dsh-security-guard
Runtime security guard for DSH: loader import confinement, HTTP Host header validation, and source patch for VM sandbox escapes (4 CVEs). AI-assisted.
DSH 运行时安全守卫:配置加载导入约束、HTTP Host 头校验、附带 VM 沙箱逃逸源码补丁(4 个 CVE)。AI 辅助制作。
How to install
dsh plugin add dsh-security-guard About
DSH Security Guard / DSH 安全守卫 **AI-assisted production.** Vulnerability triage, patch implementation, and plugin code were produced by an AI coding assistant (TraeWork / Trae) under human supervision. / 漏洞定位、补丁代码与插件实现均由 AI 编程助手(TraeWork / Trae)在人工监督下完成。 A runtime security guard plugin for DeepSeek Harness (DSH) that applies defense-in-depth measures at the Cordis plugin layer. It does **not** modify the original source code — instead, it shadows runtime methods and intercepts HTTP requests to replicate the fixes from the DSH Security Patch. DSH 运行时安全守卫插件,在 Cordis 插件层施加纵深防御。**不修改原始源码**——通过运行时方法…
Recommendation signals
Meta
- License
- MIT
- Language
- JavaScript
- GitHub stars
- 0
- mo. downloads
- –
- Last push
- 2026-09-05
- Created
- 2026-09-03
Basic safety check
- Findings
- None
- Sources
- curated:awesome-dsh-plugin.com, curated:awesome-dsh-plugin/awesome-dsh-plugin
- Topics
- dsh-plugin, security
Related plugins
dsh-secure-audit
PensiveFei/dsh-secure-audit
Read-only security and compliance plugin for DeepSeek Harness: prompt-injection detection, Chinese-PII redaction, and a local configuration audit with redacted, reproducible reports.
dsh-auto-approve
Jiao-XXX/dsh-auto-approve
Adds an `auto` permission preset between workspace-write and danger-full-access: a classifier grants routine sandbox escalations once, while dangerous or uncertain requests still go to a human.
dsh-plugin-vet
wulun811/dsh-plugin-vet
Plugin trust pipeline for DeepSeek Harness: deterministic static scan with verdicts, opt-in runtime guard with honeypot lures, agent audit-protocol skill, and a browser shield status light. Alarm-only, never an enforcer.
dsh-agent-approval
MoonlitDropOfBlood/dsh-agent-approval
An independent approval subagent judges every sandbox escalation, with a configurable model and an audit log.