dsh-redteam-model: Authorized Red Team Working Modes for DeepSeek Harness
seaof0/dsh-redteam-model
A DeepSeek Harness plugin bundle shipping ten authorized red-team research modes plus seventeen runtime plugins, using workflow gates and skills to cover pentesting, code audit, evasion and incident response.
dsh-redteam-model adds a set of authorized security research working modes to DeepSeek Harness, turning the DSH web interface into a red-team operations workbench. It targets the gap where a model holds plenty of knowledge but lacks a guiding workflow, wasting tokens or walking into dead ends, so the methodology is frozen into preset modes plus runtime plugins. Each of the ten modes is self-contained with persona, playbook, skills and reference assets, and works alongside stage-gate validation, per-turn governance injection, tool interception, trace logging and campaign memory so penetration testing, code auditing, AV evasion and incident response proceed at a steady pace. Maintained by SeaOf0 under the MIT license, it is limited to authorized testing, CTF and bug bounty scenarios.
How to Install
dsh plugin --profile web add github:seaof0/dsh-redteam-model- Category
- Models & Reasoning
- Platform
- DSH Plugin
- Author
- seaof0
- Distribution
- Plugin
dsh-redteam-model Key Features
dsh-redteam-model Repo Summary
What Does It Do?
It is a DSH plugin for DeepSeek Harness that turns the DSH web interface into a red-team workbench for authorized security research. It solves the problem of models holding plenty of knowledge but lacking a workflow to guide it, which wastes tokens and can lead the agent into dead ends. The plugin ships ten preset working modes — redteam, pentest, code-audit, binary-analysis, attack-defense, av-evasion, incident-response, cloud-security, ctf-solver and asset-mapping — each self-contained with persona, playbook, skills and reference assets. It is maintained by SeaOf0 under the MIT license and is intended only for authorized security testing, CTF competitions, bug bounties and security research.
Core Features
- Ten red-team working modes: covering penetration testing, code auditing, binary analysis, AV evasion, incident response, cloud security, CTF solving and asset mapping, with deep tasks routed to the matching specialist mode.
- Stage gates and goal contracts: stage_gate and gates_list structurally validate 32 stage gates across eight modes and log results, while operation_goal and operation_progress drive interruption recovery.
- Per-turn governance injection: each turn injects stage inference, gate checklists, mode boundaries, evidence-level expectations and reference pointers, delivering only on change and recording injection volume.
- Deterministic tool interception: report gates, write boundaries, ask-before-run for high-risk commands and rate limiting for unguarded scanning keep discipline at the tool-call layer.
- Trace vault and campaign memory: all session tool calls are persisted for search and session profiling, while tactics are accumulated across sessions and recalled per workspace.
- Results and asset views: a task ledger dashboard, a five-panel results page with cross-session aggregation, and asset mapping that produces a six-sheet Excel inventory.
How to Use This Plugin?
After enabling it in DSH, pick a working mode from the mode selector when creating a session; the nine specialist security modes are folded into a "specialist security modes" submenu, so use the general redteam mode for ordinary tasks and switch for deep work. Then describe the task scenario and objective as the mode requires, and the plugin advances stage gates, injects governance context and records the process in the trace vault. If the built-in methodology does not fit, adjust the methodology in source, or add main and sub categories in the AttackAtlas capability library and build a custom working methodology there.
How to Troubleshoot This Plugin?
The plugin has a circuit breaker for consecutive failures, so when a scanning tool call fails it registers the failure and stops blind retries; check the failure records in the trace vault to tell whether a tool is missing or the parameters are wrong. If a capability is reported as not ready, install the local dependency as described in the official instructions or switch to an already-installed alternative and retry. When a high-risk command is blocked, that is the ask-before-run design working as intended — confirm the authorization scope before allowing it.
This page is an independent rewrite of the plugin's official README — for authoritative documentation and the latest changes, refer to the source: seaof0/dsh-redteam-model. The plugin is third-party code that runs on your machine once installed; inclusion does not imply endorsement — please review the source before installing.
