DSH Marketplace

dsh-reverse-skill

dhicoc/dsh-reverse-skill

Complete reverse-skill pack (85 SKILL.md) as a DeepSeek Harness Cordis plugin: reverse engineering, authorized pentesting and security-research skill router.

17320PowerShellMITSource

Install

Add dsh-reverse-skill to DeepSeek Harness

via npm

Resolves a published tarball rather than cloning the repository, and installs without any extra setup. Swap `web` for your profile name if you run another one.

via GitHub · npm package

Installing from GitHub runs the project's build script, which pnpm blocks until you allowlist it — run the command once and pnpm prints the exact key to add under `allowBuilds` in ~/.dsh/profiles/web/pnpm-workspace.yaml.

What happened when we ran it

Installed cleanly when we ran it

Every command here is run in a throwaway container against a clean profile, and the result is whatever the harness recorded — not a guess from the source. Last run 15d ago.

Show it in your README

install verified — dshmarketplace

For maintainers: the badge serves this listing's latest sandbox verdict, so a re-run updates it on its own — and it links readers to the full result here.

Due diligence

Before you install dsh-reverse-skill

  • Source of record: dhicoc/dsh-reverse-skill — present in the community registry that DSH's own plugin market installs from.
  • Licensed under MIT.
  • Detected: terminal surface. Read the source before granting these.
  • A listing here is not a security review. Plugins run with your agent's permissions.

The AI take

What it is — This is a DeepSeek Harness Cordis plugin providing skill routing for reverse engineering, authorized pentesting, and security research.

Who it is for — Users conducting security research with DeepSeek Harness can install this plugin. Users who do not want to manually maintain candidate lists can skip it because the plugin automatically synchronizes.

Watch out — Sandbox testing passes with successful registration and enabling in a new profile. It executes shell commands. No obvious issues found.

The verdict — I will not install it because it is only suitable for authorized security research scenarios, which may not be needed for other tasks.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.

What dsh-reverse-skill does

Document tiles flow through a recursive sieve and converge into one layered core.

dsh-reverse-skill is a DeepSeek Harness plugin that registers 85 reverse-engineering, authorised penetration-testing, security-research and CTF skills as a Cordis skill provider. DeepSeek Harness discovers the packaged SKILL.md files under skills/ and CTF-Sandbox-Orchestrator/: src/index.ts recursively scans both trees, normalises front matter, builds SkillCandidate records and exposes their full bodies through ctx.skills. The model can retrieve them through ctx.skills and tool-skill, while users can invoke eligible skills by name.

The package is intended for authorised reverse engineering, penetration testing and security research. Its terminal surface is relevant because these skills can guide terminal-oriented security workflows; authorisation for the target system remains the operator’s responsibility. The plugin is a poor fit where only a small subset of these skills is needed, where existing local skills already cover the same material, or where external tooling must be available automatically: referenced MCP servers such as burp-mcp require separate configuration.

DeepSeek Harness does not include the upstream agents/*.yaml definitions, because those OpenAI Agents SDK agents cannot be mapped to its supported ctx.subagent targets. It also does not enforce allowed-tools or disallowed-tools; those constraints must be handled at the harness layer.

dsh-reverse-skill documentation

Configuring dsh-reverse-skill

DeepSeek Harness loads the package through its dsh.bundle manifest and inserts the reverse-skill Cordis plugin into the active profile. A package reference can also be placed in the plugins list:

plugins:
  - "@dhicoc/dsh-reverse-skill"

As a preset fallback, DeepSeek Harness accepts these paths under skills.local.customSkillDirs:

skills:
  local:
    customSkillDirs:
      - "./dsh-reverse-skill/skills"
      - "./dsh-reverse-skill/CTF-Sandbox-Orchestrator"

The documented discovery order is project .dsh, project .agents, customSkillDirs, user .dsh, then user .agents. Discovery is flat, so nested skills must be exposed through directories containing SKILL.md.

Commands

Run npm run build to compile TypeScript into lib/ and lib/types/. Run npm test to rebuild the plugin and test the registered provider. The test checks that all 85 skills are listed, names are unique, and each skill returns a non-empty body through get(). It also checks SKILL.md files containing a UTF-8 BOM and CRLF line endings.

How dsh-reverse-skill behaves

During apply(ctx), DeepSeek Harness calls ctx.skills.registerProvider(...). The provider recursively scans skills/ and CTF-Sandbox-Orchestrator/, parses front matter, promotes metadata.user-invocable to user-invocable, converts when_to_use to whenToUse, and stores each resource with its directory path. The complete document body is returned when a skill is requested. Adding or removing a SKILL.md changes the discovered set without editing a candidate list.

Known limits

The upstream agents/*.yaml files are not included. DeepSeek Harness does not enforce allowed-tools or disallowed-tools. MCP references in skill content, including burp-mcp, require separate entries in mcp.servers. The package is documented for authorised use only.

