All Plugins

52 plugins page 2 of 3

Results

  • Listed Bundle verified

    Support for the microsandbox backend.

    dsh plugin --profile default add github:omdsh-dev/sandbox-micro
  • Listed Bundle verified

    Risk-gated approval automation for DeepSeek Harness: flash pre-classifies whether a write/command is irreversible — safe operations are auto-approved, dangerous ones are escalated to human approval (fail-safe).

    dsh plugin --profile default add github:moon09300731/dsh-approval-gate
  • Listed Bundle verified

    Security-audit methodology skill pack plus the plugin_vet supply-chain gate: eight agent skills (secret scan, dependency audit, supply-chain review, prompt-injection review, audit orchestration, threat modeling, vuln intel, incident response) in Chinese and English editions, with an npm provider bundle that mounts the skills and registers the automated plugin_vet pre-install scanner.

    dsh plugin --profile default add github:PerryLink/dsh-skill-pack-security
  • Listed Bundle verified

    Plugin trust pipeline for DeepSeek Harness: deterministic static scan with verdicts, opt-in runtime guard with honeypot lures, agent audit-protocol skill, and a browser shield status light. Alarm-only, never an enforcer.

    dsh plugin --profile default add github:wulun811/dsh-plugin-vet
  • Listed Bundle verified

    Login gate for the dsh web surface: password or shared-token authentication, session cookies, rate limiting, and a user-management CLI (dsh.bundle manifest since 0.4.1, one-command `dsh plugin add` mounting).

    dsh plugin --profile default add github:TecFancy/dsh-auth-gate
  • Listed Bundle verified

    Scans skills and MCP configs for prompt injection, homoglyphs, hidden Unicode, dangerous shell, and credential leaks.

    dsh plugin --profile default add github:ChenLaoshiYF/dsh-mcpguard
  • Listed Bundle verified

    Turn-scoped “Allow for this task” approvals: automatically allow matching `danger-full-access` escalations only for the current task, then expire.

    dsh plugin --profile default add github:arrow949/dsh-turn-approval
  • Listed Bundle verified

    Microsoft cross-platform sandbox support.

    dsh plugin --profile default add github:omdsh-dev/sandbox-mxc
  • Listed Bundle verified

    Read-only agent-fleet credential hygiene audit: credential-file permissions, embedded credentials in git remotes (masked in output), and provider token literal counts; zero-dependency and deterministic.

    dsh plugin --profile default add github:LeslieWylie/dsh-fleet-audit
  • Listed Bundle verified

    Transport-level authentication gate for the DeepSeek Harness Web GUI with server-side sessions, HttpOnly cookies, IP-based login throttling, and an scrypt password CLI.

    dsh plugin --profile default add github:SummerSec/dsh-web-auth
  • Listed Bundle verified

    Rules execution engine for dsh: parses AGENTS.md, hard-blocks rule-violating tool calls, text-based B/D rule auditing, /guard command, version-guard for versioned files, and free-zone support (engine skips free-zone sections).

    dsh plugin --profile default add github:jilian-dsh/dsh-rule-engine
  • Listed Bundle verified

    Text hygiene as a dsh plugin: sanitize untrusted text, scan invisible characters, clean LLM formatting, and escape CSV formula injection.

    dsh plugin --profile default add github:ylwl1997/noatmark-dsh-plugin
  • Listed Bundle verified

    Deterministic code security review: 40+ rules, secret entropy detection, staged-diff review, SARIF export, baseline acceptance and SBOM-lite dependency inventory.

    dsh plugin --profile default add github:STARDUSTLC666/dsh-code-security
  • Listed Bundle verified

    Static and runtime security guard for dsh: rule-based scans for malicious code, prompt injection and token waste, runtime interception of dangerous tool calls, /scan command, plugin_scan tool, web panel, and allowlist.

    dsh plugin --profile default add github:bigclawd/dsh-security-guard
  • Listed Bundle verified

    Runtime security gate on the tool pipeline: denies calls naming hosts outside an egress allowlist, redacts credentials from results at the canonical value rather than only the rendered content, and appends every decision to a JSONL audit log; ships in monitor-only mode.

    dsh plugin --profile default add github:tancheng33/dsh-egress-guard
  • Listed Bundle verified

    Adds dangerous-operation policy checks, output redaction, and a security-review workflow.

    dsh plugin --profile default add github:lonelymoon87/dsh-guardian
  • Listed Bundle verified

    Manual approval mode ("Manual Mode" / "Ask Mode").

    dsh plugin --profile default add github:ilharp/dsh-tool-approval
  • Listed Bundle verified

    Claude Code-style permission rules engine: hard/deny/ask/allow tiers with a hard tier above full access, workspace-scoped rules, wildcard path protection, and a visual staged editor; rules persist in settings.yaml.

    dsh plugin --profile default add github:940842546/dsh-permissions
  • Listed Bundle verified

    Installation safety gate for DSH plugins: antivirus-style scan of install scripts, permissions, secrets and network callbacks on local directories or npm tarballs, returning a BLOCK/WARN/PASS verdict before "dsh plugin add".

    dsh plugin --profile default add github:863683348/dsh-plugin-gate
  • Listed Bundle verified

    Static pre-install security auditor for plugin bundles: lifecycle scripts, dynamic execution, credential-exfiltration combos, and patch-layer hazards, with zero dependencies and in-memory tar parsing.

    dsh plugin --profile default add github:BotonJ/dsh-plugin-sentinel