Security & Permissions Plugins Security & Permissions
52 plugins
Security, policy, and permission controls
52 plugins
Sort: Featured
-
Listed
Bundle verified
A LAN password gate for the Web UI: phones and tablets on the same network log in with a shared key and see the same sessions in real time, with a built-in randomUUID polyfill for plain-HTTP origins.
dsh plugin --profile default add github:x2802490130-prog/dsh-lan-pass -
Listed
Bundle verified
Agent governance suite: policy-based tool gating (allow/deny/ask with wildcards and priorities), a structured JSONL audit trail, and per-agent token quotas against the host token meter, with state under $DSH_HOME/gov.
dsh plugin --profile default add github:863683348/dsh-gov -
Listed
Bundle verified
Blocks agents from reading or writing sensitive files (.env, credentials, key material), masks leaked secret-shaped values in tool results, keeps an audit journal, and exposes safe sg_* inspection tools that never print raw values.
dsh plugin --profile default add github:JohnXu22786/secret-guard -
Listed
Bundle verified
Destructive-command interception gate for dsh: parses shell semantics, judges risk against 41 built-in rules, and holds irreversible rm -rf, git reset --hard, and git push --force style commands at a confirmation gate.
dsh plugin --profile default add github:JohnXu22786/safety-net -
Listed
Bundle verified
Autonomous permission classifier for the auto preset: tool-scoped allow/deny rules, an LLM semantic judge, and git checkpointing for unattended sessions.
dsh plugin --profile default add github:PAKIKNOWLEDGE/dsh-auto-classifier -
Listed
Bundle verified
Container-isolated backend for the `ctx.codeRuntime` seam: each Code Mode program runs in a fresh container with no network, a read-only rootfs, dropped capabilities, and kernel-enforced memory, CPU and pid ceilings.
dsh plugin --profile default add github:tancheng33/dsh-code-runtime-container
Frequently Asked QuestionsFAQ
Security, policy, and permission controls
Yes. Combine focused plugins when their responsibilities are clear and their storage or runtime requirements are compatible.
Start with the workflow you need, then compare the tags, tier, install state, and recent activity shown on this category page.