DSH Plugins Marketplace
7,146 plugins indexed · 5,699 installable · 17,917 versions tracked
138 plugins
by shuxue6662-a11y
Zero-interruption audit and fuse blocking for DeepSeek Harness: silently records every tool call with deterministic risk scoring, cumulative-risk bonuses, risk-level breakdowns and retention-based cle
★ 0
MIT
TypeScript
Aug 17, 2026
dsh plugin --profile web add dsh-risk-guardClaude Code-style permission rules engine: hard/deny/ask/allow tiers with a hard tier above full access, workspace-scoped rules, wildcard path protection, and a visual staged editor; rules persist in
★ 0
dsh plugin --profile web add dsh-permissionsP0–P4 deterministic-first permission gate with permissive tier, learning sedimentation and approval-history UI; hard-deny credentials and protected paths, auto-allow internal read-only tools.
★ 0
↓ 956/wk
dsh plugin --profile web add dsh-perm-gateRules execution engine for dsh: parses AGENTS.md, hard-blocks rule-violating tool calls, text-based B/D rule auditing, /guard command, version-guard for versioned files, and free-zone support (engine
★ 0
dsh plugin --profile web add dsh-rule-engineRead-only agent-fleet credential hygiene audit: credential-file permissions, embedded credentials in git remotes (masked in output), and provider token literal counts; zero-dependency and deterministi
★ 0
dsh plugin --profile web add dsh-fleet-auditAuto-approval permission guard: a middle tier between workspace-write and danger-full-access — auto-allows safe operations inside trust directories, always asks a human for destructive ones, with 11 p
★ 0
dsh plugin --profile web add dsh-perm-guardCommitment write-gate: operator-authored rules enforced before a tool call runs — a deterministic guard tier plus an LLM-judge tier, fail-closed by default, every block written to a contradictions log
★ 0
↓ 54/wk
dsh plugin --profile web add dsh-write-gateRuntime security gate on the tool pipeline: denies calls naming hosts outside an egress allowlist, redacts credentials from results at the canonical value rather than only the rendered content, and ap
★ 0
dsh plugin --profile web add dsh-egress-guardRedacts supported secret patterns from the `session-telemetry/record` export copy before configured telemetry backends receive it.
★ 0
dsh plugin --profile web add dsh-telemetry-redactorTurn-scoped “Allow for this task” approvals: automatically allow matching `danger-full-access` escalations only for the current task, then expire.
★ 0
dsh plugin --profile web add dsh-turn-approvalTaints the agent when tool results carry untrusted content, gates the privileged calls that follow, and refuses credentials passed to network-capable tools in every mode.
★ 0
dsh plugin --profile web add dsh-taintguardWorkspace-scoped Semgrep SAST tool for DeepSeek Harness with a managed Windows x64 runtime, structured bounded findings, cancellation and timeout controls, and user-approved sandbox escalation. Instal
★ 0
Uses an isolated LLM review to approve or reject DSH sandbox permission requests.
★ 0
dsh plugin --profile web add dsh-llm-approve-for-mePre-install supply-chain poison scanner for DSH plugins: AST (JS-X-Ray) + deobfuscation + regex heuristics, exits non-zero on findings for CI gating.
★ 0
dsh plugin --profile web add dsh-poison-guardFile-change diff bar with keep/undo summary, plus dangerous-command approval and red highlighting for bash/pwsh.
★ 0
dsh plugin --profile web add dsh-edit-guardianSingle-bundle security analysis plugin: bootstrap tool narrowing, a domain router, and 25 reverse-engineering tools covering APK, native binary, protocol, malware and LLM samples with on-demand refere
★ 0
Commit-time audit harness for AI coding agents: 24 git-diff rules (secrets, out-of-scope edits, prompt injection), HMAC-signed audit trail, snapshot rollback, and an MCP server with 84 tools. Installa
★ 0
Adds dangerous-operation policy checks, output redaction, and a security-review workflow.
★ 0
↓ 59/wk
dsh plugin --profile web add dsh-guardianPlugin value auditor: pre-install review (source scan + LLM judge) and post-install audit of installed bundles, with model-switch re-audit reminders.
★ 0
↓ 63/wk
dsh plugin --profile web add dsh-plugin-judgePermission mode between workspace-write and full access: shell commands are checked by deterministic rules and a subagent review; irreversible or system-level actions require explicit approval.
★ 0
dsh plugin --profile web add dsh-almost-full-accessDeterministic code security review: 40+ rules, secret entropy detection, staged-diff review, SARIF export, baseline acceptance, SBOM-lite dependency inventory and health self-check.
★ 0
dsh plugin --profile web add dsh-code-securityIrreversible secret-scrubbing guard: rewrites access keys, bearer tokens, and private key blocks into `[REDACTED:<category>]` placeholders before they reach the session log and the model.
★ 0
dsh plugin --profile web add dsh-secret-scrubHard-stops further tool calls after a configurable per-session budget is reached.
★ 0
dsh plugin --profile web add dsh-tool-budgetProtect declared workspace subpaths such as .git from writes, and optionally grant extra writable roots under workspace-write.
★ 0
dsh plugin --profile web add dsh-write-protect