dsh-reach
PerryLink/dsh-reach
0GitHub starsMulti-channel decision & remote-control bridge for DeepSeek Harness: pushes any workspace's approval/question cards to IM channels (WeChat iLink first) and answers them from chat, with a session console, per-channel security, and an open push service.
dsh-zcode-breaker
BOWLUNA/dsh-zcode-breaker
0GitHub starsRapid-refill circuit breaker for DeepSeek Harness automatic compaction: stops the futile compact-refill-compact loop that burns a summarization call on every step, and reports the oversized read or tool output behind it.
dsh-zcode-scribe
BOWLUNA/dsh-zcode-scribe
0GitHub starsA read-only memory room for DeepSeek Harness: a scribe_recall tool over plain markdown, path-safety rules that refuse traversal, Unicode smuggling and NTFS alternate data streams, and an index that never truncates silently.
dsh-llm-trace
wpeng77/dsh-llm-trace
0GitHub starsWire-level LLM inspector for DeepSeek Harness: capture the raw HTTP request and response bodies of every model provider call, attributed per session, in a Conversation View tab and a loopback viewer page.
关于 DeepSeek Harness 安全与策略插件
Security & Policy 插件用于检查、限制、审计或恢复 DeepSeek Harness 环境中的不同部分。本分类覆盖权限规则、Plugin Vetting、配置审计、Credential 控制、访问认证、Rollback、恢复机制、Policy Enforcement 和安全诊断。不同实现的保护范围和执行强度不同,因此 Registry 会保留源码与验证证据,而不会简单给某个插件贴上“安全”标签。
评估安全插件时,应首先判断它是报告风险,还是主动阻止或修改行为;随后检查执行位置、所需权限、文档中的 Fail-open / Fail-closed 行为、访问的文件和 Credentials、依赖、生命周期脚本、仓库活跃度以及兼容性证据。Security Signal 是客观证据,不等同于安全认证。