DeepSeek Harness Plugin Hub

CATEGORY

Security & Access DSH plugins

Verified manifests and exact versions in this category.

All plugins

688 plugins
v0.2.1
dsh-fs-allowlist

Fs Allowlist

Approval-free writes into whitelisted directories: wraps ctx.fs.checkedTarget for write/edit, auto-approves bash escalations that touch whitelisted paths, with a Settings GUI. 白名单目录写入免审批(write/edit + bash),设置页可视化调整。

security-accessdeveloper-tools00
Updated 9/2/2026
v0.8.9
dsh-ssh-files-sidebar

Ssh Files Sidebar

Remote SSH workspace and closed-loop deployment Agent for DeepSeek Harness: SSH Files, terminal, remote editing, zero-to-one Bootstrap, Runbooks, automation, Vision/OCR and safe recovery.

developer-toolssecurity-access00
Updated 9/2/2026
v0.1.0
dsh-circuit-breaker

Circuit Breaker

Stop runaway agent loops in DeepSeek Harness: denies repeated identical tool calls and enforces a per-agent call cap, outside the model where instructions cannot reach.

agents-orchestrationsecurity-access00
Updated 9/2/2026
v1.0.0
dsh-kimi-provider

Kimi Provider

Kimi (Kimi Code account) integration bundle for DeepSeek Harness: provider route, models, device-code login and auto token refresh (npm: dsh-kimi-provider)

models-usagesecurity-access00
Updated 9/2/2026
v0.1.12
@dsh-mobile/pairing

Pairing

DSH Mobile Remote plugin: Host Gateway, Public Endpoint pairing, WebRTC Direct, encrypted Tunnel Fallback

security-accessintegrations-communication00
Updated 9/2/2026
v0.1.6
dsh-grok-oauth

Grok Oauth

Grok (xAI) subscription provider for DeepSeek Harness: PKCE login, chat, usage chip, and optional Grok Imagine.

models-usagesecurity-access00
Updated 9/2/2026
v0.2.0
dsh-model-compat-guard

Model Compat Guard

DSH compatibility guard: repairs auto-compaction failures for GPT/reasoning models (raises the summary token cap and lowers reasoning effort on purpose=compaction requests), strips doomed sandbox-escalation requests, and auto-fills the required tool-call 'description' argument other models often omi

memory-contextsecurity-accessmodels-usage00
Updated 9/1/2026
v1.0.0
dsh-default-workspace

Default Workspace

Cross-platform native DSH default workspace with complete read-only access to DSH resources, including sensitive state.

security-access00
Updated 9/1/2026
v0.1.0-alpha.1
dsh-native-codex-oauth

Native Codex Oauth

Native ChatGPT OAuth controls for DeepSeek Harness's built-in OpenAI Codex provider

security-accessmodels-usage00
Updated 9/1/2026
v0.1.4
dsh-reverse-proxy-xc

Reverse Proxy Xc

DSH web plugin: LAN reverse proxy for the DSH web UI (default 0.0.0.0:3090 -> 127.0.0.1:3080, Host/Origin rewritten to loopback, crypto.randomUUID polyfill injected). Settings namespace dsh-reverse-proxy-xc: enabled, host, port, authEnabled, authUser, authPass. Ships a hand-written client half (lib/

security-access00
Updated 9/1/2026
v0.1.0
dsh-workspace-memory

Workspace Memory

Approval-gated workspace instructions and memory for DeepSeek Harness

memory-contextsecurity-access00
Updated 9/1/2026
v0.1.0
dsh-preset-zombie-guard

Preset Zombie Guard

Preset-zombie guard for DeepSeek Harness: periodically scans session logs (zstd frame decoding) for sessions whose effective agent preset no longer exists in the roster; auto-archives blank zombies via the official workspaceRegistry API and deduplicates warnings for non-blank ones. Ships preset_guar

security-accessmemory-context00
Updated 9/1/2026
v0.1.0
dsh-authmux

Authmux

A DSH-native OAuth multiplexer for subscription-backed model providers

security-accessmodels-usage00
Updated 9/1/2026
v0.1.0
dsh-pentest-bugtrace

Pentest Bugtrace

BugTraceAI penetration-testing mode for deepseek-harness (dsh): pentester persona, bundled runbook skill, and the BugTraceAI MCP bridge in one installable profile bundle.

security-accessintegrations-communication00
Updated 9/1/2026
v0.1.0
dsh-danger-guard

