- Home
- All plugins
- Security
- Skill Pack Security
Skill Pack Security for DeepSeek Harness
Repository owner: PerryLink · dsh-skill-pack-security
Security-audit skill pack for DeepSeek Harness (dsh): 5 agent skills - secret scan, dependency audit, supply-chain review, prompt-injection review, audit orchestration. Zero runtime code. Apache-2.0.
What this plugin does
Security-audit skill pack for DeepSeek Harness (dsh): 5 agent skills - secret scan, dependency audit, supply-chain review, prompt-injection review, audit orchestration. Zero runtime code. Apache-2.0.
Purpose evidence: this record includes a GitHub repository description. Any localized fallback copy is not independent verification of its capability claims.
Repository and source evidence
This public repository was verified through the GitHub API. The catalog source links the plugin to this repository, but directory inclusion is not an official endorsement.
- Repository owner
- PerryLink
- Author
- No independently verified author field is available
- Source
- https://github.com/topics/dsh-plugin
How to install
dsh plugin --profile web add github:PerryLink/dsh-skill-pack-securitySuggested commands are derived from the catalog record. Review the repository README, requested permissions, and source before installation. Read the full guide.
Example configuration
The directory snapshot does not include a repository-verified, plugin-specific configuration example, so no configuration keys are generated or guessed here. After installation, use the official DSH command to inspect the composed configuration for the active profile:
dsh --profile web --dump-configFor plugin-specific configuration, use the repository README and manifests as the source of truth: https://github.com/PerryLink/dsh-skill-pack-security
Supported DeepSeek Harness versions
Neither the repository evidence nor the directory record provides a verifiable DSH version range. Test the target DSH version in an isolated environment.
Environment, permissions, and dependencies
Environment
GitHub primary language: TypeScript. The directory has not verified the runtime or its version.
Permissions
No verified permission manifest is captured. Review the README, patches, environment variables, and external service access before installation.
Dependencies
The dependency tree was not captured or verified. Use the repository package manifest and lockfile as the source of truth.
GitHub metadata
- Stars / forks
- 1 / 0
- Last repository update
- August 14, 2026
- Latest release
- v1.2.0 · August 14, 2026
- License
- Apache-2.0
- Default branch
- main
- Available / archived
- Publicly reachable and not archived
Installation safety
No plugin-specific security assessment was collected. The following is generic DeepSeek Harness installation guidance, not a safety rating or audit conclusion for this plugin.
Third-party plugins can execute code inside your Harness environment. Before installation, review the source, recent activity, dependencies, build scripts, and requested permissions, then test in an isolated environment. Directory inclusion is not a security certification.
Git installs may execute prepare/build scripts on your machine, outside the agent sandbox. Only allow trusted source and pin a commit where possible.
Read the plugin safety guideCommon errors and troubleshooting
No plugin-specific error documentation was collected. The steps below are generic DeepSeek Harness troubleshooting, not fixes verified for this plugin.
- 1. Plugin missing after installation
Confirm installation and launch use the same profile, then run dsh --profile web --dump-config to check whether the bundle entered the composed configuration.
- 2. Git dependency build is blocked
pnpm 10+ may block prepare scripts. Only after reviewing the source, add the exact package key reported by pnpm to allowBuilds, then retry.
- 3. Version or configuration mismatch
Check the repository README, releases, and compatibility evidence. Do not treat directory-wide commands as promises from the plugin author.
More plugins in this category
SecuritySandbase Harness
sandbaseai / sandbase-harness
Open-source CMA-compatible agent runtime for any model, with MCP tools, sandboxed sessions, audit, replay, and a local console. Includes a native DeepSeek Harness bundle over stdio MCP.
View plugin detailsAxern
cofy-x / axern
Open-source sandboxes for AI agents, untrusted code execution, and durable services.
View plugin detailsPhi
pulseaiclub / phi
a coding Agent from pi. ∞ providers, sub-agents, hashline edits, and a permission gate
View plugin detailsTurn Rewind
Anionex / dsh-turn-rewind
deepseek harness对话和代码状态回退插件 | DSH — rewind conversation and workspace state, powered by a persistent Change Ledger
View plugin detailsOpenguardrails
openguardrails / openguardrails
The vendor-neutral protocol for AI agent safety & security — and the neutral benchmark that ranks the vendors.
View plugin detailsCustom Tool
omdsh-dev / dsh-custom-tool
Create and manage sandboxed JavaScript tools for DeepSeek Harness with a Monaco editor and model-driven tool lifecycle.
View plugin detailsComputer Use
Anionex / dsh-computer-use
为 DeepSeek Harness 提供电脑控制插件:新鲜 Accessibility 观测、过期状态拒绝、作用域权限与安全输入(目前支持macos)|Accessibility-first macOS Computer Use bundle for DSH with fresh observations, stale-state rejection, scoped permissions, and safe input.
View plugin detailsSecurity Audit
omdsh-dev / dsh-security-audit
DSH 本机安全审计插件:配置/插件来源/会话/网络暴露面,只读脱敏风险报告
View plugin details