DSH GetDSH Get

Security & Permissions

Browse Security & Permissions plugins for DeepSeek Harness on dshget.com.

97 plugins

Sort

api-relay-audit

819

Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.

Security & Permissionstoby-bridges

dsh-pentest

324

Authorized pentest mode for DeepSeek Harness — exploration chain, assets and findings with a Web view.

Security & Permissionshowmp

dsh-auto-review

120

Second-model auto-review on the approval answerer chain: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default.

Security & PermissionsPerryLink

dsh-redteam-model

118

Authorized-security DSH collection: nine work modes (redteam coordinator, pentest, code audit, binary analysis, attack-defense, AV evasion, incident response, cloud security, CTF solving) and fifteen runtime plugins, managed from a settings page with one-click deploy, install, update and uninstall.

Security & PermissionsSeaOf0

dsh-permission-rules

71

Claude Code-style declarative permission rules: ordered allow/deny/ask YAML rules matching tool names, arguments, workspace paths, and agent identity on the tools/pre-execute waterfall, with full session-log audit, dry-run mode, and hot reload.

Security & PermissionsPerryLink

dsh-secure-audit

65

Read-only security and compliance plugin for DeepSeek Harness: prompt-injection detection, Chinese-PII redaction, and a local configuration audit with redacted, reproducible reports.

Security & PermissionsPensiveFei

dsh-remote

51

Remote access & authentication for DeepSeek Harness web UI: account/password login gate, MFA (TOTP), signed session cookies, role-based access, in-browser directory picker, account management settings, fully localized in English and Chinese.

Security & Permissionsxgone

dsh-passwords

34

Turns DeepSeek Harness into a server-grade multi-tenant platform: remote access + auto HTTPS, subuser permissions & token/daily quotas, sandbox enforcement, encrypted auth & audit log.

Security & Permissionsslywalker2006

helm-d#helmd

29

Single-bundle security analysis plugin: bootstrap tool narrowing, a domain router, and 25 reverse-engineering tools covering APK, native binary, protocol, malware and LLM samples with on-demand reference docs.

Security & PermissionsADWMC

dsh-movein-permissions

15

Fine grained per tool permission rules for DSH at the tools/pre-execute gate, deny and ask lists in Claude Code rule syntax (Bash(rm -rf:*), Read(_secrets_), mcp__server__tool), works standalone without migrating.

Security & Permissionssjh9714

dsh-web-startup-auth

14

Replaces the dsh web startup to allow binding 0.0.0.0, gated by username/password login: signed session cookies, /api route protection, an auth tab in the settings panel, and a reset CLI that rotates the signing key to invalidate all sessions.

Security & PermissionsGDWhisper

dsh-security-audit

13

Local security audit: config, plugin origins, sessions, network exposure — read-only redacted risk report.

Security & Permissionsomdsh-dev

dsh-auto-approve

11

Adds an `auto` permission preset between workspace-write and danger-full-access: a classifier grants routine sandbox escalations once, while dangerous or uncertain requests still go to a human.

Security & PermissionsJiao-XXX

dshscan

10

Security scanner for DSH plugins: static and semantic passes over plugin source, DSH-specific attack-surface rules, npm audit, batch scanning, and an HTML report with per-finding severity and evidence.

Security & Permissionsshaoshi20

dsh-auth-gateway

9

Password + TOTP two-factor authentication gateway for the dsh web UI: every HTTP request and WebSocket upgrade is refused until login, with per-source lockout, global rate limits and one-time backup codes.

Security & Permissionsxbzbing

dsh-webui-auth

9

WebUI authentication enforced at the HTTP/transport layer: four-layer login gate (resources, plugin bundles, /api, WebSocket), server-side sessions with HttpOnly cookies.

Security & PermissionsYuuz12

dsh-approval-llm

8

Model-based permission approval: an approval-request answerer backed by a separate reviewer model.

Security & PermissionsLetter2025

dsh-auth-gate

8

Login gate for the dsh web surface: password or shared-token authentication, session cookies, rate limiting, and a user-management CLI (dsh.bundle manifest since 0.4.1, one-command `dsh plugin add` mounting).

Security & PermissionsTecFancy

upstream-radar

8

Watches DSH and plugin releases, retests exact published artifacts in disposable runners, publishes machine-readable compatibility evidence, and reconciles managed issues after fixes.

