security 81
Read-only security & compliance toolkit for DeepSeek Harness: prompt-injection detection (rule engine with a pluggable model classifier), Chinese-PII and structured-JSON redaction, and a local configuration security audit that emits redacted, reproducible
dsh plugin add dsh-secure-auditDSH RedTeam 模式:一句话拉起红队作战智能体(资产测绘 / 攻击链 / 得分目标 / 报告 / POC 知识库),含六个角色、23 个原生技能、常驻右侧控制台与一键自动更新
dsh plugin add dsh-redteam-modeAuto mode for DeepSeek Harness (dsh): an Auto entry in the Permissions selector whose approval prompts are answered by OpenGuardrails policy instead of a human — plus the full OGR guard engine underneath. No core changes.
dsh plugin add @openguardrails/dsh-auto-modeMinimal Root-Orchestrator PTES pentesting plugin for DeepSeek Harness
dsh plugin add dsh-pentesterPrompt-injection, jailbreak, and secret-leak detection with allow/ask/block interception for DeepSeek Harness: an Aho-Corasick pattern engine and heuristics ported from the Prompt-Injection-Payloads, Jailbreak-Detector, and Secret-Key-Leaker-Detect assets
dsh plugin add dsh-defendProvider plugin for dsh-skill-pack-security: registers the pack's skills/ (zh) or skills-en/ (en) edition on ctx.skills AND the plugin_vet supply-chain gate tool on ctx.tools (license/SBOM/commit-lock/malware scans + five-dimension risk card). Ships both
dsh plugin add @perrylink/dsh-skill-pack-security-provider为 DeepSeek Harness 增加介于 Workspace Write 与 Full access 之间的自动批准权限档:例行沙箱升级由分类模型一次性放行,危险或不确定的操作仍转人工审批。An auto-approval permission preset for DeepSeek Harness between workspace-write and full access: routine sandbox escalations are granted once by a classifier
dsh plugin add dsh-auto-approveLogin gate for DeepSeek Harness (dsh) web instances: password or shared-token sign-in, optional TOTP two-factor, session cookies, rate limiting, self-service password change and a user-management CLI
dsh plugin add dsh-auth-gatePII masking middleware for DeepSeek Harness: regex-detect and replace phones, emails, ID cards, bank cards, keys, and (opt-in) IPs with placeholders before they reach the model, keep the restore table host-side (memory plus a controlled storage domain, ne
dsh plugin add dsh-mask🛡️ 给 DeepSeek Harness 插件拍 X 光 —— DSH 插件安全体检与健康检查。静态启发式审计:代码执行、凭据访问、外传端点、混淆、安装脚本、bundle 清单合规,输出 0-100 风险分与裁决。Plugin security & health scanner for DeepSeek Harness: heuristic static audit (code execution, credential access, exfiltration, obfuscation, insta
dsh plugin add deepseek-harness-sentinelAudit deepseek-harness (DSH) plugins before install, guard them at runtime. Static verdict + pre-install audit protocol; supply-chain checks (typosquat, OSV); exfiltration & ransomware detection, honeypot canaries, integrity baseline. Alarm-only; blocks c
dsh plugin add @jieai/dsh-plugin-vet装插件前,先体检:第三方插件 = 进程内全权限代码,这个工具让'盲装'变成'知情安装'——恶意模式、越权路径、未检查依赖,一目了然。Static heuristic vetting for third-party DeepSeek Harness plugins: exfiltration, credential access, over-privileged paths, unvetted dependencies.
