CATEGORY
Security & Access DSH plugins
Verified manifests and exact versions in this category.
All plugins
688 pluginsum-dsh-websearchUm Dsh Websearch
Dual-backend (Exa + Parallel) web search provider plugin for DeepSeek Harness: strategy layer with master switch, per-backend enable and preferred routing, paid-REST/anonymous-MCP two-way fallback per backend, credentials-service key resolution, and a Settings-driven simplified card with a Modal det
@nevermindzzt/dsh-manager-pluginManager Plugin
Direct dsh-manager reverse tunnel plugin for DeepSeek Harness
@luoxunhao/dsh-codex-projectCodex Project
DSH web plugin inspired by Claude Code /add-dir: a native workspace gains any number of additional writable directories (cross-drive), the model can add directories via the add-dir tool (core approval confirms), and sessions read/write them under workspace-write permission — never danger-full-access
dsh-trust-checkTrust Check
Static trust audit for DeepSeek Harness plugins: capabilities, injected prompts, token cost, provenance, and a reproducible 0-100 trust score
dsh-model-account-loginModel Account Login
Persistent DSH model-account authorization UI for ChatGPT, Claude, and other llm-pi-ai login flows
@jiesou/dsh-nous-portal-free-providerNous Portal Free Provider
Nous Portal free-tier provider for dsh: Portal OAuth (device-code) agent-key lifecycle behind an OpenAI-compatible harness route
@goodandready/dsh-shadow-auditorShadow Auditor
DSH plugin for background security audits, secret leakage detection, and command safety
@dsh-external/donsetchDonsetch
First-class DonSeTch web access for DeepSeek Harness: fetch, search and crawl with browser-grade stealth, keyless engines, BYOK providers and an auto-updating native binary.
@omdsh-plugins/omdsh-remctrlOmdsh Remctrl
Remote control for the DeepSeek Harness: puts its own interface on a public address behind a passcode, over a cloudflared tunnel by default, so the window you reach from a phone is the window you left open
dsh-claim-guardClaim Guard
A deterministic pre-write claim guard for supported DeepSeek Harness file tools.
dsh-web-fetch-enhancedWeb Fetch Enhanced
Configurable non-public address allowlists for DeepSeek Harness web_fetch
dsh-safe-deleteSafe Delete
Intercepts `rm` commands issued by any DSH agent session (GUI, automation runs, headless bridges) at the tools guard layer and moves the targets to the macOS Trash instead of deleting them. Switchable from the web GUI under Settings → General.
dsh-d1D1
Cloudflare D1 tools for the DeepSeek Harness: d1_list/query/exec/schema/stats/health over the D1 HTTP API — read-only first, lexical read-only guard, write-approval gate, row clamping, CSV/JSON output.
dsh-gemini-oauth-bridgeGemini Oauth Bridge
Bridge Google AI subscription (Antigravity/Gemini OAuth, Code Assist API) into DeepSeek Harness as an OpenAI-compatible model endpoint
dsh-llm-xai-oauthLlm Xai Oauth
Native SuperGrok / X Premium OAuth provider for DeepSeek Harness. Reuses local grok-bridge tokens; no xAI API key.
@musitoolbox/dsh-remoteRemote
Opt-in mobile access to DeepSeek Harness Web through QR pairing and a managed FRP tunnel.
dsh-security-guardSecurity Guard
DSH runtime security guard plugin — loader import confinement, HTTP Host header validation, and sandbox service deny-list (QVD-2026-52631/57410/52644/52646). AI-assisted patch.
dsh-git-pushGit Push
Automatic git commit and push + code audit gate: the settings page checks the token/public key and displays the GitHub user; after pushing, it returns the 3 most recent remote commits in a table.
@deepdeck-apps/strudel-vis-builderStrudel Vis Builder
The official Strudel REPL experience for DeepDeck with a sandboxed runtime and AI-assisted live coding
dsh-claude-subscriptionClaude Subscription
Claude Pro/Max subscription for DeepSeek Harness with official Anthropic OAuth login and automatic token refresh
dsh-mcp-oauth-clientMcp Oauth Client
General-purpose MCP manager and client bridge plugin for DeepSeek Harness
dsh-dolphin-securityDolphin Security
This is a DSH ecosystem plugin. Dolphin - an active inspection security defense plugin that supports local scanning and remote SSH patrols. It converts the penetration testing methodology (information gathering → vulnerability probing → exploitation verification → reporting) into an active defense i
@goodandready/dsh-time-machineTime Machine
DSH plugin for smart checkpoints, workspace safety guards, and instant rollback
@goodandready/dsh-agent-loop-guardAgent Loop Guard
Fail-closed runtime tool-call loop guard for DeepSeek Harness.
dsh-tool-folderTool Folder
Fold the DSH tool surface per request + ChainGuard firewall (high-risk block + exfil-chain detection + anti-obfuscation) + BM25/bge-m3 hybrid tools_search. Shrinks schema tokens 80-90% while keeping selection accuracy. v0.2.0 adds a semantic retrieval leg (local Ollama bge-m3, RRF hybrid) and ChainG
dsh-wpsWps
WPS / 金山文档 cloud-docs integration for DeepSeek Harness: official SkillHub MCP (https://mcp-center.wps.cn/skill_hub/mcp), custom browser authorization (auth-guide + exchange-poll token), WPS cloud-doc tools under mcp__wps__*, wps_status/wps_oauth_start/wps_test helper tools, and a web settings panel
dsh-agent-frugalityAgent Frugality
DSH defense plugin against three-layer failure in multi-agent systems: deduplication measurement via read ledger (read-ledger), an immune compression rules area plus mechanical completion gate (immutable-core+completion-gate), and a low-cost review lane (role-router). No external dependencies; injec
@robbin810130/dsh-vault-pluginVault Plugin
DSH Vault Plugin: Frontend Privacy Lock for Projects and Conversations
dsh-plumb-identityPlumb Identity
Per-agent plumb session identity for DeepSeek Harness: stamps and declares a stable plumb session id for every DSH conversation and subagent sharing one plumb MCP connection.
dsh-guard-sensitive-pathsGuard Sensitive Paths
Approval guard for DeepSeek Harness: write/edit/editor/bash calls touching sensitive paths (.env, .git, SSH keys, .pem) and reads of SSH keys or certificates become an approval ask.