Security & PermissionsMicroMilo

cue-skills#cue-omni-reader-guard

7

Hardening guard for mcp__omni__parse in DeepSeek Harness: a tools/pre-execute listener that denies private/reserved host URLs (SSRF), enforces an allow-list or ask (consent), and is fail-closed when allowedRoots is empty.

Security & Permissionssensedeal

dsh-sentinel-scanner

6

Static security scanner for DSH plugins: read-only audit (exec, credentials, exfiltration, obfuscation, install scripts, bundle manifest) with a 0-100 risk score.

Security & PermissionsEligahyu

dsh-approval-gate

5

Risk-gated approval automation for DeepSeek Harness: flash pre-classifies whether a write/command is irreversible — safe operations are auto-approved, dangerous ones are escalated to human approval (fail-safe). File-diff review with one-click revert and session-scoped snapshots (v0.5.1: precise snapshots via tool-call parameter tracing, incl. human-approval cases).

Security & Permissionsmoon09300731

dsh-auto

5

Adds an Auto Approve permission preset to the Web UI, using a fresh restricted Reviewer Agent to allow or deny each approval request.

Security & Permissionssimon300000

dsh-defend

5

Detects prompt-injection, jailbreak, and secret-leak patterns on the agent/pre-step, tools/pre-execute, and tools/post-execute seams with allow/ask/block tiers, sanitized defend/detection audit events, a defend_report tool, and a destructive-delete command guard.

Security & PermissionsPerryLink

dsh-permgate

5

Fine-grained permission gateway: per-category tool-call review (outside-workspace directories, commands, file read/write, subagents, repeated actions) with global & per-project allow/deny exceptions, quick-tool defaults, custom rules, a bilingual approval modal with inline diff details, custom rejection reasons and a sandbox-upgrade flow.

Security & PermissionsMrWeiCodes

dsh-plugin-vetting

5

Vets third-party plugins before you trust them: static scan for malicious patterns (exfiltration, credential access, obfuscation, persistence) and over-privileged path use, transitive-dependency coverage, official-package hash baseline for supply-chain tamper detection, and an optional plugin-tool call gate.

Security & Permissionstruelove-dreamer

dsh-approval-mode

4

Adds an approval-mode toggle next to the permission selector: default approval keeps per-call confirmation, bypass approval auto-approves every tool call while staying in Workspace Write.

Security & PermissionsNEVSTOP-LAB

dsh-auth

4

Caddy forward_auth administrator login for DeepSeek Harness Web, with Argon2id passwords, revocable sessions, bilingual UI, and a native sidebar sign-out action.

Security & Permissionshxy91819

dsh-auto-approval-llm

4

LLM-assisted auto approval with countdown fallback for the Auto permission preset: static rules, risk tiers, breaker and file audit.

Security & Permissionscuddly-guacamole

dsh-guardian

4

Agent security guardrail: intercepts and audits every tool call, requiring human confirmation on sensitive operations.

Security & Permissionscdxiaodong

dsh-pentester

4

PTES-based penetration testing plugin with Root-Orchestrator architecture for DeepSeek Harness.

Security & Permissionsfb0sh

dsh-skill-pack-security

4

Security-audit methodology skill pack plus the plugin_vet supply-chain gate: eight agent skills (secret scan, dependency audit, supply-chain review, prompt-injection review, audit orchestration, threat modeling, vuln intel, incident response) in Chinese and English editions, with an npm provider bundle that mounts the skills and registers the automated plugin_vet pre-install scanner.

Security & PermissionsPerryLink

dsh-verification-receipt

4

Writes local JSONL summaries of per-turn tool counts and coarse verification signals without storing prompts, tool arguments, or result text.

Security & Permissions030611

qiushi-dsh-evidence-audit

4

Appends local hash-chained JSONL receipts for tool results and session events without storing prompts, tool arguments, result text, or raw session IDs.

Security & Permissions030611

sandbox-micro

4

Support for the microsandbox backend.

Security & Permissionsomdsh-dev

dsh-always-require-tools-approval

3

Requires one-shot user approval before configured tools (default bash, pwsh) execute — gated tools pause and ask, everything else delegates, and a missing approval channel fails closed.

Security & PermissionsJ0ss077

View all in category (97) →