dsh-security-guard
Run the following command in DeepSeek Harness:
dsh plugin install weisofns/dsh-security-guard
Paste the following prompt into your AI chat to install this plugin:
Run dsh plugin install weisofns/dsh-security-guard in the DeepSeek Harness terminal to install this plugin; the source is at https://github.com/weisofns/dsh-security-guard . It takes effect automatically after restarting DSH.
About this plugin
As the DSH plugin ecosystem expands quickly, most users install third-party plugins with virtually no security safeguard. A seemingly harmless codebase may hide credential theft, clipboard exfiltration, dynamic code execution, or even process injection, and manual review is both time-consuming and unlikely to cover every attack surface.
dsh-security-guard was built to close that gap. On installation it automatically scans every plugin in the profile, applying 28 rules that span hardcoded credentials, suspicious outbound channels, dynamic execution, high-entropy obfuscation, unauthorized listeners, supply-chain tampering, and persistence implants. Results are available three ways: ask the model in conversation to run a scan and receive a structured report, open the local web dashboard for a visual per-rule breakdown, or pipe alerts through the event bus and an optional webhook with severity filtering and rate limiting. The rule set can be pulled from remote JSON sources and refreshed on a schedule, so new threat coverage arrives without a plugin release.
Whether you operate multiple DSH instances or you are a developer constantly trialling community plugins, one install gives you natural-language security reporting in chat. It ships with zero third-party runtime dependencies, is non-invasive to the DSH host, and starts working the moment the harness restarts.
Use Cases
- Scan a freshly installed plugin for hidden credential theft or dynamic execution risks via the model
- Batch-audit every installed plugin and review its risk score and severity level on a schedule
- Present per-plugin, per-rule security reports to the team through the local web dashboard
Best For
- DSH developers who frequently trial and switch between community plugins
- Operators managing multiple DSH instances in production or staging
- Engineering leads who must produce plugin security reports for compliance or team awareness
Related Plugins
A network security red-team benchmark plugin for DeepSeek-V4.1/Flash featuring dual-layer kernel injection and zero-tool architecture for controlled model safety assessment.
A security red-team prompt plugin for DeepSeek-V4 that uses code-formal mapping and zero-trigger system prompts to enable unconditional output, intended for authorized testing and research only.
Adds an Auto approval mode on the official workspace-write sandbox, classifying semantic risks, asking when ambiguous, and denying destructive operations.
Undo/rollback system for DSH: config & plugin snapshots, one-click undo/redo/restore, message-level revert, secret masking, safe mode, and offline WebUI/GUI/CLI rescue tools for when DSH won't start.