dshpluginsdshplugins.cc

shuxue6662-a11y/dsh-risk-guard

Zero-interruption audit and fuse blocking for DeepSeek Harness: silently records every tool call with deterministic risk scoring, cumulative-risk bonuses, risk-level breakdowns and retention-based cleanup; blocks irreversible catastrophes (protected-path deletion, disk wipe, force-push to protected branches/refs, credential exfiltration), and renders a redacted /risk-guard operation bill with --since filtering.

toolsLicense MITTypeScript
55Health score

About this plugin

- Silent audit — records every tool call (tool name, redacted arguments, success/failure, risk tags, explainable score) into local JSONL files. No dialogs, no permission changes, no sandbox changes. - Deterministic risk scoring — zero LLM calls, zero extra cost. Covers destructive deletes, credential reads, network egress, writes outside the workspace, dependency installs and heavy builds; rapid repeats and consecutive high-risk calls accumulate bonus score. - Insurance fuse — blocks only irreve

Keywords
deepseek-harnessdsh-pluginsecurity
Install · dsh CLI
npm$ dsh plugin --profile web add dsh-risk-guard
github$ dsh plugin --profile web add github:shuxue6662-a11y/dsh-risk-guard

Health breakdown

55 / 100
License25 / 25
Repo verified15 / 15
Documentation15 / 15
Adoption · stars0 / 20
Community · forks0 / 10
Distribution · downloads0 / 15

Score reflects license, community signals, documentation and distribution. It is not a code audit — review the source before installing.

Security

LicenseMIT
Risk disclosurepartial — review the source
Network callsnone
Credentialsno
Manifestdeclared

Key metrics

Downloads / mo0
Star trend0
past week
Stars
0
Forks
0
Listed
Aug 19, 2026
Last updated
Aug 19, 2026

Related

Related plugins

ysr666/dsh-vision-router93

[!WARNING] 📌 Announcement (v1.2.3) v1.2.3 fixes DSH Desktop's re-appearing first-run dialog: the onboarding "seen" flag and the model-guide step now persist in the profile settings file instead of origin-scoped localStorage, which a random per-launch port (--port 0) wiped on every boot (issue #78). v1.2.2 closed the last attachment-id gap — ids announced for images the host persisted itself (e.g. readimage re-uploads, sha256:…) now resolve in visiondescribe and every pixel tool (issue #72) — st

2.7k 770
Rianico/dsh-better-edit74

Hash-anchored read / edit / batch_edit / undo_last_edit tools: every line gets a unique 3-character content hash, edits target hashes instead of line numbers, and served-state verification rejects stale ranges with fresh anchors.

1.4k 10
yun520-1/deepseek-heartflow69

HeartFlow (心虫) AGI layer-1 discriminator gate as a DSH plugin: 47-dimension rule-based text checking (heartflow_check tool) plus automatic output supervision at tools/post-execute, fail-closed when engine missing.

1.4k 5
awesome-dsh-plugin/dsh-find-plugin80

Tell your agent what you want ("notify me on WeChat when a task finishes"), and it searches the DSH plugin ecosystem on GitHub for you — top results by stars, each with a one-line description and an install command.

1.2k 58
xiehuan123/dsh-deepread77

Deep-read a book or an article: extract core claims, argument structure, and key evidence into a structured "claim–evidence–data–relation" report. Official bundle plugin: the Node half registers the deepread tool, the client half provides the result card and the reading bar in the input area.

1.1k 20
Relistencode/dsh-extension-hub74

New in v0.2.8 — one-command install: the package now ships a bundle layer, so dsh plugin --profile web add dsh-extension-hub wires the plugin row into your profile automatically (no more manual cordis.patch.yml edits in the quick start). New in v0.2.7 — the Add-ons block now also carries dsh-recall: conversation history recall for DSH — literal/fuzzy/semantic retrieval over every past session, fully local & offline. New in v0.2.6 — A curated plugin store inside DSH: browse 400+ community-curated

1.1k 7