Model-based permission approval: an approval-request answerer backed by a separate reviewer model.
dsh plugin add Letter2025/dsh-approval-llm
Reviewed DeepSeek Harness extensions — filter by category, search by capability, and jump straight to each plugin's public source.
Model-based permission approval: an approval-request answerer backed by a separate reviewer model.
dsh plugin add Letter2025/dsh-approval-llm
AI-driven source-code security scanning workbench: 5 model tools (start/finding/status/report/list) plus a /hawkeye web UI and JSON/Markdown/HTML vulnerability reports; zero-dependency Cordis plugin, installable as agent preset or npm package.
dsh plugin add liuqingman/dsh-hawkeye-scan#npm
Static capability disclosure for DeepSeek Harness plugins: a Settings page and CLI that list installed plugins' capabilities, literal destinations, install scripts, and injection shapes (prompt registrations, shipped skill text, bundle patch), each with file:line evidence. Code-determined, reproducible, zero-token. Disclosure only — not a security verdict, never a safety claim.
dsh plugin add liuwenji007/dsh-trust-check
CC-style auto-approval for DeepSeek Harness: deterministic deny/allow rules plus a two-stage allow/reject classifier with a circuit breaker and denial guidance.
dsh plugin add log-li/dsh-automode
Adds dangerous-operation policy checks, output redaction, and a security-review workflow.
dsh plugin add lonelymoon87/dsh-guardian
Re-validates Cloudflare Access JWTs at the DSH origin so Settings, Credentials, Agent Preset management, and model discovery work from a remote hostname.
dsh plugin add Luawig/dsh-cloudflare-access
File-change diff bar with keep/undo summary, plus dangerous-command approval and red highlighting for bash/pwsh.
dsh plugin add LWLAymh/dsh-edit-guardian
Read-only SonarQube Community Build tools: instance status, project Quality Gate for a branch or pull request, issue and Security Hotspot search, single hotspot detail, and coverage, duplication or caller-selected measures. Issue and hotspot results carry a normalized location with component key, file path, line and text range.
dsh plugin add maxmilian/dsh-sonarqube
Read-only DSH plugin auditor with static scanning, current-session model review, and confirmation gates.
dsh plugin add Mengshang-spec/dsh-plugin-trustlens
Watches DSH and plugin releases, retests exact published artifacts in disposable runners, publishes machine-readable compatibility evidence, and reconciles managed issues after fixes.
dsh plugin add MicroMilo/upstream-radar
Risk-gated approval automation for DeepSeek Harness: flash pre-classifies whether a write/command is irreversible — safe operations are auto-approved, dangerous ones are escalated to human approval (fail-safe). File-diff review with one-click revert and session-scoped snapshots (v0.5.1: precise snapshots via tool-call parameter tracing, incl. human-approval cases).
dsh plugin add moon09300731/dsh-approval-gate
An independent approval subagent judges every sandbox escalation, with a configurable model and an audit log.
dsh plugin add MoonlitDropOfBlood/dsh-agent-approval
Fine-grained permission gateway: per-category tool-call review (outside-workspace directories, commands, file read/write, subagents, repeated actions) with global & per-project allow/deny exceptions, quick-tool defaults, custom rules, a bilingual approval modal with inline diff details, custom rejection reasons and a sandbox-upgrade flow.
dsh plugin add MrWeiCodes/dsh-permgate
Tools guard that moves agent-issued `rm` targets to the macOS Trash instead of deleting, with a shell-aware lexer covering compound and disguised commands; a switch in Settings → General turns it off.
dsh plugin add NattoCB/dsh-safe-delete
Adds an approval-mode toggle next to the permission selector: default approval keeps per-call confirmation, bypass approval auto-approves every tool call while staying in Workspace Write.
dsh plugin add NEVSTOP-LAB/dsh-approval-mode
Local security audit: config, plugin origins, sessions, network exposure — read-only redacted risk report.
dsh plugin add omdsh-dev/dsh-security-audit
Support for the microsandbox backend.
dsh plugin add omdsh-dev/sandbox-micro
Microsoft cross-platform sandbox support.
dsh plugin add omdsh-dev/sandbox-mxc
Provenance-aware execution security that tracks sensitive data across DSH tool calls and blocks risky exfiltration before execution.
dsh plugin add onlyqzq/dsh-riskproof
Encrypted local credentials vault for the Harness: a web settings page and vault_* tools to store, search and copy passwords, API keys, TOTP secrets and card data, with health audits, expiry rotation, imports/exports and read-only/ask access modes.
dsh plugin add Ox0400/dsh-vault
Autonomous permission classifier for the auto preset: tool-scoped allow/deny rules, an LLM semantic judge, and git checkpointing for unattended sessions.
dsh plugin add PAKIKNOWLEDGE/dsh-auto-classifier
Plugin value auditor: pre-install review (source scan + LLM judge) and post-install audit of installed bundles, with model-switch re-audit reminders.
dsh plugin add pengxuding/dsh-plugin-judge
Read-only security and compliance plugin for DeepSeek Harness: prompt-injection detection, Chinese-PII redaction, and a local configuration audit with redacted, reproducible reports.
dsh plugin add PensiveFei/dsh-secure-audit
Page 3 of 5
Filter by category or keyword — every listing is a public GitHub project.
Commands follow the upstream list; check each repo's README for exact package names.
Plugins run third-party code with your permissions — read the source first.
This directory is a snapshot of the community-maintained awesome-dsh-plugin list (updated 2026-09-07). Listings link to the authors' repositories; inclusion is not an endorsement or a security review. Missing a plugin? Contribute to the upstream list.