Independent directory for the DSH ecosystem

Find the right DSH plugin for your next workflow

Reviewed DeepSeek Harness extensions — filter by category, search by capability, and jump straight to each plugin's public source.

3304 plugins 23 categories 12 editor's picks Updated 2026-09-07
Showing 97–112 of 112 Clear filters

Security & Permissions

Login gate for the dsh web surface: password or shared-token authentication, session cookies, rate limiting, and a user-management CLI (dsh.bundle manifest since 0.4.1, one-command `dsh plugin add` mounting).

dsh plugin add TecFancy/dsh-auth-gate

Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.

dsh plugin add toby-bridges/api-relay-audit

Vets third-party plugins before you trust them: static scan for malicious patterns (exfiltration, credential access, obfuscation, persistence) and over-privileged path use, transitive-dependency coverage, official-package hash baseline for supply-chain tamper detection, and an optional plugin-tool call gate.

dsh plugin add truelove-dreamer/dsh-plugin-vetting

Audits every plugin HTTP route in a profile for a browser-trust fence: plugin routes win the web server's longest-prefix match ahead of the /api gateway, so they never see its trust check and must pin the Host to loopback themselves. Grades PASS/WARN/FAIL per route and fails a fence that compares Origin to Host without pinning it (bypassable by DNS rebinding). Ships as a CLI for CI and a route_fence_scan tool.

dsh plugin add Vladimir-Kryshchenko/dsh-route-fence-linter

Login gate for the dsh web UI: unauthenticated visitors get a login/register page and the first registrant becomes admin; includes user and role management plus login and access audit logs.

dsh plugin add weibaohui/user-management

Plugin trust pipeline for DeepSeek Harness: deterministic static scan with verdicts, opt-in runtime guard with honeypot lures, agent audit-protocol skill, and a browser shield status light. Alarm-only, never an enforcer.

dsh plugin add wulun811/dsh-plugin-vet

Security-focused Feishu (Lark) channel for DeepSeek Harness: allowlisted remote-agent access with workspace-scoped paths, symlink checks, risk-based approvals, session isolation, redacted logs, and bounded message queues.

dsh plugin add WyattJHayes/dsh-feishu-channel

A LAN password gate for the Web UI: phones and tablets on the same network log in with a shared key and see the same sessions in real time, with a built-in randomUUID polyfill for plain-HTTP origins.

dsh plugin add x2802490130-prog/dsh-lan-pass

Password + TOTP two-factor authentication gateway for the dsh web UI: every HTTP request and WebSocket upgrade is refused until login, with per-source lockout, global rate limits and one-time backup codes.

dsh plugin add xbzbing/dsh-auth-gateway

Secure remote access for the DeepSeek Harness Web UI: a login gate, MFA/TOTP, signed session cookies, optional admin/user/guest roles, in-browser workspace selection, and allowlisted remote file previews.

dsh plugin add xgone/dsh-remote

One-time Full access switch for DeepSeek Harness: new sessions (workspaces and conversations) start with danger-full-access and skip the per-session Full access confirmation; installable as a dsh bundle or via patch scripts.

dsh plugin add xtd1145/dsh-full-access-switch

WebUI authentication enforced at the HTTP/transport layer: four-layer login gate (resources, plugin bundles, /api, WebSocket), server-side sessions with HttpOnly cookies.

dsh plugin add Yuuz12/dsh-webui-auth

Fourth permission preset for dsh: unconfined, GPU-capable sessions (danger-full-access) with per-operation user approval for writes outside the workspace or to protected paths (.git/**, .env*); implemented purely as a bundle over the official tools/pre-execute ask hook, no core edits.

dsh plugin add zjuhbh/dsh-full-with-approval

Page 5 of 5

How it works

1. Search the directory

Filter by category or keyword — every listing is a public GitHub project.

2. Copy the install command

Commands follow the upstream list; check each repo's README for exact package names.

3. Review before installing

Plugins run third-party code with your permissions — read the source first.

This directory is a snapshot of the community-maintained awesome-dsh-plugin list (updated 2026-09-07). Listings link to the authors' repositories; inclusion is not an endorsement or a security review. Missing a plugin? Contribute to the upstream list.