跳到主内容

安全与治理

排序
NanmiCoderNanmiCoder
116

为 DeepSeek Harness 注入 Auto 权限档:日常项目活在官方沙箱内自动放行,跨沙箱语义风险交给当前模型分类,仅真正模糊处弹一次确认。

$ dsh plugin --profile web add @nanmicoder/dsh-auto-mode
lire1131lire1131
103

为 DSH 提供撤销/回退系统:自动快照配置与插件代码,WebUI/对话/离线工具三入口一键撤销,DSH 起不来时还有安全模式与 GUI 兜底。

$ dsh plugin --profile web add github:lire1131/dsh-undo-plugin
icetomoyoicetomoyo
90

在 DSH 之上提供可命名、可持久、可后台的多 Agent Workflow 引擎,支持保存、暂停、重跑、续跑、生成与审计。

$ dsh plugin --profile web add github:icetomoyo/dsh_workflow
PerryLinkPerryLink
59

为 DeepSeek Harness 补上有界、分层、带审批门、可审计的跨会话记忆:本地 SQLite 存储、memory 工具与每次会话启动注入的冻结快照。

$ dsh plugin --profile web add dsh-memento
THEWOLFWALKERTHEWOLFWALKER
53

DSH 统一通知与远程控制插件:一个 notify() API 对接 27 个推送渠道,同时把审批、提问、会话从手机送回桌面,长任务自动心跳并支持一键停止。

$ dsh plugin --profile web add dsh-notifier
omdsh-devomdsh-dev
39

把 DSH Agent 接进飞书/Lark:在聊天里派任务、看过程、切换工作区和模型;提问、计划、工具审批用卡片回到聊天处理。

$ dsh plugin --profile web add dsh-lark-channel
lxzy-7lxzy-7
28

DeepSeek Harness 的安装安全网:安装前自动快照、启动失败自动回退、不兼容插件自动隔离并生成事故报告自动触发 Agent 分析。

$ dsh plugin --profile web add github:lxzy-7/dsh-plugin-guard
PerryLinkPerryLink
25

在 DSH 工具调用前立一道 YAML 规则闸门,按工具名/参数/路径/Agent/网络目标产生 allow/deny/ask;本地代理管控出网,全程只读审计。

$ dsh plugin --profile web add dsh-permission-rules
omdsh-devomdsh-dev
13

DSH 本机只读安全审计插件:扫描配置/插件/会话/网络四个维度,输出脱敏、可复现、可定位的风险报告;不修复、不联网、不执行被审计插件。

$ dsh plugin --profile web add github:omdsh-dev/dsh-security-audit
tensorlakeaitensorlakeai
7

把 DSH 的文件、子进程、Bash、终端、LSP 操作统一搬到一台短命的 Tensorlake 远程 Linux 沙箱里执行,本地不再触碰任何宿主机文件或进程。

$ dsh plugin --profile web add @tensorlakeai/dsh-sandbox
KhorsheedKhorsheed
4

防止 Agent 自我修改把服务改崩的守护插件(dsh 插件):绿色构建凭证绑定 git HEAD,改坏不许重启;watchdog 无感重启 + canary 自动回滚

$ dsh plugin --profile web add @khorsheed/dsh-ankh-guard
jkrandom-sudojkrandom-sudo
4

Security audit for DeepSeek Harness plugins: static permission profile with file/line evidence + a runtime sentinel gating credential access and unknown-host egress · DSH 插件安全审计:静态权限画像(附文件/行号证据)+ 运行时哨兵,触及凭证或向未知主机外发数据时先请你批准

$ dsh plugin --profile web add dsh-plugin-audit
Chhlafiu4312Chhlafiu4312
3

在 DeepSeek Harness 回复中提取引用并验证证据,帮助用户确认信息可靠性。

$ dsh plugin --profile web add --allow-build=dsh-citeguard github:Chhlafiu4312/citeguard
GHJIVHIDDGHJIVHIDD
3

原生UI界面。面向 DeepSeek Harness Web 的虚拟机沙箱插件:它基于 OrbStack 为每个会话提供独立的 debian/alpine 沙箱虚拟机,在会话视图环中新增「虚拟机」页签,支持查看/启动/休眠/删除和详细配置展示,同时为模型提供 `vm_list`、`vm_create`、`vm_exec`、`vm_delete` 工具,并内置全局运行上限、闲置自动休眠、归档/删除自动清理等资源治理能力。

$ dsh plugin --profile web add --allow-build=@deepseek-ai/dsh-plugin-vm-sandbox github:GHJIVHIDD/dsh-plugin-vm-sandbox
HYY-KingHYY-King
2

DSH plugin auditor: pre-flight compatibility check for profile plugin combinations. DSH 插件审核器:安装新插件前扫描组合兼容性,预防启动崩溃。

$ dsh plugin --profile web add github:HYY-King/dsh-plugin-auditor
MaYiFei1995MaYiFei1995
1

DSHWeb 审批增强插件:无感替代内置审批窗口,支持「拒绝并附言」,并在拒绝后终止当前回合、让模型重新结合附言思考

$ dsh plugin --profile web add github:MaYiFei1995/dsh-approval-comment
NEVSTOP-LABNEVSTOP-LAB
1

DSH 审批模式插件,在 DSH 窗口的权限下拉框(Read Only / Workspace Write / Full Access)旁边加一个「审批模式」按钮,在 Workspace Write 模式下工具调用自动放行

$ dsh plugin --profile web add github:NEVSTOP-LAB/dsh-approval-mode
sixtysevenlfsixtysevenlf
1

dsh-cost-guard — DeepSeek 成本守卫插件:会话成本核算(官方峰谷费率)、¥ 预算守卫、收敛引导、峰谷错峰队列;附对比测试报告

$ dsh plugin --profile web add github:sixtysevenlf/dsh-cost-guard
lucky8197lucky8197
1

DSH 插件:审计仓库的文档-代码一致性——版本号/更新记录表/结构树/模块清单/测试计数/文档间引用漂移检测,按严重度输出修复建议,全程只读。Document-Code Consistency Guard for DeepSeek Harness.

$ dsh plugin --profile web add github:lucky8197/dsh-doc-guard
LeslieWylieLeslieWylie
1

只读的 agent 机群凭据卫生审计:检查凭据文件权限、git remote 内嵌凭据(输出脱敏)与 provider token 字面量计数;零依赖、确定性。

$ dsh plugin --profile web add github:LeslieWylie/dsh-fleet-audit
doncelee229-cmykdoncelee229-cmyk
1

DeepSeek Harness 审批/选择方案系统级通知提醒,显示工作区名、点击跳转、多语言。Approval & decision alerts with native notifications for DeepSeek Harness.

$ dsh plugin --profile web add dsh-plugin-approval-alert