Redacts supported secret patterns from the `session-telemetry/record` export copy before configured telemetry backends receive it.
dsh plugin add 030611/dsh-telemetry-redactor
Reviewed DeepSeek Harness extensions — filter by category, search by capability, and jump straight to each plugin's public source.
Redacts supported secret patterns from the `session-telemetry/record` export copy before configured telemetry backends receive it.
dsh plugin add 030611/dsh-telemetry-redactor
Writes local JSONL summaries of per-turn tool counts and coarse verification signals without storing prompts, tool arguments, or result text.
dsh plugin add 030611/dsh-verification-receipt
Appends local hash-chained JSONL receipts for tool results and session events without storing prompts, tool arguments, result text, or raw session IDs.
dsh plugin add 030611/qiushi-dsh-evidence-audit
Authentication gate for the DeepSeek Harness Web UI: login covers pages, /api, /plugins and WebSocket upgrades; PBKDF2 password hashing, HttpOnly SameSite session cookies, IP-based login lockout, a user-management settings panel (users edit their own profile, admins add or remove users and reset passwords), admin-only model and API-key configuration guards, per-user isolation on the REST/list APIs and the WebSocket event streams, session persistence across restarts, a JSONL audit log, and a fail-closed gateway.
dsh plugin add 0QwQ0/dsh-ui-auth
Hard-stop consecutive identical tool calls after a configurable streak so the agent cannot spin in place.
dsh plugin add 173787247/dsh-repeat-stop
Hard-stops further tool calls after a configurable per-session budget is reached.
dsh plugin add 173787247/dsh-tool-budget
Agent governance suite: policy-based tool gating (allow/deny/ask with wildcards and priorities), a structured JSONL audit trail, and per-agent token quotas against the host token meter, with state under $DSH_HOME/gov.
dsh plugin add 863683348/dsh-gov
Installation safety gate for DSH plugins: antivirus-style scan of install scripts, permissions, secrets and network callbacks on local directories or npm tarballs, returning a BLOCK/WARN/PASS verdict before "dsh plugin add".
dsh plugin add 863683348/dsh-plugin-gate
Claude Code-style permission rules engine: hard/deny/ask/allow tiers with a hard tier above full access, workspace-scoped rules, wildcard path protection, and a visual staged editor; rules persist in settings.yaml.
dsh plugin add 940842546/dsh-permissions
Auto-approval permission guard: a middle tier between workspace-write and danger-full-access — auto-allows safe operations inside trust directories, always asks a human for destructive ones, with 11 per-category switches and an audit trail.
dsh plugin add a903067276-rgb/dsh-perm-guard
Single-bundle security analysis plugin: bootstrap tool narrowing, a domain router, and 25 reverse-engineering tools covering APK, native binary, protocol, malware and LLM samples with on-demand reference docs.
dsh plugin add ADWMC/helm-d#helmd
Uses an isolated LLM review to approve or reject DSH sandbox permission requests.
dsh plugin add alaxrpg/dsh-llm-approve-for-me
Permission mode between workspace-write and full access: shell commands are checked by deterministic rules and a subagent review; irreversible or system-level actions require explicit approval.
dsh plugin add Alnita-M/dsh-Almost_Full_Access
Codex-style auto-review permission mode: adds an auto-review preset that auto-approves safe sandbox escalations, asks on risky or ambiguous ones, and rejects critical unconfirmed operations.
dsh plugin add AntaresCorn/dsh-auto-reviewer
Turn-scoped “Allow for this task” approvals: automatically allow matching `danger-full-access` escalations only for the current task, then expire.
dsh plugin add arrow949/dsh-turn-approval
Pre-install static security review and runtime guard for dsh plugins: deobfuscation decoding, supply-chain checks, web one-click review/install/uninstall, and optional runtime tool-call guard.
dsh plugin add ateen18/dsh-plugin-security-review
Workspace-scoped Semgrep SAST tool for DeepSeek Harness with a managed Windows x64 runtime, structured bounded findings, cancellation and timeout controls, and user-approved sandbox escalation. Installs from npm as @aaub-software/dsh-semgrep-sast.
dsh plugin add Baiiduu/dsh-semgrep-sast#semgrep-sast
Static and runtime security guard for dsh: rule-based scans for malicious code, prompt injection and token waste, runtime interception of dangerous tool calls, /scan command, plugin_scan tool, web panel, and allowlist.
dsh plugin add bigclawd/dsh-security-guard
Static pre-install security auditor for plugin bundles: lifecycle scripts, dynamic execution, credential-exfiltration combos, and patch-layer hazards, with zero dependencies and in-memory tar parsing.
dsh plugin add BotonJ/dsh-plugin-sentinel
Agent security guardrail: intercepts and audits every tool call, requiring human confirmation on sensitive operations.
dsh plugin add cdxiaodong/dsh-guardian
Scans skills and MCP configs for prompt injection, homoglyphs, hidden Unicode, dangerous shell, and credential leaks.
dsh plugin add ChenLaoshiYF/dsh-mcpguard
Commitment write-gate: operator-authored rules enforced before a tool call runs — a deterministic guard tier plus an LLM-judge tier, fail-closed by default, every block written to a contradictions log.
dsh plugin add couldbeme/dsh-write-gate
LLM-assisted auto approval with countdown fallback for the Auto permission preset: static rules, risk tiers, breaker and file audit.
dsh plugin add cuddly-guacamole/dsh-auto-approval-llm
Automated approval review: auto-approve read-only tools, auto-deny dangerous commands, fail-closed policy engine.
dsh plugin add DamonKoy/dsh-plugins#dsh-approve-for-me
Page 1 of 5
Filter by category or keyword — every listing is a public GitHub project.
Commands follow the upstream list; check each repo's README for exact package names.
Plugins run third-party code with your permissions — read the source first.
This directory is a snapshot of the community-maintained awesome-dsh-plugin list (updated 2026-09-07). Listings link to the authors' repositories; inclusion is not an endorsement or a security review. Missing a plugin? Contribute to the upstream list.