Security & Permissions Plugins Security & Permissions
52 plugins
Security, policy, and permission controls
52 plugins
Sort: Featured
-
Listed
Bundle verified
Login gate for the dsh web surface: password or shared-token authentication, session cookies, rate limiting, and a user-management CLI (dsh.bundle manifest since 0.4.1, one-command `dsh plugin add` mounting).
dsh plugin --profile default add github:TecFancy/dsh-auth-gate -
Listed
Bundle verified
Scans skills and MCP configs for prompt injection, homoglyphs, hidden Unicode, dangerous shell, and credential leaks.
dsh plugin --profile default add github:ChenLaoshiYF/dsh-mcpguard -
Listed
Bundle verified
Turn-scoped “Allow for this task” approvals: automatically allow matching `danger-full-access` escalations only for the current task, then expire.
dsh plugin --profile default add github:arrow949/dsh-turn-approval -
Listed
Bundle verified
Microsoft cross-platform sandbox support.
dsh plugin --profile default add github:omdsh-dev/sandbox-mxc -
Listed
Bundle verified
Read-only agent-fleet credential hygiene audit: credential-file permissions, embedded credentials in git remotes (masked in output), and provider token literal counts; zero-dependency and deterministic.
dsh plugin --profile default add github:LeslieWylie/dsh-fleet-audit -
Listed
Bundle verified
Transport-level authentication gate for the DeepSeek Harness Web GUI with server-side sessions, HttpOnly cookies, IP-based login throttling, and an scrypt password CLI.
dsh plugin --profile default add github:SummerSec/dsh-web-auth
Frequently Asked QuestionsFAQ
Security, policy, and permission controls
Yes. Combine focused plugins when their responsibilities are clear and their storage or runtime requirements are compatible.
Start with the workflow you need, then compare the tags, tier, install state, and recent activity shown on this category page.