security 81
Read-only security & compliance toolkit for DeepSeek Harness: prompt-injection detection (rule engine with a pluggable model classifier), Chinese-PII and structured-JSON redaction, and a local configuration security audit that emits redacted, reproducible
dsh plugin add dsh-secure-auditDSH RedTeam 模式:一句话拉起红队作战智能体(资产测绘 / 攻击链 / 得分目标 / 报告 / POC 知识库),含六个角色、23 个原生技能、常驻右侧控制台与一键自动更新
dsh plugin add dsh-redteam-modeAuto mode for DeepSeek Harness (dsh): an Auto entry in the Permissions selector whose approval prompts are answered by OpenGuardrails policy instead of a human — plus the full OGR guard engine underneath. No core changes.
dsh plugin add @openguardrails/dsh-auto-modeMinimal Root-Orchestrator PTES pentesting plugin for DeepSeek Harness
dsh plugin add dsh-pentesterPrompt-injection, jailbreak, and secret-leak detection with allow/ask/block interception for DeepSeek Harness: an Aho-Corasick pattern engine and heuristics ported from the Prompt-Injection-Payloads, Jailbreak-Detector, and Secret-Key-Leaker-Detect assets
dsh plugin add dsh-defendProvider plugin for dsh-skill-pack-security: registers the pack's skills/ (zh) or skills-en/ (en) edition on ctx.skills AND the plugin_vet supply-chain gate tool on ctx.tools (license/SBOM/commit-lock/malware scans + five-dimension risk card). Ships both
dsh plugin add @perrylink/dsh-skill-pack-security-providerLogin gate for DeepSeek Harness (dsh) web instances: password or shared-token sign-in, optional TOTP two-factor, session cookies, rate limiting, self-service password change and a user-management CLI
dsh plugin add dsh-auth-gate为 DeepSeek Harness 增加介于 Workspace Write 与 Full access 之间的自动批准权限档:例行沙箱升级由分类模型一次性放行,危险或不确定的操作仍转人工审批。An auto-approval permission preset for DeepSeek Harness between workspace-write and full access: routine sandbox escalations are granted once by a classifier
dsh plugin add dsh-auto-approvePII masking middleware for DeepSeek Harness: regex-detect and replace phones, emails, ID cards, bank cards, keys, and (opt-in) IPs with placeholders before they reach the model, keep the restore table host-side (memory plus a controlled storage domain, ne
dsh plugin add dsh-mask🛡️ 给 DeepSeek Harness 插件拍 X 光 —— DSH 插件安全体检与健康检查。静态启发式审计:代码执行、凭据访问、外传端点、混淆、安装脚本、bundle 清单合规,输出 0-100 风险分与裁决。Plugin security & health scanner for DeepSeek Harness: heuristic static audit (code execution, credential access, exfiltration, obfuscation, insta
dsh plugin add deepseek-harness-sentinelSecurity audit plugin for DeepSeek Harness: static permission profiling and a runtime sentinel for third-party plugins
dsh plugin add dsh-plugin-auditAudit deepseek-harness (DSH) plugins before install, guard them at runtime. Static verdict + pre-install audit protocol; supply-chain checks (typosquat, OSV); exfiltration & ransomware detection, honeypot canaries, integrity baseline. Alarm-only; blocks c
dsh plugin add @jieai/dsh-plugin-vet装插件前,先体检:第三方插件 = 进程内全权限代码,这个工具让'盲装'变成'知情安装'——恶意模式、越权路径、未检查依赖,一目了然。Static heuristic vetting for third-party DeepSeek Harness plugins: exfiltration, credential access, over-privileged paths, unvetted dependencies.
dsh plugin add dsh-plugin-vettingGitee/GitHub AI 员工:issue 里 @ 机器人自动开发并提 PR;v1.2 新增代码安全扫描——配置仓库地址后按内置/自定义提示词扫描漏洞,去重后提交 issue。An issue-driven AI developer for DeepSeek Harness (Gitee & GitHub) with optional static security scanning (dedup + issue reporting).
dsh plugin add gitee-ai-employeeDSH 规则执行引擎 v3:容器解析 AGENTS.md + 理解器 + 匹配机 + 执行框架
dsh plugin add dsh-rule-engineAgent-decided approvals for DeepSeek Harness: an 自动审批 permission mode where every sandbox escalation is judged automatically by an LLM (default judge: one direct LLM call with no subagent session; optional isolated judge subagent) plus an independent 自动审查
dsh plugin add @duke-dsh-plugins/dsh-agent-approvalDeepSeek Harness plugin for SecurStack security scans, policy checks, doctor diagnostics, and JSON CLI results.
dsh plugin add @securstack/dsh-pluginPlugin insight center — one answer to '哪些值得装': requirement matching (plugin_guide), environment recipes (recipe), health scoring (plugin_rank), static security scanning (plugin_audit), and a single install verdict (plugin_verdict)
dsh plugin add dsh-insightFail-closed LLM-assisted approval reviewer for DeepSeek Harness
dsh plugin add dsh-smart-approvalDeepSeek Harness community Bundle for the skill-security-guard static scanner
dsh plugin add dsh-skill-security-guardSecret-scrubbing guard plugin: irreversible regex redaction of secrets before session-log persistence and model requests
dsh plugin add dsh-secret-scrubStatic bundle form of the DSH plugin-install security gate: reviews cordis_define/cordis_run with a fail-safe policy, plus review/audit tools and a browser approval popup (agree / agree+whitelist / reject; agree+whitelist writes the plugin family into tru
dsh plugin add dsh-plugin-security-reviewSemgrep SAST bundle and model-facing scan tool for DeepSeek Harness.
