Security & Permissions Plugins Security & Permissions
52 plugins
Security, policy, and permission controls
52 plugins
Sort: Featured
-
Listed
Bundle verified
Rules execution engine for dsh: parses AGENTS.md, hard-blocks rule-violating tool calls, text-based B/D rule auditing, /guard command, version-guard for versioned files, and free-zone support (engine skips free-zone sections).
dsh plugin --profile default add github:jilian-dsh/dsh-rule-engine -
Listed
Bundle verified
Text hygiene as a dsh plugin: sanitize untrusted text, scan invisible characters, clean LLM formatting, and escape CSV formula injection.
dsh plugin --profile default add github:ylwl1997/noatmark-dsh-plugin -
Listed
Bundle verified
Deterministic code security review: 40+ rules, secret entropy detection, staged-diff review, SARIF export, baseline acceptance and SBOM-lite dependency inventory.
dsh plugin --profile default add github:STARDUSTLC666/dsh-code-security -
Listed
Bundle verified
Static and runtime security guard for dsh: rule-based scans for malicious code, prompt injection and token waste, runtime interception of dangerous tool calls, /scan command, plugin_scan tool, web panel, and allowlist.
dsh plugin --profile default add github:bigclawd/dsh-security-guard -
Listed
Bundle verified
Runtime security gate on the tool pipeline: denies calls naming hosts outside an egress allowlist, redacts credentials from results at the canonical value rather than only the rendered content, and appends every decision to a JSONL audit log; ships in monitor-only mode.
dsh plugin --profile default add github:tancheng33/dsh-egress-guard -
Listed
Bundle verified
Adds dangerous-operation policy checks, output redaction, and a security-review workflow.
dsh plugin --profile default add github:lonelymoon87/dsh-guardian
Frequently Asked QuestionsFAQ
Security, policy, and permission controls
Yes. Combine focused plugins when their responsibilities are clear and their storage or runtime requirements are compatible.
Start with the workflow you need, then compare the tags, tier, install state, and recent activity shown on this category page.