DSH Plugins Marketplace

DSH Plugins

DSH Plugins Marketplace

7,148 plugins indexed · 5,699 installable · 17,937 versions tracked

AllDevelopment & Infrastructure (485)Tools & Capabilities (1496)Memory & Context (199)Workflow & Automation (234)Models & Providers (201)Terminal & Clients (148)Security & Audit (138)Vision & Multimodal (155)UI & Experience (592)Notifications & Integrations (142)Themes & Skins (128)Sessions & Messages (224)Just for Fun (109)

Sort:

Most starsRecently updatedNewestName A–ZInstallable only

124 plugins

dsh-workspace-write-plus

Adds a workspace-write++ permission that keeps file tools inside the workspace while skipping the Windows process sandbox for wildcard-allowlisted executables such as Git Bash.

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-workspace-write-plus

Claude Code-style permission rules engine: hard/deny/ask/allow tiers with a hard tier above full access, workspace-scoped rules, wildcard path protection, and a visual staged editor; rules persist in

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-permissions

P0–P4 deterministic-first permission gate with permissive tier, learning sedimentation and approval-history UI; hard-deny credentials and protected paths, auto-allow internal read-only tools.

Security & AuditManifest valid

0

956/wk

dsh plugin --profile web add dsh-perm-gate

A LAN password gate for the Web UI: phones and tablets on the same network log in with a shared key and see the same sessions in real time, with a built-in randomUUID polyfill for plain-HTTP origins.

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-lan-pass

Rules execution engine for dsh: parses AGENTS.md, hard-blocks rule-violating tool calls, text-based B/D rule auditing, /guard command, version-guard for versioned files, and free-zone support (engine

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-rule-engine

Read-only agent-fleet credential hygiene audit: credential-file permissions, embedded credentials in git remotes (masked in output), and provider token literal counts; zero-dependency and deterministi

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-fleet-audit

Auto-approval permission guard: a middle tier between workspace-write and danger-full-access — auto-allows safe operations inside trust directories, always asks a human for destructive ones, with 11 p

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-perm-guard

String-matches tool-call input arguments, blocks dangerous tool calls (deny) or allows them with an injected warning (warn), and ships a full rules-management panel.

Security & AuditManifest valid

0

dsh plugin --profile web add @jypjypjypjyp/dsh-guardrail

Commitment write-gate: operator-authored rules enforced before a tool call runs — a deterministic guard tier plus an LLM-judge tier, fail-closed by default, every block written to a contradictions log

Security & AuditManifest valid

0

54/wk

dsh plugin --profile web add dsh-write-gate

Runtime security gate on the tool pipeline: denies calls naming hosts outside an egress allowlist, redacts credentials from results at the canonical value rather than only the rendered content, and ap

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-egress-guard

Redacts supported secret patterns from the `session-telemetry/record` export copy before configured telemetry backends receive it.

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-telemetry-redactor

Turn-scoped “Allow for this task” approvals: automatically allow matching `danger-full-access` escalations only for the current task, then expire.

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-turn-approval

Taints the agent when tool results carry untrusted content, gates the privileged calls that follow, and refuses credentials passed to network-capable tools in every mode.

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-taintguard

Uses an isolated LLM review to approve or reject DSH sandbox permission requests.

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-llm-approve-for-me

by tancheng33

HashiCorp Vault backend for the DeepSeek Harness credential seam: central secrets, AppRole machine auth, rotation without restart, and no long-lived provider key on the agent host

Security & AuditManifest valid

0

MIT

TypeScript

Aug 16, 2026

dsh plugin --profile web add dsh-credentials-vault

Vets local, npm, and GitHub plugin source before installation, blocks configured high-risk tool calls at runtime, audits output secret patterns, and writes HMAC-chained local audit logs.

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-guardwall

Pre-install supply-chain poison scanner for DSH plugins: AST (JS-X-Ray) + deobfuscation + regex heuristics, exits non-zero on findings for CI gating.

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-poison-guard

Adds dangerous-operation policy checks, output redaction, and a security-review workflow.

Security & AuditManifest valid

0

59/wk

dsh plugin --profile web add dsh-guardian

Plugin value auditor: pre-install review (source scan + LLM judge) and post-install audit of installed bundles, with model-switch re-audit reminders.

Security & AuditManifest valid

0

63/wk

dsh plugin --profile web add dsh-plugin-judge

Permission mode between workspace-write and full access: shell commands are checked by deterministic rules and a subagent review; irreversible or system-level actions require explicit approval.

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-almost-full-access

File-change diff bar with keep/undo summary, plus dangerous-command approval and red highlighting for bash/pwsh.

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-edit-guardian

Irreversible secret-scrubbing guard: rewrites access keys, bearer tokens, and private key blocks into `[REDACTED:<category>]` placeholders before they reach the session log and the model.

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-secret-scrub

Hard-stops further tool calls after a configurable per-session budget is reached.

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-tool-budget

Protect declared workspace subpaths such as .git from writes, and optionally grant extra writable roots under workspace-write.

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-write-protect

Page 4 of 6