dsh-jev-interceptor
AskTheWay/dsh-jev-interceptor
1GitHub stars⚡ Millisecond System-1 judgement for every tool call in DeepSeek Harness — Jev-powered risk classification & evidence-gated auto-approval. Fail-closed by construction. dsh 生态第一个 System-1 决策插件
dsh-super-code
ArtlexYoung/dsh-super-code
1GitHub stars一个更快、更节省、更准确的 DeepSeek Harness 插编码件。在 SWE-bench Pro 最难的 100 道题中,回答耗时减少 36%,每题token减少 17%,正确率甚至增加了 5%。A faster, more accurate, and more cost-effective DeepSeek Harness plug-in component. Among the 100 most difficult questions in SWE-bench Pro, the response time -36%, tokens per question -17%, and the accuracy rate even +5%.
dsh-allow
DWJZ/dsh-allow
1GitHub stars按路径与能力(read/write/create/delete/execute)授予 DSH shell 调用的文件权限,并在进程真正运行其下的 macOS Seatbelt profile 里强制;会话里的「审批」标签页显示每次判定是规则、自动复核还是人拍的板。 / Filesystem permissions for DSH shell calls, granted per path and capability instead of per command name, enforced in the process sandbox, with an Approvals tab showing which layer decided each call.
dsh-canvas-tsx-sidebar
drscrewdriver/dsh-canvas-tsx-sidebar
1GitHub starsDSH 侧边栏插件:把 Qoder Canvas `*.canvas.tsx` 静态解析为结构化报告页,在 dsh-better-sidebar 右侧栏渲染(文件查看器接管 + 页签)。纯静态管线,不执行源码。附 writing-qoder-canvas skill。| Render Qoder Canvas `.canvas.tsx` reports in the DSH right sidebar. Static parse only — no code execution.
dsh-pocket-console
picsky/dsh-pocket-console
1GitHub starsDon't hand over the whole machine, just the decision blocking it: an unattended DeepSeek Harness (DSH) run's tool-call approvals and ask_user_question prompts reach your phone as Feishu cards — desktop first, outbound only.
dsh-opinionated-subagent
dat-lequoc/dsh-opinionated-subagent
1GitHub starsA minimal, opinionated subagent for DeepSeek Harness: you choose which models a child may run on and at which reasoning effort, and a correction reaches a working child at its next step
关于 DeepSeek Harness 安全与策略插件
Security & Policy 插件用于检查、限制、审计或恢复 DeepSeek Harness 环境中的不同部分。本分类覆盖权限规则、Plugin Vetting、配置审计、Credential 控制、访问认证、Rollback、恢复机制、Policy Enforcement 和安全诊断。不同实现的保护范围和执行强度不同,因此 Registry 会保留源码与验证证据,而不会简单给某个插件贴上“安全”标签。
评估安全插件时,应首先判断它是报告风险,还是主动阻止或修改行为;随后检查执行位置、所需权限、文档中的 Fail-open / Fail-closed 行为、访问的文件和 Credentials、依赖、生命周期脚本、仓库活跃度以及兼容性证据。Security Signal 是客观证据,不等同于安全认证。