DSH Plugins Marketplace

DSH Plugins

Plugins

/

Security & Audit

/

dsh-pluginGuard

w

dsh-pluginGuard

Manifest valid★ 1

Plugin Guard for DeepSeek Harness (DSH): isolate broken plugins so the web UI never goes down, with one-click self-update from npm.

UI (client)hasBundlePatch

English | 中文

dsh-plugin-guard

A safety-guard plugin for DeepSeek Harness (DSH) — a broken plugin can never take your web UI down.

Plugin health scan · Damage isolation · Enable / disable / uninstall · One-click self-update from npm

npm ci license

What is it · Why it cannot crash · Features · Install · Update · Standalone guard · FAQ · License

What is it

dsh-plugin-guard is a plugin for DeepSeek Harness (DSH) that adds a Plugin Guard tab under Settings → Plugins. It watches over the plugins you install into your user profile: list them, enable / pause / uninstall them, scan them for damage, and — most importantly — isolate any plugin that would otherwise crash the whole web client on startup.

It also keeps itself healthy: the tab checks npm for a newer version of dsh-plugin-guard and shows a one-click update button when one is available.

Everyday stateA broken plugin, isolated
Plugin Guard in a healthy profileA damaged plugin quarantined while the web client stays up

Right: demo-crash-plugin throws on import — without the guard it takes the whole web client down at boot; with the guard it is quarantined and shown as damaged, while everything else keeps running.

Why it cannot crash

GuaranteeHow
Other plugins won't crash the web UIThe guard imports every user plugin entry in isolation; anything that throws is removed from the boot bundles, disabled via cordis.patch.yml, and recorded in dsh-plugin-guard-damage.json as "damaged plugin" instead of breaking startup.
The guard itself never crashesEvery server entry point and every UI render is wrapped in failure isolation (route try/catch, React error boundary, guarded module loading). At worst, the guard's own tab is unavailable — the rest of the web client is untouched.
DSH upgrades won't break itThe plugin imports zero DSH runtime packages. It only uses Node.js built-ins and defensively probes the loader / slots APIs, so a DSH upgrade degrades it gracefully instead of crashing it.

Features

  • Plugin Guard tab in Settings → Plugins: lists only the plugins you installed yourself (built-in/runtime plugins are never shown or touched).
  • Scan & isolate: one click re-validates every user plugin and quarantines the broken ones.
  • Enable / pause / uninstall user plugins, persisted across restarts through the profile's cordis.patch.yml.
  • Bilingual UI (English / 中文) that follows the DSH language setting automatically.
  • Self-update check: compares the running version with npm; shows an Update now button when a newer release exists and installs it in place (restart the web client to finish).
  • Standalone guard script (lib/profile-guard.js) that can repair a profile before the web client even starts.

All writes are confined to the user profile directory: DSH_HOME (or dsh_home) when set, otherwise ~/.dsh/profiles/web (same layout on macOS, Linux, and Windows). The application install directory is never modified.

Install

With the DSH CLI:

dsh plugin --profile web add dsh-plugin-guard

Or edit <dsh-home>/profiles/web/package.json by hand:

{
  "dependencies": {
    "dsh-plugin-guard": "^0.1.0"
  },
  "dsh": {
    "profile": {
      "bundles": ["dsh-plugin-guard"]
    }
  }
}

then run pnpm install (or npm install) in that profile directory and restart the DSH web client.

<dsh-home> resolves to $DSH_HOME, then $dsh_home, then ~/.dsh.

Update

Open Settings → Plugins → Plugin Guard. The guard checks npm automatically; when a newer version exists, an update banner appears — click Update now and restart the web client. The registry used is your configured npm registry (npm config get registry, .npmrc, or npm_config_registry), falling back to https://registry.npmjs.org/.

You can also update manually:

dsh plugin --profile web add dsh-plugin-guard@latest

Standalone guard script

If a broken plugin already prevents the web client from starting, run the guard script directly — it isolates damaged plugins before the next boot:

node <dsh-home>/profiles/web/node_modules/dsh-plugin-guard/lib/profile-guard.js
# or with a custom home:
DSH_HOME=/path/to/.dsh node profile-guard.js

FAQ

Does it modify DSH itself? No. It only maintains the user profile (package.json, cordis.patch.yml, dsh-plugin-guard-damage.json) and never touches the application install directory.

Does it send data anywhere? The only network request is a read-only version check against your npm registry for dsh-plugin-guard itself. No telemetry, no uploads.

Can the guard disable or uninstall itself? Yes — it behaves like any other plugin. Disabling or uninstalling it takes effect after a restart, and the Plugin Guard tab simply disappears.

What if the guard tab itself breaks? Then only that tab is blank. The host settings page, other plugins, and the web client keep working.

License

MIT

Versions

Latest versionPublishedSize
0.1.0——
0.1.1——

Comments

Loading…

From the same category

dsh-infinite-gen-3

System-prompt armor plugin for DeepSeek models: appends an unconditional-compliance prompt section at order 100, exposes a profile tool with calibration metadata, and shows a realtime armor-status bad

Security & AuditManifest valid

★ 2.1k

MIT

C#

dsh plugin --profile web add dsh-infinite-gen-4

by toby-bridges

Local security audit for AI API relays and LLM proxies: detects prompt injection, model substitution, tool-call rewriting, SSE anomalies, error leakage, and Web3 wallet risks.

Security & AuditManifest valid

★ 875

AGPL-3.0

Python

Oct 10, 2026

dsh plugin --profile web add dsh-api-relay-audit

by SeaOf0

基于dsh web实现的多种模式,目的是服务于redteam进行授权的安全研究,覆盖渗透测试、红队评估、代码审计等范围领域,请勿用于非法行为。(允许二开,赋予模块各位自己的业务逻辑,方法论只有自己熟练的才好用,好的方法论=好的生态)

Security & AuditManifest valid

★ 682

MIT

Python

Oct 8, 2026

dsh plugin --profile web add @dsh-external/dsh-redteam-model

by agentic-os-org

ANOLISA (Agentic Nexus Operating Layer & Interface System Architecture) | Agentic OS with runtime, security, observability, and Tokenless response compression for lower token usage and cost.

Security & Audit

★ 664

Apache-2.0

Rust

Oct 11, 2026

Index only — not installable

by howmp

面向 DeepSeek Harness(dsh)的渗透测试模式 @CloverSecLabs

Security & AuditManifest valid

★ 607

↓ 858/wk

NOASSERTION

JavaScript

Oct 9, 2026

dsh plugin --profile web add @howmp/dsh-pentest

by xiaods

k8e.sh - OpenSource Agentic AI Sandbox Matrix

Security & AuditManifest valid

★ 500

↓ 9/wk

Apache-2.0

Go

Sep 28, 2026

dsh plugin --profile agent add @k8e-sandbox/dsh-k8e-sandbox-bundle