MIT-licensed DeepSeek Harness plugin that turns dsh web into a redteam security-workflow engine: nine presets (pentest, code-audit, cloud-security, CTF, …) plus fifteen runtime plugins, self-contained and offline-deployable.
DSH integration
Native runtime
Author-claimed
Safety audit
Unaudited
Last verified
2026-08-29
License
MIT
01What can it help you accomplish?
Run authorized redteam security research inside DeepSeek Harness — pentest, red-team assessment, code audit, binary analysis, AV-evasion, incident response, cloud security, and CTF.
Nine ready-to-use security work modes (presets) with runnable runtime plugins, each carrying persona, playbook, skills, and an indexed refs/ knowledge base.
Security researchers and red teams who already hold written authorization for security testing, CTF, bug-bounty, or vulnerability research.
Solve CTF challenges and document the kill-chain inside DeepSeek Harness.
Per-challenge registration, module routing (web/pwn/reverse/crypto/misc), a solving loop, and a flag ledger with post-mortem notes.
CTF players and teams competing in authorized capture-the-flag events.
02How to install into DeepSeek Harness
Prerequisites
- Install DeepSeek Harness (deepseek-harness) first — the project is an add-on that empowers the harness.
Installation steps
- 01
Download the repo source package and let DeepSeek install it into deepseek-harness for you.
- 02
In a new dsh web session, select the corresponding mode to start the task.
Verify the integration
Not specified by the author
03DSH integration and capability boundaries
Loads into DeepSeek Harness (dsh web) as nine redteam security work modes (presets) plus their runtime plugins — self-contained and offline-deployable.
Nine redteam security work modes (presets)
A task brief inside DeepSeek Harness (dsh web)→redteam / pentest / code-audit / binary-analysis / attack-defense / av-evasion / incident-response / cloud-security / ctf-solver modes
Runs offensive security testing (pentest, AV-evasion, cloud attack-defense); restricted to authorized scenarios onlyFour-layer asset structure (persona → playbook → skills → refs/)
Each work mode's bundled assets→Each mode self-contains persona, playbook, loadable skills, and an indexed external refs/ knowledge base with zero local paths.
Fifteen runtime plugins
DeepSeek Harness runtime→Fifteen runtime plugins mounted into the harness (stage-gate enforcement and related security-workflow helpers).
04Who is it for? When not to use it?
Good for
- Security researchers and red teams who already hold written authorization for security testing, CTF, bug-bounty, or vulnerability research.
- CTF players and teams competing in authorized capture-the-flag events.
Not for
- Must only be used for authorized security testing, CTF, bug-bounty, and vulnerability research; the author explicitly forbids illegal use.
05Compatibility, maintenance and safety notes
- Must only be used for authorized security testing, CTF, bug-bounty, and vulnerability research; the author explicitly forbids illegal use.
- Requires DeepSeek Harness (deepseek-harness) to be installed and set up before this project; it is an add-on that empowers the harness, not a standalone tool.
- Ships self-contained and supports offline deployment; the only required runtime is DeepSeek Harness itself.
MIT · no tagged release (latest_release null), last push 2026-08-28
06Frequently asked questions
How do I install dsh-redteam-model?
Install DeepSeek Harness (deepseek-harness) first. Then download the repo source package and let DeepSeek install it into deepseek-harness for you; in a new dsh web session, pick the mode you want to start the task.
What work modes does it provide?
Nine modes: redteam (entry/orchestration), pentest, code-audit, binary-analysis, attack-defense, av-evasion, incident-response, cloud-security, and ctf-solver. Each is self-contained with its own persona, playbook, skills, and refs/ knowledge base.
Is it legal / safe to use?
The author explicitly says do not use it for illegal activity. It is meant only for authorized security testing, CTF competitions, bug-bounty, and vulnerability research. DSH has not performed a safety audit of this plugin.
Do the modes need internet or external services?
The project is self-contained and can be deployed offline; the only required runtime is DeepSeek Harness itself. The external refs/ knowledge base is indexed by original text with zero local paths.
Can I customize a mode's methodology?
Yes. You can adjust each mode's methodology at the source level, or use the 'AttackAtlas' plugin's 'custom work methodology' and 'capability library' features to build your own workflow.
07Related DSH workflows
archify
by tt-a1i
Turn any idea, plan, or codebase into a beautiful interactive diagram. An agent skill for Claude Code, Codex, and more.
openviking
by volcengine
Self-evolving Context Database for AI Agents. Unify Agent Memory, Knowledge RAG and Skills.
nocobase
by nocobase
NocoBase is an open-source AI + no-code platform for building business systems fast. Instead of generating everything from scratch, AI works on top of production-proven infrastructure and a WYSIWYG no-code interface, so you get both speed and reliability.
learn-harness-engineering
by walkinglabs
Harness engineering beginner tutorial, from 0 to 1
08Data and sources
该项目是为 [https://github.com/deepseek-ai/deepseek-harness](https://github.com/deepseek-ai/deepseek-harness) 赋能的项目,先装好 deeps…
在 dsh web 的新会话中选择相应的模式即可开始任务。
This page is generated from the project’s public documentation, repository metadata and a structured parse of DSH Plugins; last verified on 2026-08-29. Found an error? Submit a correction.
Best DeepSeek Harness Plugins
Twelve plugins worth installing first — picked from the whole catalog, across every category.
