Security and policy plugins inspect, restrict, audit, or recover parts of a DeepSeek Harness environment. This category covers permission rules, plugin vetting, configuration audits, credential controls, access gates, rollback and recovery mechanisms, policy enforcement, and security-focused diagnostics. Protection and enforcement levels differ by implementation, so the Registry keeps source and verification evidence visible instead of reducing plugins to a generic safe label.
When evaluating a security plugin, first determine whether it reports findings or actively blocks and modifies behavior. Review its enforcement point, required privileges, documented fail-open or fail-closed behavior, files and credentials it accesses, dependencies, lifecycle scripts, repository activity, and compatibility evidence. A Security Signal describes observable evidence; it is not itself a security certification.