agent-security 8
Always-on dependency and compatibility monitoring for DeepSeek Harness plugins, including exact paths, upstream changes, and isolated install/load evidence.
dsh plugin add upstream-radarProvenance-aware execution and output security for DeepSeek Harness, with visible receipts and trusted declassification.
dsh plugin add dsh-riskproofAgentic Control Plane for DeepSeek Harness — check every tool call against your policies before it runs, and keep a durable record of what was allowed and why.
dsh plugin add @agenticcontrolplane/dshAllow, ask, or deny DeepSeek Harness tool calls before execution
dsh plugin add @drifter-yh/dsh-tool-policyNative Auto Review for DeepSeek Harness with automatic host compatibility selection
dsh plugin add @jhckevin/dsh-auto-reviewModel-facing typed tools wrapping the frozen, reviewed underseal adapter for the DeepSeek Harness
dsh plugin add dsh-tool-undersealCorrectover runtime security for DeepSeek Harness (DSH): CCS 7-dimension verification, command-injection/SSRF/credential-exfil blocking, Ed25519 receipts, audit-first. Install with `dsh plugin add dsh-correctover`.
dsh plugin add dsh-correctoverAgent 行为守护桌宠:跨 agent 监控可疑外传(加密打包直传对象存储 / DNS 外泄线索 / 敏感密钥被读),发现即告警,明确确认后按「一次一个」终止目标 agent;事件写入只追加 guard-events.jsonl,并通过 DSH host 工具 + MCP(stdio) 供其它 agent 查询
dsh plugin add deskpet-guard