Written from the project's own documentation and kept in sync with it. Where the two disagree, the source is authoritative — read the README on GitHub

Same category

Alternatives to dsh-reverse-skill

dsh-skill-explorer

zhu1090093659

7.6k

Skill center for the dsh web GUI: browse all loaded skills grouped by source, enable or disable model invocation, create new skills, and delete into a recoverable trash.

Installed cleanly when we ran it

npm packageTypeScript20d ago

AI review

dsh-skill-explorer

What it is — Browse loaded skills in dsh web GUI, grouped by source. Enable or disable model invocation, create new skills and delete to a recoverable trash.

Who it is for — When you need to manage skill configurations across models in the dsh web, this plugin allows browsing, enabling or disabling invocation, creating new skills and deleting. If your work only involves session operations without skill customization, you don't need this plugin.

Watch out — Sandbox test passed. Successfully installed in a fresh profile and registered by Harness. No obvious issues found.

The verdict — I would install it because it provides tools for skill creation and recovery, which is necessary when extending model capabilities.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
Source

dashi-taskboard

chuspeeism

3.1k

现代化可灵活嵌入的任务面板,支持 Codex、DeepSeek Harness

Installed cleanly when we ran it

GitHub sourceJavaScript27d ago

AI review

dashi-taskboard

What it is — This is a modern embeddable task panel supporting Codex and DeepSeek Harness.

Who it is for — When using DeepSeek Harness to proxy processing of Codex project issues, people who need an embedded panel to manage issue status find this plugin useful. If you do not need to provide an API key or token and do not execute shell commands, this plugin is not applicable.

Watch out — Requires providing an API key or token and executing shell commands. Sandbox test passed in a fresh profile with registration into Harness. No obvious pitfalls found.

The verdict — I would install it because sandbox testing passed and it registers into Harness for stable support of Codex task management.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
2Source

vox-director

Alisa0808

2.1k

Turn one topic into a finished Vox-style paper-collage explainer/ad video — automated end to end on Atlas Cloud + ffmpeg. An agent skill.

Installed cleanly when we ran it

GitHub sourcePython1mo ago

AI review

vox-director

What it is — DeepSeek Harness agent skill that automates turning one topic into a Vox-style paper-collage explainer/ad video.

Who it is for — If you are using a coding agent with DeepSeek Harness to generate explainer videos. If you prefer manual control over the video production process.

Watch out — Requires an Atlas Cloud API key and local ffmpeg installation. Static checks indicate it will execute shell commands, but sandbox test confirmed successful installation in a new profile and registration with harness. No obvious pitfalls found.

The verdict — I would install it because it can turn one topic into a finished explainer video.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
1Source

Aegis

GanyuanRan

1.3k

Software-engineering method pack for coding agents, with skills for baseline-first planning, systematic debugging, prompt hygiene, verification before completion, and repair/retirement tracking.

Installed cleanly when we ran it

GitHub sourcePython12d ago

AI review

Aegis

What it is — Aegis is a software engineering method pack for coding agents.

Who it is for — Developers using DeepSeek Harness for complex coding tasks who require baseline-first planning are suitable for installing Aegis. Users who only handle simple requests without needing verification before completion can skip installing it.

Watch out — Sandbox testing passed: it was installed in a new profile and registered by Harness. No obvious issues found.

The verdict — I would install it because it provides verification before completion proofs for coding agents on DeepSeek Harness, which is valuable when proof before "done" is needed.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
1Details

Minke

lencx

669

🐳 DeepSeek Harness Desktop

Did not install when we ran it

GitHub sourceTypeScript8d ago

AI review

Minke

What it is — Minke provides a native desktop workspace for DeepSeek Harness.

Who it is for — Users who need to provide an API key or token when using DeepSeek Harness are suitable to install it. Users who do not need remote access can skip it.

Watch out — Sandbox test shows after installation Harness did not register it into the profile. It needs to provide an API key or token. No other obvious issues found.

The verdict — I will not install it now because the sandbox test showed that after installation Harness did not register it into the profile; if the registration issue is fixed later I will consider it.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
2Source

superdesign-skill

superdesigndev

612

Design skill for UI and marketing graphics on the Superdesign canvas: reads the repo for context, extracts its design system, then generates and iterates branchable design drafts, flow pages, and reusable components through the Superdesign CLI.

Installed cleanly when we ran it

GitHub sourceJavaScript1mo ago

AI review

superdesign-skill

What it is — Superdesign-skill is a design skill that generates iterative design drafts for UI and graphics through the Superdesign CLI.

Who it is for — When iterating product feature page design in Cursor, this plugin provides support for design system extraction and draft generation. If all design tasks are handled in the superdesign.dev web app, then no need to install via plugin.

Watch out — Sandbox test passed: installation and registration into a new profile via harness succeeded. No obvious pitfalls found.

The verdict — I would install it because it supports cross-session continuity, allowing iterations to resume without repeating codebase discovery.

Generated by grok-4.6, and a starting point rather than a verdict. Where it says a plugin installs or does not, that is from a real run in a clean profile — everything else is read off the repository. Trust the source over this.Read the source
1Details