awesome-dsh-mobile-plugins

A curated collection of mobile-optimized plugins for DeepSeek Harness — powerful AI capabilities at your fingertips.

Listing 3 plugins · What is DeepSeek Harness? ↗

What is DSHBox? ↗ — the DSH mobile workstation

Install method
Date listed
  1. Runs local security audits of AI API relays and LLM proxies from DeepSeek Harness, producing Markdown reports for prompt injection, model substitution signals, tool-call rewriting, error leakage, stream integrity, and profile-gated Web3 risks.

    Security & Permissions
    Install ▾
  2. Authorized-security DSH collection: nine work modes (redteam coordinator, pentest, code audit, binary analysis, attack-defense, AV evasion, incident response, cloud security, CTF solving) and fifteen runtime plugins, managed from a settings page with one-click deploy, install, update and uninstall.

    Security & Permissions
    Install ▾
  3. Authorized pentest mode for DeepSeek Harness — exploration chain, assets and findings with a Web view.

    Security & Permissions
    Install ▾
No plugins match.

Install notes

# from npm (prebuilt)
dsh plugin --profile web add <npm-package>

# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:owner/repo

Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).

How to submit

1. Add one YAML file under data/plugins/, named <owner>__<repo>.yml (a monorepo subpackage: <owner>__<repo>--<subpath>).
2. Fill it in like the example below — five keys only, anything else is rejected.
3. Open a PR against main: CI checks the fields, the file name and the repository binding; once merged, the READMEs and this site regenerate themselves.

# data/plugins/meyaomiao__dsh-server-deck.yml
url: https://github.com/meyaomiao/dsh-server-deck
name: meyaomiao/dsh-server-deck
category: remote
description:
  en: Server dashboard: per-host status, CPU, memory, disk and latency.
  zh: 服务器仪表盘:每台主机的状态、CPU、内存、磁盘与延迟。
# tarball: https://github.com/owner/repo/releases/download/v1.0.0/pkg.tgz  # 仅在只能装预构建产物时填

About listing

We list metadata only — one file per plugin, pointing at the author’s own repository. Plugin code never lives here.

Add your plugin

Open a PR against this repository — one YAML file under data/plugins/ is the whole submission; the READMEs and this site regenerate automatically. Add the dsh-plugin topic to your repo too.

Install method

Read from the entry’s target and composed by the build: npm → package manager, tarball → pinned release, otherwise github:owner/repo → default branch.

Date listed

The added date records when the entry was first listed here — not when the plugin was released.