allowlist 8
Configurable User-Agent and non-public address allowlists for DeepSeek Harness web_fetch
dsh plugin add dsh-web-fetch-enhancedDSH permission-gate for the DeepSeek Harness 0.1.5 line: a single self-sufficient, deterministic-first, fail-closed gate covering P0 hard-deny -> P1 session grant -> P2 static rule (allow/deny) chain -> P3 optional LLM semantic classifier -> P4 ask, with
dsh plugin add dsh-perm-gateModel authorization gate: subagent model/provider pulls must be in the user-controlled allowlist. 模型授权闸:子代理拉模型必须 ∈ 用户 allowlist
dsh plugin add dsh-miopiik-model-authRuntime security gate for DeepSeek Harness: egress host allowlist, secret redaction in tool results, and an append-only audit log
dsh plugin add dsh-egress-guardEgress policy for DeepSeek Harness: a host allowlist on web_fetch and web_search enforced at connect time, audit-mode by default, with OCSF Network Activity records
dsh plugin add dsh-netguardDSH plugin: automatic approval for configured directories and commands — stop the sandbox-escalation popups you already trust, keep the rest. · DSH 自动权限审批插件:按允许目录与「以某命令开头」的允许命令自动放行工作区写模式下的越权审批弹窗,并在审批卡片上提供「始终允许」按钮。
dsh plugin add dsh-dhe-allowFine grained per tool permission rules for DeepSeek Harness (DSH). deny/ask lists in Claude Code rule syntax, enforced at the tools/pre-execute gate. Works standalone.
dsh plugin add dsh-movein-permissionsIP/domain allowlist web_fetch provider for DeepSeek Harness: lets web_fetch reach allowlisted hosts/IPs freely (incl. proxy fake-IP addresses like 198.18.x.x) while keeping the default public-IP safety check for everything else.
dsh plugin add dsh-web-allowlist-fetch