Pre-install static security review and runtime guard for dsh plugins: deobfuscation decoding, supply-chain checks, web one-click review/install/uninstall, and optional runtime tool-call guard.
dsh plugin add ateen18/dsh-plugin-security-review
Reviewed DeepSeek Harness extensions — filter by category, search by capability, and jump straight to each plugin's public source.
Pre-install static security review and runtime guard for dsh plugins: deobfuscation decoding, supply-chain checks, web one-click review/install/uninstall, and optional runtime tool-call guard.
dsh plugin add ateen18/dsh-plugin-security-review
Workspace-scoped Semgrep SAST tool for DeepSeek Harness with a managed Windows x64 runtime, structured bounded findings, cancellation and timeout controls, and user-approved sandbox escalation. Installs from npm as @aaub-software/dsh-semgrep-sast.
dsh plugin add Baiiduu/dsh-semgrep-sast#semgrep-sast
Static and runtime security guard for dsh: rule-based scans for malicious code, prompt injection and token waste, runtime interception of dangerous tool calls, /scan command, plugin_scan tool, web panel, and allowlist.
dsh plugin add bigclawd/dsh-security-guard
Static pre-install security auditor for plugin bundles: lifecycle scripts, dynamic execution, credential-exfiltration combos, and patch-layer hazards, with zero dependencies and in-memory tar parsing.
dsh plugin add BotonJ/dsh-plugin-sentinel
Agent security guardrail: intercepts and audits every tool call, requiring human confirmation on sensitive operations.
dsh plugin add cdxiaodong/dsh-guardian
Scans skills and MCP configs for prompt injection, homoglyphs, hidden Unicode, dangerous shell, and credential leaks.
dsh plugin add ChenLaoshiYF/dsh-mcpguard
Commitment write-gate: operator-authored rules enforced before a tool call runs — a deterministic guard tier plus an LLM-judge tier, fail-closed by default, every block written to a contradictions log.
dsh plugin add couldbeme/dsh-write-gate
LLM-assisted auto approval with countdown fallback for the Auto permission preset: static rules, risk tiers, breaker and file audit.
dsh plugin add cuddly-guacamole/dsh-auto-approval-llm
Automated approval review: auto-approve read-only tools, auto-deny dangerous commands, fail-closed policy engine.
dsh plugin add DamonKoy/dsh-plugins#dsh-approve-for-me
Automatic secret redaction in tool results: masks API keys, tokens, JWTs, private keys and configured secrets before the model sees them.
dsh plugin add DamonKoy/dsh-plugins#dsh-secret-redactor
Pre-install supply-chain checks for DeepSeek Harness plugins: verify the tarball you are about to install matches the source you read, before any code runs.
dsh plugin add Darren-Tang/dsh-provenance
DSH Desktop plugin safety guard: self-repairs plugin load crashes and runs 8 core safety checks (2 optional: deep-config & smoke), prompting you when a plugin changes. Non-commercial source-available.
dsh plugin add DingZhiQi5596/dsh-plugin-guard
Static security scanner for DSH plugins: read-only audit (exec, credentials, exfiltration, obfuscation, install scripts, bundle manifest) with a 0-100 risk score.
dsh plugin add Eligahyu/dsh-sentinel-scanner
PTES-based penetration testing plugin with Root-Orchestrator architecture for DeepSeek Harness.
dsh plugin add fb0sh/dsh-pentester
Replaces the dsh web startup to allow binding 0.0.0.0, gated by username/password login: signed session cookies, /api route protection, an auth tab in the settings panel, and a reset CLI that rotates the signing key to invalidate all sessions.
dsh plugin add GDWhisper/dsh-web-startup-auth
Policy plugin that gates kubectl by kubeconfig context: hard-deny irreversible verbs outside local clusters, ask for the rest.
dsh plugin add gengwg/dsh-kubectl-guard
Background security auditor for DeepSeek Harness: scans agent outputs for secret leakage, checks command safety before execution, and surfaces findings in a persistent audit log.
dsh plugin add GooDAnDReaDY/dsh-shadow-auditor
Keeps DSH agents from forgetting your requirements during long tasks. It saves important conditions and completion evidence locally, brings them back after context compaction or session resume, and stops partial work from being reported as the whole task done.
dsh plugin add GreenLv/dsh-completion-guard
Authorized pentest mode for DeepSeek Harness — exploration chain, assets and findings with a Web view.
dsh plugin add howmp/dsh-pentest
Caddy forward_auth administrator login for DeepSeek Harness Web, with Argon2id passwords, revocable sessions, bilingual UI, and a native sidebar sign-out action.
dsh plugin add hxy91819/dsh-auth
Vets local, npm, and GitHub plugin source before installation, blocks configured high-risk tool calls at runtime, audits output secret patterns, and writes HMAC-chained local audit logs.
dsh plugin add iiiweiii/dsh-guardwall
Manual approval mode ("Manual Mode" / "Ask Mode").
dsh plugin add ilharp/dsh-tool-approval
Multi-user login gateway for the DSH web UI: the first visit creates the admin account, admins add and manage users in the GUI settings panel, ordinary users see only their own conversations, and unauthenticated visitors are redirected to /login.
dsh plugin add islibaodong/dsh-login
Requires one-shot user approval before configured tools (default bash, pwsh) execute — gated tools pause and ask, everything else delegates, and a missing approval channel fails closed.
dsh plugin add J0ss077/dsh-always-require-tools-approval
Page 123 of 138
Filter by category or keyword — every listing is a public GitHub project.
Commands follow the upstream list; check each repo's README for exact package names.
Plugins run third-party code with your permissions — read the source first.
This directory is a snapshot of the community-maintained awesome-dsh-plugin list (updated 2026-09-07). Listings link to the authors' repositories; inclusion is not an endorsement or a security review. Missing a plugin? Contribute to the upstream list.