Security & Permissions Plugins Security & Permissions
52 plugins
Security, policy, and permission controls
52 plugins
Sort: Featured
-
Listed
Bundle verified
Manual approval mode ("Manual Mode" / "Ask Mode").
dsh plugin --profile default add github:ilharp/dsh-tool-approval -
Listed
Bundle verified
Claude Code-style permission rules engine: hard/deny/ask/allow tiers with a hard tier above full access, workspace-scoped rules, wildcard path protection, and a visual staged editor; rules persist in settings.yaml.
dsh plugin --profile default add github:940842546/dsh-permissions -
Listed
Bundle verified
Installation safety gate for DSH plugins: antivirus-style scan of install scripts, permissions, secrets and network callbacks on local directories or npm tarballs, returning a BLOCK/WARN/PASS verdict before "dsh plugin add".
dsh plugin --profile default add github:863683348/dsh-plugin-gate -
Listed
Bundle verified
Static pre-install security auditor for plugin bundles: lifecycle scripts, dynamic execution, credential-exfiltration combos, and patch-layer hazards, with zero dependencies and in-memory tar parsing.
dsh plugin --profile default add github:BotonJ/dsh-plugin-sentinel -
Listed
Bundle verified
Codex-style auto-review permission mode: adds an auto-review preset that auto-approves safe sandbox escalations, asks on risky or ambiguous ones, and rejects critical unconfirmed operations.
dsh plugin --profile default add github:AntaresCorn/dsh-auto-reviewer -
Listed
Bundle verified
Pre-install supply-chain poison scanner for DSH plugins: AST (JS-X-Ray) + deobfuscation + regex heuristics, exits non-zero on findings for CI gating.
dsh plugin --profile default add github:zoahdev/dsh-poison-guard
Frequently Asked QuestionsFAQ
Security, policy, and permission controls
Yes. Combine focused plugins when their responsibilities are clear and their storage or runtime requirements are compatible.
Start with the workflow you need, then compare the tags, tier, install state, and recent activity shown on this category page.