CATEGORY
Security & Access DSH plugins
Verified manifests and exact versions in this category.
All plugins
688 pluginsdsh-recovery-proofRecovery Proof
Read-only recovery drill evidence for DeepSeek Harness
dsh-audit-bundleAudit Bundle
Content-addressed audit indexes across independent DeepSeek Harness evidence producers
dsh-policy-drift-proofPolicy Drift Proof
Content-addressed, value-redacted policy drift evidence for DeepSeek Harness
muretai-dsh-skillMuretai Dsh Skill
Join the Muretai agent network from DeepSeek Harness: own identity, invite-based introductions, signed end-to-end encrypted agent-to-agent messaging, inbound-mail wake.
dsh-connect-traeConnect Trae
Connect locally signed-in Trae models to DeepSeek Harness, plus a read-only usage/credits summary.
dsh-tokenrhythm-billTokenrhythm Bill
基元律动 Billing Center: account balance and limited-time quotas, model pricing cards filterable by category (including discounted prices), official-equivalent service status, and platform key management; credentials are stored only on the local host.
dsh-plugin-oauth-subsPlugin Oauth Subs
ChatGPT Codex, xAI Grok, Zhipu GLM, AWS Kiro, Google Antigravity, and Cursor subscription OAuth for DeepSeek Harness — PKCE / device-code / Google login, local Responses proxy, llm-pi-ai sync.
dsh-login-gatewayLogin Gateway
DeepSeek Harness login gatekeeper plugin: provides an external access entry point for the dsh Web UI and username/password login verification
dsh-tool-sessionTool Session
DeepSeek Harness session management tools plugin: provides models with tools for creating, renaming, archiving, switching, and listing sessions; supports sandbox privilege escalation approval and UI-level session switching with dedicated views for session tools.
dsh-git-credentialsGit Credentials
Out-of-tree dsh plugin: GitLab, GitHub, Gitee, Gitea, and Bitbucket tokens stay out of the model context, stored encrypted (AES-256-GCM) in a plugin-owned file; the model calls forge API tools on demand, and the web settings page manages sites and tokens.
dsh-anthropic-oauthAnthropic Oauth
Bridge Claude Code OAuth (Pro/Max/Team) into DSH — reuses ~/.claude/.credentials.json, auto-refreshes, syncs ANTHROPIC_OAUTH_TOKEN, pulls the model catalog live from /v1/models, and shows a live subscription quota panel (5h/7d usage + reset) — without hardcoding
dsh-audit-modeAudit Mode
Fifth DeepSeek Harness mode with configurable Codex, Claude Code, or DSH audits, user-approved remediation turns, progressive Cordis/skill elevation, safety pauses, and Web/TUI review controls.
dsh-plugin-security-reviewPlugin Security Review
Static bundle form of the DSH plugin-install security gate: reviews cordis_define/cordis_run with a fail-safe policy, plus review/audit tools and a browser approval popup (agree / agree+whitelist / reject; agree+whitelist writes the plugin family into trusted-local so install+dev no longer re-prompt
dsh-ai-soulAi Soul
Persistent identity layer for DeepSeek Harness
dsh-mobile-accessMobile Access
DeepSeek Harness mobile access plugin: PC approval gate · automatic detection and mode switching for LAN/VPN/public network · gateway proxy (0.0.0.0 port forwarding) · QR code access · real-time WebSocket forwarding · narrow-screen UI adaptation (automatically disables third-party skins)
dsh-qr-shareQr Share
DSH web plugin: a sidebar footer QR-code button that lets a phone scan and re-issue the current browser's authenticated launch URL, reusing the same ?token exchange the desktop just completed.
dsh-approval-auto-reviewApproval Auto Review
Codex-inspired Guardian approval reviewer for DeepSeek Harness
dsh-mcp-workspace-scopeMcp Workspace Scope
Per-workspace MCP scoping for the DeepSeek Harness — decide which MCP servers a session may see from the directory it was opened in.
dsh-permissionsPermissions
DeepSeek Harness permission rule engine: four rule levels (hard/deny/ask/allow), with hard taking precedence over full access; global and workspace scopes; wildcard path protection; visual draft-style editor; rules persisted in settings.yaml
dsh-session-vaultSession Vault
Secure session management plugin for DSH rc.7: archive restoration, unlimited recycle bin, batch operations, and permanent deletion.
dsh-mcpguardMcpguard
Mingleng mcpguard for DeepSeek Harness 鈥?the first security plugin for DSH. Scans skills and MCP configs for prompt injection, homoglyphs, hidden Unicode, dangerous shell and credential leaks.
dsh-multi-workspaceMulti Workspace
Multi-workspace sandbox for DSH: automatically grant file-write access to ALL registered workspaces — add a workspace in the UI, write to it immediately, no config needed.
phone-tunnel-poolPhone Tunnel Pool
One-click Cloudflare quick-tunnel pool for the dsh web GUI — access from your phone via QR, self-healing generations, chase service worker.
dsh-plugin-auth-webserverPlugin Auth Webserver
DeepSeek Harness bundle providing HTTP Basic Authentication, a bilingual web login page, a Web UI settings card, remote IP access, brute-force throttling, and QVD-2026-57410 hardening for self-hosted server deployments.
@dsh-so/dsh-code-securityCode Security
DeepSeek Harness security bundle: auto-audits newly installed plugins with the harness's own model (settings panel + batch tools), and ships the Security-Audit-Mode agent preset with the OpenAI Codex Security workflow skills and dsh_security_* scan tools. One package, one `dsh plugin add`.
dsh-x-connectX Connect
X (Twitter) connector for DeepSeek Harness: OAuth 2.0 credential binding, posting tweets with per-post cost estimation, and reading/summarizing related posts. Ships a settings card in the Web plugin page.
agent-guard-dshAgent Guard Dsh
Destructive-action reliability layer for AI agents on DeepSeek Harness: intercepts Bash before execution, quarantines deletions to .agent-trash/ with a restorable manifest, snapshots git before overwrites, and escalates compound shapes to the human (Decision Protocol: ALLOW / RELOCATE / SNAPSHOT / A
dsh-guardrailGuardrail
Tool call policy guard: matches strings in agent tool call parameters, blocks matches for dangerous behavior and injects the reason (deny), or allows them while injecting a warning (warn), with a rule management panel
dsh-hover-approveHover Approve
DSH Web sidebar-anchored bubbles: authorization / questions / plan confirmation / goal blocking, handled with one click beside the conversation row without opening the conversation
dsh-airbagAirbag
Non-intrusive safety belt for DeepSeek Harness: blocks API keys pasted to the agent, blocks secret writes, tracks leak events, and offers a workspace health scan. 非侵入式安全护栏:拦截粘贴给 Agent 的 API 密钥、写入拦截、泄露追踪与工作区安全体检。