dsh plugin add dsh-plugin-vettingSecurity audit plugin for DeepSeek Harness: static permission profiling and a runtime sentinel for third-party plugins
dsh plugin add dsh-plugin-auditAgent-decided approvals for DeepSeek Harness: an 自动审批 permission mode where every sandbox escalation is judged automatically by an LLM (default judge: one direct LLM call with no subagent session; optional isolated judge subagent) plus an independent 自动审查
dsh plugin add @duke-dsh-plugins/dsh-agent-approvalGitee/GitHub AI 员工:issue 里 @ 机器人自动开发并提 PR;v1.2 新增代码安全扫描——配置仓库地址后按内置/自定义提示词扫描漏洞,去重后提交 issue。v1.3 适配 DSH 0.2.x:配置卡片迁移到侧栏「插件」页 plugins.item slot。An issue-driven AI developer for DeepSeek Harness (Gitee & GitHub) with optional static security scanning (dedup
dsh plugin add gitee-ai-employeeDSH 规则执行引擎 v3:容器解析 AGENTS.md + 理解器 + 匹配机 + 执行框架
dsh plugin add dsh-rule-enginePlugin insight center — one answer to '哪些值得装': requirement matching (plugin_guide), environment recipes (recipe), health scoring (plugin_rank), static security scanning (plugin_audit), and a single install verdict (plugin_verdict)
dsh plugin add dsh-insightSecret-scrubbing guard plugin: irreversible regex redaction of secrets before session-log persistence and model requests
dsh plugin add dsh-secret-scrubStatic bundle form of the DSH plugin-install security gate: reviews cordis_define/cordis_run with a fail-safe policy, plus review/audit tools and a browser approval popup (agree / agree+whitelist / reject; agree+whitelist writes the plugin family into tru
dsh plugin add dsh-plugin-security-reviewFail-closed LLM-assisted approval reviewer for DeepSeek Harness
dsh plugin add dsh-smart-approvalDeepSeek Harness community Bundle for the skill-security-guard static scanner
dsh plugin add dsh-skill-security-guardDeepSeek Harness plugin for SecurStack security scans, policy checks, doctor diagnostics, and JSON CLI results.
dsh plugin add @securstack/dsh-plugin面向多 Agent、多模型、多 Provider 的 AI Coding Agent 安全配置中心
dsh plugin add agentreveal保险区 Vault Wall — 让 DeepSeek Harness 无法感知、无法触碰用户指定敏感路径的隔离墙插件(隔离墙 + 人在回路审批 + 执行后验证 + 循环纠正 + 可回滚规则)
dsh plugin add dsh-vault-wallSemgrep SAST bundle and model-facing scan tool for DeepSeek Harness.
dsh plugin add @aaub-software/dsh-semgrep-sastHold a DeepSeek Harness agent to a capmark capability manifest: mask its tools and judge every call.
dsh plugin add dsh-capmark-gateDeepSeek Harness 插件:为 Agent 增加 code_scan 工具,用 semgrep 扫描代码并输出按文件/行号/严重级别分组的中文报告
dsh plugin add dsh-code-scanTransport-layer data masking for deepseek-harness (dsh): sensitive values never leave the process — the model sees placeholders, you see real values restored live in the stream.
dsh plugin add dsh-llmaskingAutonomous (auto) mode permission classifier for DeepSeek Harness: a Claude-Code-auto-mode-like classifier over tools/pre-execute and approval/request, a selectable 'auto' permission preset, LLM semantic judge, git checkpointing, agent discipline guidance
dsh plugin add dsh-auto-classifierPre-install supply-chain poison scanner for DeepSeek Harness plugins: AST analysis (NodeSecure JS-X-Ray) + deobfuscation decoder + regex heuristics to catch credential exfiltration, dynamic code execution, obfuscated imports, and install-time scripts.
dsh plugin add dsh-poison-guardSingle-password authentication gate for the dsh web surface: configurable session validity, Ctrl+Shift+L lock, CLI password management, brute-force lockout, in-UI password controls.
dsh plugin add dsh-simple-authRead-only health auditor for DSH plugins — admission checks plus static security scan, with a 建议安装/谨慎安装/不建议安装 verdict. Never executes the code it audits.
dsh plugin add dsh-plugin-verifierPII detection & exfiltration guard for DeepSeek Harness — scans tool arguments and results for personal data (emails, phone numbers, CN IDs, cards, keys), blocks outbound calls carrying PII, JSONL audit without storing raw matches.
