CATEGORY
Security & Access DSH plugins
Verified manifests and exact versions in this category.
All plugins
688 pluginsdsh-fs-allowlistFs Allowlist
Approval-free writes into whitelisted directories: wraps ctx.fs.checkedTarget for write/edit, auto-approves bash escalations that touch whitelisted paths, with a Settings GUI. 白名单目录写入免审批(write/edit + bash),设置页可视化调整。
dsh-ssh-files-sidebarSsh Files Sidebar
Remote SSH workspace and closed-loop deployment Agent for DeepSeek Harness: SSH Files, terminal, remote editing, zero-to-one Bootstrap, Runbooks, automation, Vision/OCR and safe recovery.
dsh-circuit-breakerCircuit Breaker
Stop runaway agent loops in DeepSeek Harness: denies repeated identical tool calls and enforces a per-agent call cap, outside the model where instructions cannot reach.
dsh-kimi-providerKimi Provider
Kimi (Kimi Code account) integration bundle for DeepSeek Harness: provider route, models, device-code login and auto token refresh (npm: dsh-kimi-provider)
@dsh-mobile/pairingPairing
DSH Mobile Remote plugin: Host Gateway, Public Endpoint pairing, WebRTC Direct, encrypted Tunnel Fallback
dsh-grok-oauthGrok Oauth
Grok (xAI) subscription provider for DeepSeek Harness: PKCE login, chat, usage chip, and optional Grok Imagine.
dsh-model-compat-guardModel Compat Guard
DSH compatibility guard: repairs auto-compaction failures for GPT/reasoning models (raises the summary token cap and lowers reasoning effort on purpose=compaction requests), strips doomed sandbox-escalation requests, and auto-fills the required tool-call 'description' argument other models often omi
dsh-default-workspaceDefault Workspace
Cross-platform native DSH default workspace with complete read-only access to DSH resources, including sensitive state.
dsh-native-codex-oauthNative Codex Oauth
Native ChatGPT OAuth controls for DeepSeek Harness's built-in OpenAI Codex provider
dsh-reverse-proxy-xcReverse Proxy Xc
DSH web plugin: LAN reverse proxy for the DSH web UI (default 0.0.0.0:3090 -> 127.0.0.1:3080, Host/Origin rewritten to loopback, crypto.randomUUID polyfill injected). Settings namespace dsh-reverse-proxy-xc: enabled, host, port, authEnabled, authUser, authPass. Ships a hand-written client half (lib/
dsh-workspace-memoryWorkspace Memory
Approval-gated workspace instructions and memory for DeepSeek Harness
dsh-preset-zombie-guardPreset Zombie Guard
Preset-zombie guard for DeepSeek Harness: periodically scans session logs (zstd frame decoding) for sessions whose effective agent preset no longer exists in the roster; auto-archives blank zombies via the official workspaceRegistry API and deduplicates warnings for non-blank ones. Ships preset_guar
dsh-authmuxAuthmux
A DSH-native OAuth multiplexer for subscription-backed model providers
dsh-pentest-bugtracePentest Bugtrace
BugTraceAI penetration-testing mode for deepseek-harness (dsh): pentester persona, bundled runbook skill, and the BugTraceAI MCP bridge in one installable profile bundle.
dsh-danger-guardDanger Guard
DSH Dangerous Command Guard: Uses the tools/pre-execute gate to intercept high-risk bash/pwsh commands (rm -rf /, mkfs, dd writing to devices, piping scripts for execution, git push --force, etc.), with tiered policies (extremely high risk always denied / medium risk follows the global deny/ask/log
dsh-safe-toolSafe Tool
AI-powered command approval plugin for DeepSeek Harness — intercepts tool calls and routes them through a read-only review subagent
@aiwayds/dsh-vaultVault
dsh-plugin: encrypted backup / restore / migration of the dsh home config through a private GitHub repo
@try-works/dsh-righthandRighthand
DeepSeek Harness plugin: DSH-native righthand tools — durable KV store, credential/settings management, governed exec, and a tool guard
deepseek-harness-sshDeepseek Harness Ssh
SSH remote control for DeepSeek Harness: run commands / compile and read-write files on a remote machine over SSH (works with reverse-SSH tunnels or Tailscale)
dsh-secret-scrubSecret Scrub
DeepSeek Harness plugin: redacts known secret shapes in tool arguments and results behind stable placeholders, and appends preimage-free JSONL incidents
dsh-guardian-modeGuardian Mode
Fifth DeepSeek Harness mode with configurable Codex, Claude Code, or DSH audits, user-approved remediation turns, progressive Cordis/skill elevation, safety pauses, and Web/TUI review controls.
dsh-session-allowSession Allow
DSH Web GUI plugin: session-scoped "Allow for this session" option in the approval dialog (per-mode standing grants, localStorage)
@yangzhe1991/dsh-futu-mcpFutu Mcp
DSH plugin: connect to Futu (富途) MCP via OAuth 2.1 and expose its tools to the agent; tokens persisted outside the workspace
dsh-loop-brakeLoop Brake
DeepSeek Harness plugin: a circuit breaker that denies the Nth identical tool call in a row, by exact hash of tool name and canonical arguments
dsh-security-assuranceSecurity Assurance
Evidence-backed application-security assurance for DeepSeek Harness
dsh-qqbot-panelQqbot Panel
Visual web settings panel for the official @tencent-connect/dsh-qqbot plugin: manage the QQ Bot AppID/AppSecret, c2c & group access modes/allowlists, cwd and requireMention directly in the DSH web settings page (reads/writes the qqbot profile's cordis.patch.yml).
dsh-cloudflare-mcpCloudflare Mcp
Cloudflare MCP connection for DeepSeek Harness: official OAuth 2.0 flow (dynamic client registration + PKCE) against mcp.cloudflare.com, Cloudflare API tools under mcp__cloudflare__*, and a web settings panel
dsh-canaryCanary
DeepSeek Harness plugin: plants a canary string in model-visible context and denies any tool argument or outbound URL that echoes it back
@short-arm-ape/dsh-intranet-browserIntranet Browser
Bypasses the SSRF protection of @yeesy369/dsh-browser-playwright.
dsh-oidcOidc
Standards-based OIDC identity, enterprise API-key binding, declarative branding, and OpenAI-compatible model integration for DeepSeek Harness