dsh plugin add @aaub-software/dsh-semgrep-sast保险区 Vault Wall — 让 DeepSeek Harness 无法感知、无法触碰用户指定敏感路径的隔离墙插件(隔离墙 + 人在回路审批 + 执行后验证 + 循环纠正 + 可回滚规则)
dsh plugin add dsh-vault-wallDeepSeek Harness 插件:为 Agent 增加 code_scan 工具,用 semgrep 扫描代码并输出按文件/行号/严重级别分组的中文报告
dsh plugin add dsh-code-scanHold a DeepSeek Harness agent to a capmark capability manifest: mask its tools and judge every call.
dsh plugin add dsh-capmark-gateTransport-layer data masking for deepseek-harness (dsh): sensitive values never leave the process — the model sees placeholders, you see real values restored live in the stream.
dsh plugin add dsh-llmaskingPre-install supply-chain poison scanner for DeepSeek Harness plugins: AST analysis (NodeSecure JS-X-Ray) + deobfuscation decoder + regex heuristics to catch credential exfiltration, dynamic code execution, obfuscated imports, and install-time scripts.
dsh plugin add dsh-poison-guardSingle-password authentication gate for the dsh web surface: configurable session validity, Ctrl+Shift+L lock, CLI password management, brute-force lockout, in-UI password controls.
dsh plugin add dsh-simple-auth面向多 Agent、多模型、多 Provider 的 AI Coding Agent 安全配置中心
dsh plugin add agentrevealAutonomous (auto) mode permission classifier for DeepSeek Harness: a Claude-Code-auto-mode-like classifier over tools/pre-execute and approval/request, a selectable 'auto' permission preset, LLM semantic judge, git checkpointing, agent discipline guidance
dsh plugin add dsh-auto-classifierDeny an AI agent access to .env files, credential stores, keys and any path you hide — across file tools, shell commands, search selectors and run_code. A DeepSeek Harness (dsh) plugin.
dsh plugin add dsh-hidden-pathsXbox 手柄硬件审批 dsh 插件 — Agent 高危工具调用需物理按键确认(A 批准 / B 驳回)
dsh plugin add dsh-gamepad-approvalFine grained per tool permission rules for DeepSeek Harness (DSH). deny/ask lists in Claude Code rule syntax, enforced at the tools/pre-execute gate. Works standalone.
dsh plugin add dsh-movein-permissionsESLint Security SAST bundle and model-facing scan tool for DeepSeek Harness.
dsh plugin add @aaub-software/dsh-eslint-security-sastDSH 插件推荐助手:首次使用自动弹出对话框询问你的职业/角色(程序员、设计师、写作、研究、运维、学生…),按角色推荐合适的 DSH 插件,并对每个插件做安全审计(静态扫描)与口碑检查(下载量/星数)。A role-based plugin recommender with security & trust audit for DeepSeek Harness.
dsh plugin add dsh-plugin-recommenderDSH 白盒审计模式:AI 驱动的 SAST,记录方法论、审计链路、漏洞与代码资产,并在 Web 中可视化展示。
dsh plugin add @tangxiaofeng7/dsh-sastLocal tool-call failsafe for DSH: blocks a fixed list of high-risk shell patterns and credential-file reads before execution, with a per-session hash-linked JSONL audit log, and an optional external Gateway for centralized policy.
dsh plugin add dsh-plugin-vajraclawDeepSeek Harness plugin for CVE impact retesting: fingerprint a target, judge it against a CVE's affected range, gather passive evidence, and report a verdict with confidence and limitations.
dsh plugin add dsh-plugin-cvescoutFold the DSH tool surface per request + ChainGuard firewall (high-risk block + exfil-chain detection + anti-obfuscation) + BM25/bge-m3 hybrid tools_search. Shrinks schema tokens 80-90% while keeping selection accuracy. v0.2.0 adds a semantic retrieval leg
dsh plugin add dsh-tool-folderFour-mode file-permission fence for DeepSeek Harness (workspace read/write x outside read/write), enforced at the tool layer, with a read-only composer mode indicator and a locale-aware UI.
dsh plugin add dsh-plugin-permission-guardDeclarative tool-call permission control for DeepSeek Harness — allow/deny/ask rules over tools, paths and commands, fail-closed by default, with JSONL audit log.
dsh plugin add dsh-tool-policyIndependent AI reviewer for one-shot DeepSeek Harness approval requests
dsh plugin add dsh-ai-approvalRuntime security guard for DeepSeek Harness (DSH) — blocks command injection, SSRF, credential exfiltration, and destructive operations at runtime.
dsh plugin add dsh-ccs-securityAuthenticated, policy-gated WebFetchProvider for the DeepSeek Harness web capability seam (ctx.web)
dsh plugin add @yadsh/dsh-web-fetch-authenticatedBudgeted DSH preflight and one-shot escalation with conversation-following or independent reviewers.
dsh plugin add @klarkxy/dsh-safe-autodsh 插件 · 密钥安全输入卡片:AI 需要用户提供密钥(API Key / Token / 密码)时只负责描述「该写到哪个文件、哪个键」;密钥由用户在弹窗卡片中直接输入,由本插件写入配置文件并可选验证是否生效,密钥全程不进入会话记录,AI 只拿到「写入与验证结果」。
dsh plugin add dsh-secret-cardOperator policy and a tamper-evident decision log for DeepSeek Harness. Every tool call judged against your organisation's pack, and written down.
dsh plugin add prae-gateHost-only command safety gate for DeepSeek Harness: blocks recognized dangerous operations and requests DSH approval when a command cannot be inspected.
dsh plugin add @goodandready/dsh-approval-gateDSH plugin for background security audits, secret leakage detection, and command safety
dsh plugin add @goodandready/dsh-shadow-auditor