Security & Permissions Plugins Security & Permissions
52 plugins
Security, policy, and permission controls
52 plugins
Sort: Featured
-
Listed
Bundle verified
HashiCorp Vault backend for the credential seam: KV v2/v1, AppRole machine auth, per-operation reads so rotation needs no restart, and compare-and-swap writes.
dsh plugin --profile default add github:tancheng33/dsh-credentials-vault -
Listed
Bundle verified
Live CVE/supply-chain audit for your workspace's own project dependencies (npm/pip/go), backed by OSV.dev, with a `cve_audit` tool plus optional automatic re-scan on lockfile changes.
dsh plugin --profile default add github:SARTHAK2511/dsh-cve-audit -
Listed
Bundle verified
DamonKoy/dsh-plugins#dsh-approve-for-me: Automated approval review: auto-approve read-only tools, auto-deny dangerous commands, fail-closed policy engine. DamonKoy/dsh-plugins#dsh-mcp-client-v2: Enhanced MCP client: paginated tool discovery, non-blocking startup, mcp_tool_search, hand-rolled stdio/streamable-http transports. DamonKoy/dsh-plugins#dsh-memories: Project-scoped persistent key-value memories with set/get/list/delete/search model tools and JSON-file storage. DamonKoy/dsh-plugins#dsh-secret-redactor: Automatic secret redaction in tool results: masks API keys, tokens, JWTs, private keys and configured secrets before the model sees them. DamonKoy/dsh-plugins#dsh-system-proxy: System proxy detection (scutil/env/PAC) with a status tool and a proxy_export bash snippet tool. DamonKoy/dsh-plugins#dsh-usage-cost: Token usage and cost tracking with daily/session budget alerts and a usage_report tool.
dsh plugin --profile default add github:DamonKoy/dsh-plugins#path:/packages/dsh-approve-for-me -
Listed
Bundle verified
Plugin value auditor: pre-install review (source scan + LLM judge) and post-install audit of installed bundles, with model-switch re-audit reminders.
dsh plugin --profile default add github:pengxuding/dsh-plugin-judge
Frequently Asked QuestionsFAQ
Security, policy, and permission controls
Yes. Combine focused plugins when their responsibilities are clear and their storage or runtime requirements are compatible.
Start with the workflow you need, then compare the tags, tier, install state, and recent activity shown on this category page.