DSH Plugins Marketplace
7,148 plugins indexed · 5,699 installable · 18,270 versions tracked
124 plugins
Pre-install static security review and runtime guard for dsh plugins: deobfuscation decoding, supply-chain checks, web one-click review/install/uninstall, and optional runtime tool-call guard.
★ 0
dsh plugin --profile web add dsh-plugin-security-reviewDeterministic code security review: 40+ rules, secret entropy detection, staged-diff review, SARIF export, baseline acceptance, SBOM-lite dependency inventory and health self-check.
★ 0
dsh plugin --profile web add dsh-code-securityTools guard that moves agent-issued `rm` targets to the macOS Trash instead of deleting, with a shell-aware lexer covering compound and disguised commands; a switch in Settings → General turns it off.
★ 0
dsh plugin --profile web add dsh-safe-deleteManual approval mode ("Manual Mode" / "Ask Mode").
★ 0
dsh plugin --profile web add dsh-tool-approvalOne-time Full access switch for DeepSeek Harness: new sessions (workspaces and conversations) start with danger-full-access and skip the per-session Full access confirmation; installable as a dsh bund
★ 0
dsh plugin --profile web add dsh-full-access-switchFourth permission preset for dsh: unconfined, GPU-capable sessions (danger-full-access) with per-operation user approval for writes outside the workspace or to protected paths (.git/**, .env*); implem
★ 0
dsh plugin --profile web add dsh-full-with-approvalApplies per-workspace default Agent and permission presets to new root sessions automatically (Settings - Workspace defaults), using only official extension points.
★ 0
dsh plugin --profile web add @ahiosuz/dsh-workspace-toolsby SodaZheng
为 DeepSeek Harness 加一道由你掌控的访问验证。An access-verification step for DeepSeek Harness, under your control.
★ 0
MIT
JavaScript
Sep 10, 2026
dsh plugin --profile web add dsh-totpLive CVE/supply-chain audit for your workspace's own project dependencies (npm/pip/go), backed by OSV.dev, with a `cve_audit` tool plus optional automatic re-scan on lockfile changes.
★ 0
dsh plugin --profile web add @dsh-plugins/dsh-cve-auditPolicy plugin that gates kubectl by kubeconfig context: hard-deny irreversible verbs outside local clusters, ask for the rest.
★ 0
↓ 71/wk
dsh plugin --profile web add dsh-kubectl-guardby Vladimir-Kryshchenko
Static linter for DeepSeek Harness plugin HTTP routes: every webServer route bypasses the /api gateway's trust check and must pin the Host to loopback itself. PASS/WARN/FAIL per route, as a CLI and a
★ 0
MIT
TypeScript
Aug 22, 2026
dsh plugin --profile web add dsh-route-fence-linterAgent governance suite: policy-based tool gating (allow/deny/ask with wildcards and priorities), a structured JSONL audit trail, and per-agent token quotas against the host token meter, with state und
★ 0
dsh plugin --profile web add dsh-govText hygiene as a dsh plugin: sanitize untrusted text, scan invisible characters, clean LLM formatting, and escape CSV formula injection.
★ 0
↓ 99/wk
dsh plugin --profile web add noatmark-dsh-pluginby JohnXu22786
Blocks agents from reading or writing sensitive files (.env, credentials, key material), masks leaked secret-shaped values in tool results, keeps an audit journal, and exposes safe sg_* inspection too
★ 0
MIT
TypeScript
Aug 17, 2026
dsh plugin --profile web add dsh-secret-guardby tancheng33
Container-isolated backend for the DeepSeek Harness code-execution seam: Code Mode programs run in a fresh container with no network, a read-only rootfs, and kernel-enforced memory, CPU, and pid ceili
★ 0
MIT
TypeScript
Aug 16, 2026
dsh plugin --profile web add dsh-code-runtime-containerBackground security auditor for DeepSeek Harness: scans agent outputs for secret leakage, checks command safety before execution, and surfaces findings in a persistent audit log.
★ 0
dsh plugin --profile web add @goodandready/dsh-shadow-auditorSecurity-focused Feishu (Lark) channel for DeepSeek Harness: allowlisted remote-agent access with workspace-scoped paths, symlink checks, risk-based approvals, session isolation, redacted logs, and bo
★ 0
dsh plugin --profile web add dsh-feishu-channelAutonomous permission classifier for the auto preset: tool-scoped allow/deny rules, an LLM semantic judge, and git checkpointing for unattended sessions.
★ 0
dsh plugin --profile web add dsh-auto-classifierRead-only DSH plugin auditor with static scanning, current-session model review, and confirmation gates.
★ 0
dsh plugin --profile web add dsh-plugin-trustlensStatic and runtime security guard for dsh: rule-based scans for malicious code, prompt injection and token waste, runtime interception of dangerous tool calls, /scan command, plugin_scan tool, web pan
★ 0
dsh plugin --profile web add dsh-security-guardSemantic risk grading and progressive authorization: classifies tool calls into safe/risky/redline, asks before irreversible actions, auto-allows only approved-and-succeeded signatures.
★ 0
dsh plugin --profile web add dsh-risk-gateTransport-level authentication gate for the DeepSeek Harness Web GUI with server-side sessions, HttpOnly cookies, IP-based login throttling, and an scrypt password CLI.
★ 0
dsh plugin --profile web add @summersec/dsh-web-authGlobal prompt-injection / context-virus defense for DeepSeek Harness: scans tool arguments, tool results, pre-model messages and the outbound stream; quarantine/block/monitor modes, canary trap, and a
★ 0
dsh plugin --profile web add dsh-prompt-antivirusby Top-Celestial-Company-Ltd
⚡ DROS™ VajraClaw for DSH: Deterministic Runtime Execution Governance & Security Circuit-Breaker Plugin
★ 0
TypeScript
Sep 5, 2026
dsh plugin --profile web add dsh-plugin-vajraclaw