DSH Plugins Marketplace

DSH Plugins

DSH Plugins Marketplace

7,148 plugins indexed · 5,699 installable · 17,937 versions tracked

AllDevelopment & Infrastructure (485)Tools & Capabilities (1496)Memory & Context (199)Workflow & Automation (234)Models & Providers (201)Terminal & Clients (148)Security & Audit (138)Vision & Multimodal (155)UI & Experience (592)Notifications & Integrations (142)Themes & Skins (128)Sessions & Messages (224)Just for Fun (109)

Sort:

Most starsRecently updatedNewestName A–ZInstallable only

138 plugins

dsh-secret-scrub

Irreversible secret-scrubbing guard: rewrites access keys, bearer tokens, and private key blocks into `[REDACTED:<category>]` placeholders before they reach the session log and the model.

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-secret-scrub

Hard-stops further tool calls after a configurable per-session budget is reached.

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-tool-budget

Protect declared workspace subpaths such as .git from writes, and optionally grant extra writable roots under workspace-write.

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-write-protect

Pre-install static security review and runtime guard for dsh plugins: deobfuscation decoding, supply-chain checks, web one-click review/install/uninstall, and optional runtime tool-call guard.

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-plugin-security-review

One-time Full access switch for DeepSeek Harness: new sessions (workspaces and conversations) start with danger-full-access and skip the per-session Full access confirmation; installable as a dsh bund

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-full-access-switch

Tools guard that moves agent-issued `rm` targets to the macOS Trash instead of deleting, with a shell-aware lexer covering compound and disguised commands; a switch in Settings → General turns it off.

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-safe-delete

Manual approval mode ("Manual Mode" / "Ask Mode").

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-tool-approval

Fourth permission preset for dsh: unconfined, GPU-capable sessions (danger-full-access) with per-operation user approval for writes outside the workspace or to protected paths (.git/**, .env*); implem

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-full-with-approval

by SodaZheng

为 DeepSeek Harness 加一道由你掌控的访问验证。An access-verification step for DeepSeek Harness, under your control.

Security & AuditManifest valid

0

MIT

JavaScript

Sep 10, 2026

dsh plugin --profile web add dsh-totp

Applies per-workspace default Agent and permission presets to new root sessions automatically (Settings - Workspace defaults), using only official extension points.

Security & AuditManifest valid

0

dsh plugin --profile web add @ahiosuz/dsh-workspace-tools

Live CVE/supply-chain audit for your workspace's own project dependencies (npm/pip/go), backed by OSV.dev, with a `cve_audit` tool plus optional automatic re-scan on lockfile changes.

Security & AuditManifest valid

0

dsh plugin --profile web add @dsh-plugins/dsh-cve-audit

Agent governance suite: policy-based tool gating (allow/deny/ask with wildcards and priorities), a structured JSONL audit trail, and per-agent token quotas against the host token meter, with state und

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-gov

Policy plugin that gates kubectl by kubeconfig context: hard-deny irreversible verbs outside local clusters, ask for the rest.

Security & AuditManifest valid

0

71/wk

dsh plugin --profile web add dsh-kubectl-guard

by Vladimir-Kryshchenko

Static linter for DeepSeek Harness plugin HTTP routes: every webServer route bypasses the /api gateway's trust check and must pin the Host to loopback itself. PASS/WARN/FAIL per route, as a CLI and a

Security & AuditManifest valid

0

MIT

TypeScript

Aug 22, 2026

dsh plugin --profile web add dsh-route-fence-linter

AI-driven source-code security scanning workbench: 5 model tools (start/finding/status/report/list) plus a /hawkeye web UI and JSON/Markdown/HTML vulnerability reports; zero-dependency Cordis plugin,

Security & Audit

0

Index only — not installable

Background security auditor for DeepSeek Harness: scans agent outputs for secret leakage, checks command safety before execution, and surfaces findings in a persistent audit log.

Security & AuditManifest valid

0

dsh plugin --profile web add @goodandready/dsh-shadow-auditor

Automated approval review: auto-approve read-only tools, auto-deny dangerous commands, fail-closed policy engine.

Security & Audit

0

Index only — not installable

Text hygiene as a dsh plugin: sanitize untrusted text, scan invisible characters, clean LLM formatting, and escape CSV formula injection.

Security & AuditManifest valid

0

99/wk

dsh plugin --profile web add noatmark-dsh-plugin

by JohnXu22786

Blocks agents from reading or writing sensitive files (.env, credentials, key material), masks leaked secret-shaped values in tool results, keeps an audit journal, and exposes safe sg_* inspection too

Security & AuditManifest valid

0

MIT

TypeScript

Aug 17, 2026

dsh plugin --profile web add dsh-secret-guard

by tancheng33

Container-isolated backend for the DeepSeek Harness code-execution seam: Code Mode programs run in a fresh container with no network, a read-only rootfs, and kernel-enforced memory, CPU, and pid ceili

Security & AuditManifest valid

0

MIT

TypeScript

Aug 16, 2026

dsh plugin --profile web add dsh-code-runtime-container

Security-focused Feishu (Lark) channel for DeepSeek Harness: allowlisted remote-agent access with workspace-scoped paths, symlink checks, risk-based approvals, session isolation, redacted logs, and bo

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-feishu-channel

Keeps DSH agents from forgetting your requirements during long tasks. It saves important conditions and completion evidence locally, brings them back after context compaction or session resume, and st

Security & AuditManifest valid

0

dsh plugin --profile web add dsh-completion-guard

Hardening guard for mcp__omni__parse in DeepSeek Harness: a tools/pre-execute listener that denies private/reserved host URLs (SSRF), enforces an allow-list or ask (consent), and is fail-closed when a

Security & Audit

0

Index only — not installable

Runtime security guard for DSH: loader import confinement, HTTP Host header validation, and source patch for VM sandbox escapes (4 CVEs). AI-assisted.

Security & AuditManifest valid

0

139/wk

dsh plugin --profile web add dsh-security-guard

Page 5 of 6