DeepSeek Harness Plugin Hub

Publish and manage complete Harness Profiles. Discover Plugins for your next setup.

Explore

PluginsPresetsDocsNews

Community

Publish a pluginContactReport an issue

Resources

Plugin Hub on GitHubDeepSeek HarnessSystem statusPrivacy notice
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

Independent and unofficial. Not affiliated with, authorized by, or endorsed by DeepSeek.

Cc Safety Net — DSH Plugin for DeepSeek Harness
DeepSeek Harness Plugin Hub
ProfilesPluginsCategoriesNewsDocsSign inManage Profiles
ProfilesPluginsCategoriesNewsDocsSign in
← Plugins

cc-safety-net

Cc Safety Net

A coding agent CLI hook - block destructive commands and secret file access

The plugin will be installed here. Keep web if you are unsure.

npx -y @deepseek-ai/dsh plugin --profile web add cc-safety-net@2.6.0
READMECompatibilityVersions

Compatibility and provenance

Cc Safety Net is published as cc-safety-net and currently resolves to version 2.6.0. The Hub verifies its manifest and preserves the exact installation source for reproducible installs.

DSH compatibility
*
Runtime surfaces
any
Release source
npm
Registry updated
10/7/2026

Versions

2.6.0stable
10/5/2026
2.5.2stable
10/3/2026
2.5.1stable
10/2/2026
Show 1 more versionCollapse versions
2.5.0stable
10/1/2026

Related plugins

Loading related plugins…

Latest
2.6.0
DSH
*
HMR
Process restart
Tree shaking
Safe tree shaking not declared
Unpacked size
1.9 MB
Files
23
Surface
any
License
MIT
Source
npm
GitHub
★ 1.6k
Weekly downloads
13,087
Security scan
✓ v2.6.0 scan passed
Last push
10/6/2026
View source ↗Project homepage ↗
README badge

Click the badge to copy Markdown for your README.

Do you maintain this Plugin?Claim benefit · Priority security scan

Verify the GitHub repository declared in package.json to manage this listing. After you claim it, Hub will prioritize a security scan of the current version and publish the result when it passes.

Claim this Plugin →
Report an issue

README

CC Safety Net

English · 简体中文 · 日本語

https://github.com/user-attachments/assets/928dbe97-31e3-41d1-b35a-7941a701b056

CC Safety Net (Coding CLI Safety Net) blocks destructive commands and access to secrets such as SSH keys and .env files before the tool call runs. It parses what the command does. Wrapping the command or reordering flags does not hide it. A broken config file never blocks anything. It is not a sandbox: it does not contain processes, set filesystem permissions, or watch network egress.

[!NOTE] Full documentation → covers installation, configuration, reference material, guides, and the security model. This README is the short version.

How it works

An AI coding agent tries to run a command or open a file. CC Safety Net checks what it would actually do before it runs. Safe calls such as git status run normally; dangerous ones such as git reset --hard never run, and the agent is told why.

Supported coding CLIs

CC Safety Net supports these coding agent CLIs on Windows, macOS, and Linux.

Amp Code
Amp Code
Antigravity CLI
Antigravity CLI
Claude Code
Claude Code
Codex
Codex
Cursor
Cursor
DeepSeek Harness
DeepSeek Harness
Devin CLI
Devin CLI
Factory Droid
Factory Droid
Gemini CLI
Gemini CLI
GitHub Copilot CLI
GitHub Copilot CLI
Grok Build
Grok Build
Hermes Agent
Hermes Agent
Kimi Code
Kimi Code
OpenClaw
OpenClaw
OpenCode
OpenCode
Pi
Pi

Features

  • Blocks destructive commands such as git reset --hard, git push --force, and rm -rf on dangerous targets, even inside bash -c or python -c. See Blocked Commands.
  • Blocks secret access to SSH keys, .env files, ~/.aws, and coding-CLI credentials, from the shell and from the agent's file tools. See Secret Protection.
  • Tunes the policy in a GUI. Run npx cc-safety-net gui to pick the Standard, Strict, or Paranoid preset and turn rules on or off. See Modes.
  • Adds blocks through rulebooks: official packs for Terraform, AWS, gcloud, and Azure, or your own JSON. See Official Rulebooks.
  • Shares policy through git. Commit .cc-safety-net/ so clones and cloud sessions get the same rules. See Team Setup.
  • Embeds in your own tools. Call checkCommand from Node.js without installing the hook. See Library API.

Quick start

You need Node.js 18 or higher. Install into the coding CLIs on this machine, then check that protection is working:

npx -y cc-safety-net@latest install
npx -y cc-safety-net@latest doctor

Update with npx -y cc-safety-net@latest update and uninstall with npx -y cc-safety-net uninstall. Keep the @latest qualifier: a bare cc-safety-net spec can run an older copy from the npx cache. Per-CLI requirements are in Installation.

Development

See CONTRIBUTING.md to report a bug or request a feature.

License

MIT

Related plugins

More verified plugins in security-access.

Experimental Auto Review@deepseek-ai/dsh-experimental-auto-reviewPer-tool LLM authorization review for the DeepSeek Harness Auto permission presetDoctor@linxin666/dsh-doctorTransactional rescue mode for DSH profiles with a supervised launcher, isolated recovery capsule, deterministic repairs, health monitoring, and a local Web recovery consolePocketdsh-pocketPut DeepSeek Harness in your pocket: one package, one settings page, and scan a QR code on your phone to access DSH on your computer in sync (LAN + public network, real-time screen mirroring).Codex Subscriptiondsh-codex-subscriptionUse ChatGPT and Codex subscriptions in DeepSeek Harness with OAuth, quota, safe resets, web search, images, and Fast mode