dsh-security-guard
Static and runtime security guard for dsh: rule-based scans for malicious code, prompt injection and token waste, runtime interception of dangerous tool calls, /scan command, plugin_scan tool, web panel, and allowlist.
dsh 安全守卫插件:基于规则的静态扫描覆盖恶意代码、提示词注入与令牌浪费,运行时拦截危险工具调用,提供 /scan 命令、plugin_scan 工具、Web 面板与白名单。
How to install
dsh plugin add dsh-security-guard About
🛡️ dsh-security-guard **English** | 中文 A security guard for the DeepSeek Harness (dsh). Static scanning and runtime interception that **never executes** the code it protects you from. --- ✨ Highlights | | | | --- | --- | | 🔍 **Static scan** | Rule-based analysis of source files — ts.createSourceFile only, scanned code is never imported or executed | | 👁️ **Runtime watch** | Intercepts dangerous tool calls, prompt steps and file operations before they happen | | 📊 **Verdicts** | Every finding classified block \| warn \| clean, written to JSON or human-readable reports | | 🧩 **Extensible ru…
Recommendation signals
Meta
- License
- MIT
- Language
- TypeScript
- GitHub stars
- 1
- mo. downloads
- 929
- Last push
- 2026-08-16
- Created
- 2026-08-16
Basic safety check
- Findings
- None
- Sources
- curated:awesome-dsh-plugin.com, curated:awesome-dsh-plugin/awesome-dsh-plugin
- Topics
- deepseek-harness, dsh, dsh-plugin
Related plugins
dsh-auto-mode
NanmiCoder/dsh-auto-mode
Adds an Auto permission preset between Workspace Write and Full access: routine work stays in the official workspace-write sandbox while the current session model reviews escalation and destructive calls, granting one exact wider access once, asking when the intent is ambiguous, and denying critical paths.
dsh-passwords
slywalker2006/dsh-passwords
Turns DeepSeek Harness into a server-grade multi-tenant platform: remote access + auto HTTPS, subuser permissions & token/daily quotas, sandbox enforcement, encrypted auth & audit log.
sofagent
KongFangXun/sofagent/tree/main/engine/dsh-plugins/cordis-plugin-sofagent-audit
Commit-time audit harness for AI coding agents: 24 git-diff rules (secrets, out-of-scope edits, prompt injection), HMAC-signed audit trail, snapshot rollback, and an MCP server with 84 tools. Installable via dsh plugin add.
dsh-vault
Ox0400/dsh-vault
Encrypted local credentials vault for the Harness: a web settings page and vault_* tools to store, search and copy passwords, API keys, TOTP secrets and card data, with health audits, expiry rotation, imports/exports and read-only/ask access modes.