shuxue6662-a11y/dsh-risk-guard
Zero-interruption audit and fuse blocking for DeepSeek Harness: silently records every tool call with deterministic risk scoring, cumulative-risk bonuses, risk-level breakdowns and retention-based cleanup; blocks irreversible catastrophes (protected-path deletion, disk wipe, force-push to protected branches/refs, credential exfiltration), and renders a redacted /risk-guard operation bill with --since filtering.
About this plugin
- Silent audit — records every tool call (tool name, redacted arguments, success/failure, risk tags, explainable score) into local JSONL files. No dialogs, no permission changes, no sandbox changes. - Deterministic risk scoring — zero LLM calls, zero extra cost. Covers destructive deletes, credential reads, network egress, writes outside the workspace, dependency installs and heavy builds; rapid repeats and consecutive high-risk calls accumulate bonus score. - Insurance fuse — blocks only irreve
$ dsh plugin --profile web add dsh-risk-guard$ dsh plugin --profile web add github:shuxue6662-a11y/dsh-risk-guardHealth breakdown
55 / 100Score reflects license, community signals, documentation and distribution. It is not a code audit — review the source before installing.
Security
Key metrics
Related
Related plugins
Browse, search and install community plugins from inside DeepSeek Harness settings, with category filters, one-click updates, enable/disable, theme switching and configuration backup.
Tell your agent what you want ("notify me on WeChat when a task finishes"), and it searches the DSH plugin ecosystem on GitHub for you — top results by stars, each with a one-line description and an install command.
Free, keyless web search for DSH: 7 engines (DuckDuckGo/Bing/SearXNG free + Exa/Perplexity/DeepSeek paid), auto-failover, settings-page UI with API key inputs and official links, web_fetch, and an engine test tool.
MCP Connector for DeepSeek Harness: an MCP manager with one panel to connect servers, configure authorization, search tools across connections, and troubleshoot failures. Browse a continuously updated catalog of over one hundred connectors; filter by connection/server/status, inspect readable parameters and the last successful cache time, and rediscover tools. Supports OAuth 2.0 PKCE, API keys, stdio/HTTP, and mcpServers JSON import. Maintained by Qichacha/QCC.
Use your ChatGPT / Codex subscription with DeepSeek Harness via OAuth, with model access, usage quotas, search, and image generation — no API key or Codex CLI required.
Framework upgrade safety & plugin version gating for DeepSeek Harness (DSH): one-click framework upgrade with auto-rollback on failure → one-click rollback to the previous version after an upgrade → plugins the new framework cannot load are auto-disabled → the plugin upgrade gate refuses a version the host can't take. A built-in multi-source plugin market & index (500+ plugins / 300+ skills, zero GitHub API calls) rides on top as the discovery layer — and every source is swappable: install sourc