Adds an `auto` permission preset between workspace-write and danger-full-access: a classifier grants routine sandbox escalations once, while dangerous or uncertain requests still go to a human.
dsh plugin add Jiao-XXX/dsh-auto-approve
Reviewed DeepSeek Harness extensions — filter by category, search by capability, and jump straight to each plugin's public source.
Adds an `auto` permission preset between workspace-write and danger-full-access: a classifier grants routine sandbox escalations once, while dangerous or uncertain requests still go to a human.
dsh plugin add Jiao-XXX/dsh-auto-approve
Rules execution engine for dsh: parses AGENTS.md, hard-blocks rule-violating tool calls, text-based B/D rule auditing, /guard command, version-guard for versioned files, and free-zone support (engine skips free-zone sections).
dsh plugin add jilian-dsh/dsh-rule-engine
Irreversible secret-scrubbing guard: rewrites access keys, bearer tokens, and private key blocks into `[REDACTED:<category>]` placeholders before they reach the session log and the model.
dsh plugin add jkt-check/dsh-secret-scrub
Destructive-command interception gate for dsh: parses shell semantics, judges risk against 41 built-in rules, and holds irreversible rm -rf, git reset --hard, and git push --force style commands at a confirmation gate.
dsh plugin add JohnXu22786/safety-net
Blocks agents from reading or writing sensitive files (.env, credentials, key material), masks leaked secret-shaped values in tool results, keeps an audit journal, and exposes safe sg_* inspection tools that never print raw values.
dsh plugin add JohnXu22786/secret-guard
Honesty guardrails on the tool pipeline: blocks a coding agent from weakening tests, swallowing errors, stubbing type checks, or deleting tests through the shell — nine deterministic hooks, each backed by a planted-failure test proving the guard can fail.
dsh plugin add JW53222/faultseed#dsh
String-matches tool-call input arguments, blocks dangerous tool calls (deny) or allows them with an injected warning (warn), and ships a full rules-management panel.
dsh plugin add jypjypjypjyp/dsh-guardrail
Commit-time audit harness for AI coding agents: 24 git-diff rules (secrets, out-of-scope edits, prompt injection), HMAC-signed audit trail, snapshot rollback, and an MCP server with 83 tools. Installable via dsh plugin add.
dsh plugin add KongFangXun/sofagent#cordis-plugin-sofagent-audit
Read-only agent-fleet credential hygiene audit: credential-file permissions, embedded credentials in git remotes (masked in output), and provider token literal counts; zero-dependency and deterministic.
dsh plugin add LeslieWylie/dsh-fleet-audit
Model-based permission approval: an approval-request answerer backed by a separate reviewer model.
dsh plugin add Letter2025/dsh-approval-llm
AI-driven source-code security scanning workbench: 5 model tools (start/finding/status/report/list) plus a /hawkeye web UI and JSON/Markdown/HTML vulnerability reports; zero-dependency Cordis plugin, installable as agent preset or npm package.
dsh plugin add liuqingman/dsh-hawkeye-scan#npm
Static capability disclosure for DeepSeek Harness plugins: a Settings page and CLI that list installed plugins' capabilities, literal destinations, install scripts, and injection shapes (prompt registrations, shipped skill text, bundle patch), each with file:line evidence. Code-determined, reproducible, zero-token. Disclosure only — not a security verdict, never a safety claim.
dsh plugin add liuwenji007/dsh-trust-check
CC-style auto-approval for DeepSeek Harness: deterministic deny/allow rules plus a two-stage allow/reject classifier with a circuit breaker and denial guidance.
dsh plugin add log-li/dsh-automode
Adds dangerous-operation policy checks, output redaction, and a security-review workflow.
dsh plugin add lonelymoon87/dsh-guardian
Re-validates Cloudflare Access JWTs at the DSH origin so Settings, Credentials, Agent Preset management, and model discovery work from a remote hostname.
dsh plugin add Luawig/dsh-cloudflare-access
File-change diff bar with keep/undo summary, plus dangerous-command approval and red highlighting for bash/pwsh.
dsh plugin add LWLAymh/dsh-edit-guardian
Read-only SonarQube Community Build tools: instance status, project Quality Gate for a branch or pull request, issue and Security Hotspot search, single hotspot detail, and coverage, duplication or caller-selected measures. Issue and hotspot results carry a normalized location with component key, file path, line and text range.
dsh plugin add maxmilian/dsh-sonarqube
Read-only DSH plugin auditor with static scanning, current-session model review, and confirmation gates.
dsh plugin add Mengshang-spec/dsh-plugin-trustlens
Watches DSH and plugin releases, retests exact published artifacts in disposable runners, publishes machine-readable compatibility evidence, and reconciles managed issues after fixes.
dsh plugin add MicroMilo/upstream-radar
Risk-gated approval automation for DeepSeek Harness: flash pre-classifies whether a write/command is irreversible — safe operations are auto-approved, dangerous ones are escalated to human approval (fail-safe). File-diff review with one-click revert and session-scoped snapshots (v0.5.1: precise snapshots via tool-call parameter tracing, incl. human-approval cases).
dsh plugin add moon09300731/dsh-approval-gate
An independent approval subagent judges every sandbox escalation, with a configurable model and an audit log.
dsh plugin add MoonlitDropOfBlood/dsh-agent-approval
Fine-grained permission gateway: per-category tool-call review (outside-workspace directories, commands, file read/write, subagents, repeated actions) with global & per-project allow/deny exceptions, quick-tool defaults, custom rules, a bilingual approval modal with inline diff details, custom rejection reasons and a sandbox-upgrade flow.
dsh plugin add MrWeiCodes/dsh-permgate
Tools guard that moves agent-issued `rm` targets to the macOS Trash instead of deleting, with a shell-aware lexer covering compound and disguised commands; a switch in Settings → General turns it off.
dsh plugin add NattoCB/dsh-safe-delete
Adds an approval-mode toggle next to the permission selector: default approval keeps per-call confirmation, bypass approval auto-approves every tool call while staying in Workspace Write.
dsh plugin add NEVSTOP-LAB/dsh-approval-mode
Page 124 of 138
Filter by category or keyword — every listing is a public GitHub project.
Commands follow the upstream list; check each repo's README for exact package names.
Plugins run third-party code with your permissions — read the source first.
This directory is a snapshot of the community-maintained awesome-dsh-plugin list (updated 2026-09-07). Listings link to the authors' repositories; inclusion is not an endorsement or a security review. Missing a plugin? Contribute to the upstream list.