 危险命令的审批与标红。","cmd":"dsh plugin --profile web add github:LWLAymh/dsh-edit-guardian","href":"/zh/p/LWLAymh/dsh-edit-guardian/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-09-03","npm":0,"name":"dsh-safe-delete","owner":"NattoCB","short":"dsh-safe-delete","slug":"NattoCB/dsh-safe-delete","desc":"工具守卫将 agent 执行的 rm 目标移入 macOS 废纸篓而非直接删除，shell 感知词法器覆盖复合与伪装命令；设置页通用设置中可随时关闭。","cmd":"dsh plugin --profile web add github:NattoCB/dsh-safe-delete","href":"/zh/p/NattoCB/dsh-safe-delete/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-09-24","npm":0,"name":"dsh-keychain-credentials","owner":"nengong-ai","short":"dsh-keychain-credentials","slug":"nengong-ai/dsh-keychain-credentials","desc":"纯 JavaScript 实现的 macOS Keychain 凭据提供器，替换 DeepSeek Harness 的明文 .credentials.yaml 存储，完整支持 refs 和 records，无需原生构建、代码签名或 Xcode。","cmd":"dsh plugin --profile web add github:nengong-ai/dsh-keychain-credentials","href":"/zh/p/nengong-ai/dsh-keychain-credentials/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-09-05","npm":0,"name":"dsh-security-guard","owner":"ruanhaodong-tt","short":"dsh-security-guard","slug":"ruanhaodong-tt/dsh-security-guard","desc":"DSH 运行时安全守卫：配置加载导入约束、HTTP Host 头校验、附带 VM 沙箱逃逸源码补丁（4 个 CVE）。AI 辅助制作。","cmd":"dsh plugin --profile web add github:ruanhaodong-tt/dsh-security-guard","href":"/zh/p/ruanhaodong-tt/dsh-security-guard/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-08-18","npm":0,"name":"dsh-taintguard","owner":"sashankh","short":"dsh-taintguard","slug":"sashankh/dsh-taintguard","desc":"当工具结果包含不可信内容时将代理标记为已污染，对随后的高权限调用进行拦截，并在所有模式下拒绝将凭据传递给可联网的工具。","cmd":"dsh plugin --profile web add github:sashankh/dsh-taintguard","href":"/zh/p/sashankh/dsh-taintguard/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-09-18","npm":0,"name":"dsh-auto-pass","owner":"sujingkpo","short":"dsh-auto-pass","slug":"sujingkpo/dsh-auto-pass","desc":"延续 simon300000/dsh-auto 的 DSH WebUI 自动审批权限档位：每次审批只走一次单轮模型审查、不再起审查子代理，只自动放行审查通过的动作、其余全部转回人工审批；并会把用户确认过的决定记成项目级与全局级的允许/拒绝名单，右侧栏另有审批时间线。","cmd":"dsh plugin --profile web add github:sujingkpo/dsh-auto-pass","href":"/zh/p/sujingkpo/dsh-auto-pass/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-08-16","npm":0,"name":"dsh-code-runtime-container","owner":"tancheng33","short":"dsh-code-runtime-container","slug":"tancheng33/dsh-code-runtime-container","desc":"`ctx.codeRuntime` seam 的容器隔离后端：每个 Code Mode 程序跑在全新容器里，无网络、根文件系统只读、丢弃全部 capability，内存/CPU/进程数上限由内核强制。","cmd":"dsh plugin --profile web add github:tancheng33/dsh-code-runtime-container","href":"/zh/p/tancheng33/dsh-code-runtime-container/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-08-16","npm":0,"name":"dsh-credentials-vault","owner":"tancheng33","short":"dsh-credentials-vault","slug":"tancheng33/dsh-credentials-vault","desc":"凭证 seam 的 HashiCorp Vault 后端：支持 KV v2/v1、AppRole 机器认证、逐次操作读取（轮换无需重启）与 compare-and-swap 写入。","cmd":"dsh plugin --profile web add github:tancheng33/dsh-credentials-vault","href":"/zh/p/tancheng33/dsh-credentials-vault/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-08-21","npm":0,"name":"dsh-route-fence-linter","owner":"Vladimir-Kryshchenko","short":"dsh-route-fence-linter","slug":"Vladimir-Kryshchenko/dsh-route-fence-linter","desc":"审计 profile 内所有插件 HTTP 路由的浏览器信任围栏：插件路由在 Web 服务器的最长前缀匹配中优先，因此缺少围栏的路由会被静默暴露；逐条给出文件与行号级别的证据。","cmd":"dsh plugin --profile web add github:Vladimir-Kryshchenko/dsh-route-fence-linter","href":"/zh/p/Vladimir-Kryshchenko/dsh-route-fence-linter/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-09-18","npm":0,"name":"dsh-jumpserver","owner":"we39","short":"dsh-jumpserver","slug":"we39/dsh-jumpserver","desc":"通过对话查询与管理 JumpServer：资产、用户、账号、授权、会话、命令审计、命令过滤与 RBAC 角色，使用 AccessKeyID/AccessKeySecret（HTTP 签名）鉴权。","cmd":"dsh plugin --profile web add github:we39/dsh-jumpserver","href":"/zh/p/we39/dsh-jumpserver/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-09-07","npm":0,"name":"dsh-security-guard","owner":"weisofns","short":"dsh-security-guard","slug":"weisofns/dsh-security-guard","desc":"DSH 插件安全卫士：28 条规则静态扫描、风险评分、白名单/黑名单、本地 Web 仪表盘与 DSH 内风险弹窗。","cmd":"dsh plugin --profile web add github:weisofns/dsh-security-guard","href":"/zh/p/weisofns/dsh-security-guard/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-09-18","npm":0,"name":"dsh-fs-allowlist","owner":"wzn16","short":"dsh-fs-allowlist","slug":"wzn16/dsh-fs-allowlist","desc":"白名单目录写入免审批——write/edit 文件工具直通白名单栅栏，命中白名单的 bash 沙箱升权自动放行，设置页可视化管理目录与开关。","cmd":"dsh plugin --profile web add github:wzn16/dsh-fs-allowlist","href":"/zh/p/wzn16/dsh-fs-allowlist/"},{"cat":"security","tag":"安全与权限","dl":null,"stars":0,"added":"2026-09-09","npm":0,"name":"dsh-permission-matrix","owner":"zhang8019","short":"dsh-permission-matrix","slug":"zhang8019/dsh-permission-matrix","desc":"把 DSH 权限拆成 9 个可选预设（3 种沙箱 × 4 种审批），规则 + LLM 双通道四档风险分级，高风险操作需输入批准密码才放行，附 JSONL 审计日志。","cmd":"dsh plugin --profile web add github:zhang8019/dsh-permission-matrix","href":"/zh/p/zhang8019/dsh-permission-matrix/"}]}