Skip to content
dsh.fish

Browse

25 results

Bundle

dsh-api-relay-audit

DeepSeek Harness bundle for running API Relay Audit locally

toby-bridges824
Bundle

@shaoshi/dshscan

Security scanner for DSH plugins: static and semantic passes over plugin source, DSH-specific attack-surface rules, npm audit, batch scanning, and an HTML report with per-finding severity and evidence.

shaoshi2010
Bundle

dsh-plugin-doctor

Health checks for DeepSeek Harness: manifest/patch/entry/build/pack/install verification, model-callable plugin_check, profile host-shadowing + manifest-BOM detection, environment diagnostics, supply-chain poison preflight, and broken tool-call-sequence detection (#2334).

zoahdev7
Bundle

dsh-capability-receipt

Content-addressed receipts for skills actually loaded by DeepSeek Harness

dongsheng1231324
Bundle

dsh-release-proof

Reproducible multi-source release evidence for DeepSeek Harness

dongsheng1231323
Bundle

@jieai/dsh-plugin-vet

Audit deepseek-harness (DSH) plugins before install, guard them at runtime. Static verdict + pre-install audit protocol; supply-chain checks (typosquat, OSV); exfiltration & ransomware detection, honeypot canaries, integrity baseline. Alarm-only; blocks confirmed destructive ops.

wulun8113
Bundle

dsh-profile-lock-proof

Content-addressed proof that a DeepSeek Harness profile declaration, pnpm lock and installed bundles agree

dongsheng1231322
Bundle

dsh-plugin-security-review

Security review gate for DeepSeek Harness (dsh) plugins: static pre-install vetting of malicious code, vulnerabilities and supply-chain risks (with deobfuscation decoding), runtime audit, optional tool-call guard, and a one-click web review/install/uninstall panel.

ateen182
Bundle

dsh-skillx

A safe external-skill discovery and adoption bundle for DeepSeek Harness

drowned-fish12
Bundle

dsh-plugin-guard

DSH plugin gate + clinic: static audit before and after install, hash lock, peer search, mechanical detox. Never executes the target plugin.

taxueseek2
Bundle

dsh-poison-guard

Pre-install supply-chain poison scanner for DeepSeek Harness plugins: AST analysis (NodeSecure JS-X-Ray) + deobfuscation decoder + regex heuristics to catch credential exfiltration, dynamic code execution, obfuscated imports, and install-time scripts.

zoahdev2
Bundle

cn-intel-mcp-dsh

China hard-tech supply chain intelligence for DeepSeek Harness: signal board, earnings tracker, track record, Q&A via cn-intel MCP

lory690602
Bundle

dsh-plugin-gate

Installation safety gate & data-protection guard for DeepSeek Harness: 60 static signature rules (31 high/24 medium/5 low) scan plugin sources for malicious install scripts, credential theft, obfuscation, persistence and network callbacks before 'dsh plugin add', plus 12 destructive-command patterns and workspace-boundary checks against accidental deletion. | 安装安全闸门与数据保护闸:60 条静态签名规则(31 高危/24 中危/5 低危)扫描插件恶意行为、持久化与外传,12 种危险命令模式与边界检查拦截误删。

8636833481
Bundle

dsh-capcheck

V0 capability-disclosure scanner for DeepSeek Harness (DSH) cordis plugins: reports which sensitive services (credentials/shell/approval/sandbox/fs/tools...) a plugin declares or references before you trust it.

heming-gmh1
Bundle

dsh-xray-plugin

Look up what a DeepSeek Harness plugin can actually do, from inside dsh.

unStone1
Bundle

dsh-provenance

Pre-install supply-chain provenance checks for DeepSeek Harness plugins: verify the tarball you're about to install matches the source you read, before any code runs. Never executes the audited package.

Darren-Tang1
Bundle

@mkaliezz/dsh-dependency-firewall

Dependency-installation guard for DeepSeek Harness: classifies package-manager commands as ALLOW, ASK, or BLOCK before execution.

MkaliezZ1
Bundle

upstream-radar

Always-on dependency and compatibility monitoring for DeepSeek Harness plugins, including exact paths, upstream changes, and isolated install/load evidence.

MicroMilo
Bundle

correctover

AI Agent runtime authorization & evidence verification — tool-call GuardrailProvider, CCS 7-dimension verification standard, MCP/DSH security scanner, SSRF/command-injection/credential-exfil blocking with Ed25519 signed receipts.

Guigui Wang
Bundle

dsh-reproducible-build-proof

Offline content-addressed proof that independent builds reproduced byte-identical specified artifacts

dongsheng123132
Bundle

dsh-plugin-trust-center

Evidence-first inspection, compatibility verification, and quarantine tooling for DeepSeek Harness plugins.

TonyWang-hub
Bundle

dsh-deployment-rollback-proof

Offline content-addressed proof that failed deployments converged to one last-known-good artifact

dongsheng123132
Bundle

dsh-artifact-promotion-proof

Offline content-addressed proof that one immutable artifact followed a declared promotion chain

dongsheng123132
Bundle

dsh-build-hermeticity-proof

Offline content-addressed proof that a recorded build stayed within declared inputs and outputs

dongsheng123132