dsh plugin add dsh-pii-gateDeepSeek Harness 权限规则引擎:hard/deny/ask/allow 四级规则(hard 高于全访问)、全局与 workspace 作用域、通配符路径保护、可视化草稿式编辑器,规则持久化于自管 JSON
dsh plugin add dsh-permissionsDeny an AI agent access to .env files, credential stores, keys and any path you hide — across file tools, shell commands, search selectors and run_code. A DeepSeek Harness (dsh) plugin.
dsh plugin add dsh-hidden-pathsXbox 手柄硬件审批 dsh 插件 — Agent 高危工具调用需物理按键确认(A 批准 / B 驳回)
dsh plugin add dsh-gamepad-approvalFine grained per tool permission rules for DeepSeek Harness (DSH). deny/ask lists in Claude Code rule syntax, enforced at the tools/pre-execute gate. Works standalone.
dsh plugin add dsh-movein-permissionsRead-side SIEM forwarder for DeepSeek Harness: normalises session activity to OCSF and ships it
dsh plugin add dsh-ocsf-forwarderDSH 插件推荐助手:首次使用自动弹出对话框询问你的职业/角色(程序员、设计师、写作、研究、运维、学生…),按角色推荐合适的 DSH 插件,并对每个插件做安全审计(静态扫描)与口碑检查(下载量/星数)。A role-based plugin recommender with security & trust audit for DeepSeek Harness.
dsh plugin add dsh-plugin-recommenderDSH 白盒审计模式:AI 驱动的 SAST,记录方法论、审计链路、漏洞与代码资产,并在 Web 中可视化展示。
dsh plugin add @tangxiaofeng7/dsh-sastLocal tool-call failsafe for DSH: blocks a fixed list of high-risk shell patterns and credential-file reads before execution, with a per-session hash-linked JSONL audit log, and an optional external Gateway for centralized policy.
dsh plugin add dsh-plugin-vajraclawDeepSeek Harness plugin for CVE impact retesting: fingerprint a target, judge it against a CVE's affected range, gather passive evidence, and report a verdict with confidence and limitations.
dsh plugin add dsh-plugin-cvescoutFold the DSH tool surface per request + ChainGuard firewall (high-risk block + exfil-chain detection + anti-obfuscation) + BM25/bge-m3 hybrid tools_search. Shrinks schema tokens 80-90% while keeping selection accuracy. v0.2.0 adds a semantic retrieval leg
dsh plugin add dsh-tool-folderESLint Security SAST bundle and model-facing scan tool for DeepSeek Harness.
dsh plugin add @aaub-software/dsh-eslint-security-sastDeclarative tool-call permission control for DeepSeek Harness — allow/deny/ask rules over tools, paths and commands, fail-closed by default, with JSONL audit log.
dsh plugin add dsh-tool-policyIndependent AI reviewer for one-shot DeepSeek Harness approval requests
dsh plugin add dsh-ai-approvalRuntime security guard for DeepSeek Harness (DSH) — blocks command injection, SSRF, credential exfiltration, and destructive operations at runtime.
dsh plugin add dsh-ccs-securityAuthenticated, policy-gated WebFetchProvider for the DeepSeek Harness web capability seam (ctx.web)
dsh plugin add @yadsh/dsh-web-fetch-authenticateddsh 插件 · 密钥安全输入卡片:AI 需要用户提供密钥(API Key / Token / 密码)时只负责描述「该写到哪个文件、哪个键」;密钥由用户在弹窗卡片中直接输入,由本插件写入配置文件并可选验证是否生效,密钥全程不进入会话记录,AI 只拿到「写入与验证结果」。
dsh plugin add dsh-secret-cardOperator policy and a tamper-evident decision log for DeepSeek Harness. Every tool call judged against your organisation's pack, and written down.
dsh plugin add prae-gate