Security & Permissions Plugins Security & Permissions
52 plugins
Security, policy, and permission controls
52 plugins
Sort: Featured
-
Listed
Bundle verified
Agent security guardrail: intercepts and audits every tool call, requiring human confirmation on sensitive operations.
dsh plugin --profile default add github:cdxiaodong/dsh-guardian -
Listed
Bundle verified
Vets third-party plugins before you trust them: static scan for malicious patterns (exfiltration, credential access, obfuscation, persistence) and over-privileged path use, transitive-dependency coverage, official-package hash baseline for supply-chain tamper detection, and an optional plugin-tool call gate.
dsh plugin --profile default add github:truelove-dreamer/dsh-plugin-vetting -
Listed
Bundle verified
Fine-grained permission gateway: per-category tool-call review (outside-workspace directories, commands, file read/write, subagents, repeated actions) with global & per-project allow/deny exceptions, quick-tool defaults, custom rules, a bilingual approval modal with inline diff details, custom rejection reasons and a sandbox-upgrade flow.
dsh plugin --profile default add github:MrWeiCodes/dsh-permgate -
Listed
Bundle verified
Adds an `auto` permission preset between workspace-write and danger-full-access: a classifier grants routine sandbox escalations once, while dangerous or uncertain requests still go to a human.
dsh plugin --profile default add github:Jiao-XXX/dsh-auto-approve -
Listed
Bundle verified
Adds an Auto Approve permission preset to the Web UI, using a fresh restricted Reviewer Agent to allow or deny each approval request.
dsh plugin --profile default add github:simon300000/dsh-auto -
Listed
Bundle verified
LLM auto-approval for sandbox escalation requests, with presets and a fail-closed fallback.
dsh plugin --profile default add github:SeverusZh/dsh-yolo-mode
Frequently Asked QuestionsFAQ
Security, policy, and permission controls
Yes. Combine focused plugins when their responsibilities are clear and their storage or runtime requirements are compatible.
Start with the workflow you need, then compare the tags, tier, install state, and recent activity shown on this category page.