SkillSpector
NVIDIA
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
GITHUB TOPIC
19projects include this topic
The "prompt-injection" topic on GitHub groups 19 open-source projects in the DeepSeek Harness (DSH) ecosystem, led by SkillSpector with 17k GitHub stars. SkillSpector — Security scanner for AI agent skills. Every project here is indexed by DSH Universe with live GitHub data — stars, activity and install status — so you can compare and install directly.
{count} projects
Exact GitHub Topic match
NVIDIA
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
z91772524-ai
一个脚本搞定 DSH / WorkBuddy / ZCode / Codex / Cursor / Claude 六客户端的提示词与人格替换:零依赖、双击即用、可自证、改前备份、一键还原。附 bandit/semgrep 扫描与 SHA256 校验。
PensiveFei
Read-only security & compliance plugin for DeepSeek Harness: prompt-injection detection, Chinese-PII redaction, and local configuration audit with redacted, reproducible reports.
PerryLink
Prompt-injection, jailbreak, and secret-leak defense for DeepSeek Harness: Aho-Corasick detection with allow/ask/block interception and sanitized audit events
PerryLink
Security-audit skill pack + plugin_vet supply-chain gate for DeepSeek Harness (dsh): 8 bilingual agent skills (secret scan, dependency audit, supply-chain review, prompt-injection review, audit orchestration, threat modeling, vuln intel, incident response) plus the plugin_vet automated pre-install scanner. Apache-2.0.
dttxorg
Auditable vision and cross-platform Computer Use runtime for DeepSeek Harness — strict evidence, health-checked failover, original pixels, and Token accounting.
Chhlafiu4312
Local prompt-injection and secret-exfiltration firewall for DeepSeek Harness.
ChenLaoshiYF
?? for DeepSeek Harness: first security plugin for dsh. Scans skills/MCP configs for prompt injection, homoglyphs, hidden Unicode, dangerous shell, credential leaks. DSH ????????
drowned-fish1
DeepSeek Harness plugin for safely discovering, auditing, and adopting external Agent Skills — prompt-injection and AgentBaiting defense.
MJorgin
Task-to-skill pairing for DeepSeek Harness — pours the minimal set (usually one; zero when plain tools suffice), prefers workflow skills over hand-composed atomics. Laziness ladder, quarantine → SkillSpector scan → explicit human approval, never auto-installs. Task-to-skill pairing · laziness ladder · secure cellar · never auto-install
AskTheWay
⚡ Millisecond System-1 judgement for every tool call in DeepSeek Harness — Jev-powered risk classification & evidence-gated auto-approval. Fail-closed by construction. dsh 生态第一个 System-1 决策插件
dsh-plugin-evaluation
DSH plugin for agent observability and security evaluation
imroc
Private, per-project prompt rules for DeepSeek Harness — matched by git remote/repo/path, worktree-aware, never committed to the repo
ishamishra0408
A teammate posts one Slack message. Your AI assistant reads it, believes it, and hands over your keys through a link preview — nothing shows in the channel. Three plugins for the dsh agent harness stop the message before it leaves. Live demo you can run: real detectors, a real model as the victim.
kakapengta
A standalone security-check plugin that links directly to a DeepSeek Harness (DSH) Web profile. Before installing or using an untrusted Skill, run a local browser rough check first, then let the user decide whether to call the DSH-configured LLM for structured review.
BOWLUNA
A read-only memory room for DeepSeek Harness: a scribe_recall tool over plain markdown, path-safety rules that refuse traversal, Unicode smuggling and NTFS alternate data streams, and an index that never truncates silently.
MangShe3-0
Offline-first security scanner for DeepSeek Harness plugins: prompt injection, ransomware, exfiltration, and supply-chain risks.
sashankh
Indirect prompt-injection guard for DeepSeek Harness: taints tool output by origin, gates privileged calls that follow untrusted content, and refuses credentials heading off the machine.
XiaoYuOvO
DSH LLM response-stream injection filter: hard-block rare Unicode scripts (Track A) + score-based disposal of control chars / protocol markers / script mixing / spam keywords (Track B) on the llm/stream waterfall. Install: dsh plugin --profile web add github:XiaoYuOvO/dsh-llm-injection-filter