CATEGORY
Security & Access DSH plugins
Verified manifests and exact versions in this category.
All plugins
688 pluginsdsh-tool-policyTool Policy
Allow, ask, or deny DeepSeek Harness tool calls before execution
chicheng-gateChicheng Gate
DSH Web plugin: LAN/remote access control, frpc tunneling, panel password protection, and mobile UI adaptation.
dsh-capability-receiptCapability Receipt
Content-addressed receipts for skills actually loaded by DeepSeek Harness
chrome-faithfulChrome Faithful
Faithful control of your real, logged-in Chrome profiles: MCP server + MV3 extension + authenticated localhost bridge. No copied profiles, no debug profile, no remote-debugging port, no Edge.
dsh-mnemosMnemos
Cross-session memory with governance, self-evolution and an approval-gated write path for DeepSeek Harness. Heat-ranked recall, environment conventions, forgetting lifecycle, supersession chains, poisoning defense, auto-distillation, and an open measurement ABI.
@blaxel/dsh-sandboxSandbox
Blaxel sandbox execution plugin for DeepSeek Harness (DSH)
dsh-context-provenanceContext Provenance
Observe-only provenance ledger over public DeepSeek Harness runtime evidence
dsh-autogateAutogate
DeepSeek Harness auto-approval plugin: Adds an Auto mode on top of the workspace-write sandbox—deterministic rules allow or deny, ambiguous operations are adjudicated by the LLM, and dangerous operations are escalated to a human. Preserves the workspace sandbox boundary without widening it to full-a
dsh-capability-toggle-pluginCapability Toggle Plugin
DSH WebUI capability controls for skills, MCP servers, tools, prompt injections, approvals, and safety guards at session, project, and global levels.
dsh-omp-advisorOmp Advisor
Ward Council — oh-my-pi advisor subsystem ported to DeepSeek Harness: independent reviewer models watch your agent's live transcript, investigate with read-only tools, and advise it. Advisors guide. The ward protects. The model executes.
dsh-jumpserverJumpserver
JumpServer asset lookup for DeepSeek Harness: query assets via conversation using AccessKey/SecretKey signed requests
dsh-safemode-profileSafemode Profile
Safemode profile enforcer: force-restores ~/.dsh/profiles/safemode to a clean whitelist (dsh-base + dsh-web-app) on start and continuously guards it against modification, so `dsh --profile safemode` always boots with zero third-party plugins. No build scripts: the bundle row does all work.
dsh-ssh-tunnelSsh Tunnel
Multi-host SSH tunnel and SSHManager tool for DeepSeek Harness (project-scoped grants)
dsh-route-resilienceRoute Resilience
Multi-route high availability, fault isolation and observability for DeepSeek Harness. Route groups fail over between authorized provider routes on rate limits (429 / Retry-After), transport errors and auth/quota failures, with per-route quarantine (exponential backoff) and disablement.
@deepseek-ai/dsh-host-telegramHost Telegram
Telegram remote-control surface for dsh sessions: whitelisted chats list, read, prompt, and stop dsh sessions through the host ApiProxy
dsh-approval-modeApproval Mode
Approval mode control for DeepSeek Harness: default approval (ask) or bypass approval (auto-approve every tool call), next to the permission selector. DSH 审批模式插件。
dsh-kiroKiro
Kiro provider for DeepSeek Harness with multi-method login, usage, model controls, and token/profile refresh
@j0ss077/dsh-always-require-tools-approvalAlways Require Tools Approval
Require a one-shot user approval before configured tools execute
dsh-plugin-qr-connectPlugin Qr Connect
DeepSeek Harness (DSH) Web plugin: a QR-code button above Settings that lets phones connect to the web UI through an auth-gated reverse proxy.
dsh-polymarket-knowhowPolymarket Knowhow
DeepSeek Harness plugin: complete Polymarket API coverage — market data tools, authenticated trading tools, WebSocket stream service, and an embedded Polymarket knowhow skill
dsh-ag-uiAg Ui
Authenticated AG-UI HTTP and SSE gateway plugin for DeepSeek Harness
dsh-automodeAutomode
CC-style auto mode for DeepSeek Harness: deterministic deny/allow rules + pre-execute gate + model-agnostic two-stage classifier. TypeScript rewrite merging dsh-auto-mode v0.4.1 with Nuo-cl/dsh-auto-mode native integration.
dsh-crypto-portfolioCrypto Portfolio
Crypto portfolio tracker (BTC/EVM/Solana/Hyperliquid/CEX) as a DSH plugin. All private keys/wallets live in user-local JSON configs, never in this package.
@riceawa/dsh-lan-gatewayLan Gateway
LAN/internet reverse-proxy gateway for the DeepSeek Harness web GUI: binds 0.0.0.0, forwards to the loopback dsh web server with header rewrite to pass the /api trust fence. LAN sources are password-free; non-LAN sources get a login page + HMAC cookie. Optional TLS with auto-generated self-signed or
dsh-injection-guardInjection Guard
Source-aware prompt injection protection for DeepSeek Harness
dsh-lark-web-authLark Web Auth
Multi-tenant Feishu/Lark OAuth login and per-user session isolation for the DeepSeek Harness Web GUI
dsh-governed-workflowGoverned Workflow
Policy-enforced, evidence-first governed workflows for DeepSeek Harness agents — installable community plugin (governance core + authority provider)
@islibaodong/dsh-loginLogin
Single-password authentication gateway plugin for the DSH Web GUI
@deepseek-ai/dsh-plugin-vm-sandboxPlugin Vm Sandbox
OrbStack VM sandbox v0.4.0: Building on v0.3 (security/reliability), adds A1 interactive terminal, A3 scenario-based one-click creation, A4 deletion undo + completion notifications, A5 at-a-glance quota visibility, A6 collaboration groups, B1 security baseline vm_harden, B2 secret store vm_secret, C
@dsh-community/dsh-plugin-containerPlugin Container
Deployment-grade Docker container sandbox plugin for DeepSeek Harness (feature parity with dsh-plugin-vm-sandbox): 39 docker_* model tools, snapshots/rollback, file transfer, port forwarding, background tasks, auditing, sharing/quotas/reclamation, network policies, parallel execution across multiple