Danger Guard

DSH Dangerous Command Guard: Uses the tools/pre-execute gate to intercept high-risk bash/pwsh commands (rm -rf /, mkfs, dd writing to devices, piping scripts for execution, git push --force, etc.), with tiered policies (extremely high risk always denied / medium risk follows the global deny/ask/log

security-accessdeveloper-tools00
Updated 9/1/2026
v0.1.0
dsh-safe-tool

Safe Tool

AI-powered command approval plugin for DeepSeek Harness — intercepts tool calls and routes them through a read-only review subagent

security-accessdeveloper-tools00
Updated 9/1/2026
v0.1.0
@aiwayds/dsh-vault

Vault

dsh-plugin: encrypted backup / restore / migration of the dsh home config through a private GitHub repo

security-accessdeveloper-tools00
Updated 9/1/2026
v0.1.20
@try-works/dsh-righthand

Righthand

DeepSeek Harness plugin: DSH-native righthand tools — durable KV store, credential/settings management, governed exec, and a tool guard

security-accessdeveloper-tools00
Updated 9/1/2026
v1.4.0
deepseek-harness-ssh

Deepseek Harness Ssh

SSH remote control for DeepSeek Harness: run commands / compile and read-write files on a remote machine over SSH (works with reverse-SSH tunnels or Tailscale)

developer-toolssecurity-access00
Updated 9/1/2026
v0.1.0
dsh-secret-scrub

Secret Scrub

DeepSeek Harness plugin: redacts known secret shapes in tool arguments and results behind stable placeholders, and appends preimage-free JSONL incidents

security-access00
Updated 9/1/2026
v0.5.0
dsh-guardian-mode

Guardian Mode

Fifth DeepSeek Harness mode with configurable Codex, Claude Code, or DSH audits, user-approved remediation turns, progressive Cordis/skill elevation, safety pauses, and Web/TUI review controls.

security-accessdeveloper-toolsui-customization0
Updated 9/1/2026
v0.3.1
dsh-session-allow

Session Allow

DSH Web GUI plugin: session-scoped "Allow for this session" option in the approval dialog (per-mode standing grants, localStorage)

security-access00
Updated 8/31/2026
v0.1.1
@yangzhe1991/dsh-futu-mcp

Futu Mcp

DSH plugin: connect to Futu (富途) MCP via OAuth 2.1 and expose its tools to the agent; tokens persisted outside the workspace

integrations-communicationsecurity-access00
Updated 8/31/2026
v0.1.0
dsh-loop-brake

Loop Brake

DeepSeek Harness plugin: a circuit breaker that denies the Nth identical tool call in a row, by exact hash of tool name and canonical arguments

security-accessdeveloper-tools00
Updated 8/31/2026
v0.1.0-rc.10
dsh-security-assurance

Security Assurance

Evidence-backed application-security assurance for DeepSeek Harness

security-access00
Updated 8/31/2026
v0.1.0
dsh-qqbot-panel

Qqbot Panel

Visual web settings panel for the official @tencent-connect/dsh-qqbot plugin: manage the QQ Bot AppID/AppSecret, c2c & group access modes/allowlists, cwd and requireMention directly in the DSH web settings page (reads/writes the qqbot profile's cordis.patch.yml).

ui-customizationintegrations-communicationsecurity-access00
Updated 8/31/2026
v0.1.1
dsh-cloudflare-mcp

Cloudflare Mcp

Cloudflare MCP connection for DeepSeek Harness: official OAuth 2.0 flow (dynamic client registration + PKCE) against mcp.cloudflare.com, Cloudflare API tools under mcp__cloudflare__*, and a web settings panel

integrations-communicationsecurity-access00
Updated 8/31/2026
v0.1.0
dsh-canary

Canary

DeepSeek Harness plugin: plants a canary string in model-visible context and denies any tool argument or outbound URL that echoes it back

security-access00
Updated 8/31/2026
v0.1.0
@short-arm-ape/dsh-intranet-browser

Intranet Browser

Bypasses the SSRF protection of @yeesy369/dsh-browser-playwright.

security-access00
Updated 8/31/2026
v0.1.0-alpha.10
dsh-oidc

Oidc

Standards-based OIDC identity, enterprise API-key binding, declarative branding, and OpenAI-compatible model integration for DeepSeek Harness

security-accessmodels-usage00
Updated 8/31/2026