All Plugins
Results
-
Listed
Bundle verified
Second-model auto-review on the approval answerer chain: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default.
dsh plugin --profile default add github:PerryLink/dsh-auto-review -
Listed
Bundle verified
Local security audit: config, plugin origins, sessions, network exposure — read-only redacted risk report.
dsh plugin --profile default add github:omdsh-dev/dsh-security-audit -
Listed
Bundle verified
Turns DeepSeek Harness into a server-grade multi-tenant platform: remote access + auto HTTPS, subuser permissions & token/daily quotas, sandbox enforcement, encrypted auth & audit log.
dsh plugin --profile default add github:slywalker2006/dsh-passwords -
Listed
Bundle verified
Claude Code-style declarative permission rules: ordered allow/deny/ask YAML rules matching tool names, arguments, workspace paths, and agent identity on the tools/pre-execute waterfall, with full session-log audit, dry-run mode, and hot reload.
dsh plugin --profile default add github:PerryLink/dsh-permission-rules -
Listed
Bundle verified
Model-based permission approval: an approval-request answerer backed by a separate reviewer model.
dsh plugin --profile default add github:Letter2025/dsh-approval-llm -
Listed
Bundle verified
Always-on dependency security for DSH plugins: tracks exact installed paths, OSV vulnerabilities, npm releases, and breaking-change signals, then routes project evidence to a DSH Agent.
dsh plugin --profile default add github:MicroMilo/upstream-radar -
Listed
Bundle verified
Appends local hash-chained JSONL receipts for tool results and session events without storing prompts, tool arguments, result text, or raw session IDs.
dsh plugin --profile default add github:030611/qiushi-dsh-evidence-audit -
Listed
Bundle verified
Writes local JSONL summaries of per-turn tool counts and coarse verification signals without storing prompts, tool arguments, or result text.
dsh plugin --profile default add github:030611/dsh-verification-receipt -
Listed
Bundle verified
Agent security guardrail: intercepts and audits every tool call, requiring human confirmation on sensitive operations.
dsh plugin --profile default add github:cdxiaodong/dsh-guardian -
Listed
Bundle verified
Redacts supported secret patterns from the `session-telemetry/record` export copy before configured telemetry backends receive it.
dsh plugin --profile default add github:030611/dsh-telemetry-redactor -
Listed
Bundle verified
Support for the nono sandbox backend.
dsh plugin --profile default add github:omdsh-dev/sandbox-nono -
Listed
Bundle verified
Support for the microsandbox backend.
dsh plugin --profile default add github:omdsh-dev/sandbox-micro -
Listed
Bundle verified
Security-audit methodology skill pack plus the plugin_vet supply-chain gate: eight agent skills (secret scan, dependency audit, supply-chain review, prompt-injection review, audit orchestration, threat modeling, vuln intel, incident response) in Chinese and English editions, with an npm provider bundle that mounts the skills and registers the automated plugin_vet pre-install scanner.
dsh plugin --profile default add github:PerryLink/dsh-skill-pack-security -
Listed
Bundle verified
Plugin trust pipeline for DeepSeek Harness: deterministic static scan with verdicts, opt-in runtime guard with honeypot lures, agent audit-protocol skill, and a browser shield status light. Alarm-only, never an enforcer.
dsh plugin --profile default add github:wulun811/dsh-plugin-vet -
Listed
Bundle verified
Login gate for the dsh web surface: password or shared-token authentication, session cookies, rate limiting, and a user-management CLI (dsh.bundle manifest since 0.4.1, one-command `dsh plugin add` mounting).
dsh plugin --profile default add github:TecFancy/dsh-auth-gate -
Listed
Bundle verified
Microsoft cross-platform sandbox support.
dsh plugin --profile default add github:omdsh-dev/sandbox-mxc -
Listed
Bundle verified
Text hygiene as a dsh plugin: sanitize untrusted text, scan invisible characters, clean LLM formatting, and escape CSV formula injection.
dsh plugin --profile default add github:ylwl1997/noatmark-dsh-plugin -
Listed
Bundle verified
Deterministic code security review: 40+ rules, secret entropy detection, staged-diff review, SARIF export, baseline acceptance and SBOM-lite dependency inventory.
dsh plugin --profile default add github:STARDUSTLC666/dsh-code-security -
Listed
Bundle verified
Static and runtime security guard for dsh: rule-based scans for malicious code, prompt injection and token waste, runtime interception of dangerous tool calls, /scan command, plugin_scan tool, web panel, and allowlist.
dsh plugin --profile default add github:bigclawd/dsh-security-guard -
Listed
Bundle verified
Runtime security gate on the tool pipeline: denies calls naming hosts outside an egress allowlist, redacts credentials from results at the canonical value rather than only the rendered content, and appends every decision to a JSONL audit log; ships in monitor-only mode.
dsh plugin --profile default add github:tancheng33/dsh-egress-guard