# cue-skills-cue-omni-reader-guard — DeepSeek Harness plugin install manifest

> Generated: 2026-09-18 06:57 · Source: https://deepseekmodel.com/plugins

## Overview

Hardening guard for mcp__omni__parse in DeepSeek Harness: a tools/pre-execute listener that denies private/reserved host URLs (SSRF), enforces an allow-list or ask (consent), and is fail-closed when allowedRoots is empty.

## Plugin info

| Category | Maintainer | GitHub stars | License | Primary language | Last push |
| --- | --- | --- | --- | --- | --- |
| Security & Permissions | sensedeal | 7 | — | — | — |

## Install

```bash
dsh plugin --profile web add github:sensedeal/cue-skills#path:/dsh/cue-omni-reader-guard
```

## Steps

1. Install and start DeepSeek Harness (DSH, MIT-licensed open-source agent runtime) — `npx @deepseek-ai/dsh web`
2. Run the command above; the CLI resolves the plugin and verifies its source
3. Confirm with dsh plugins list; restart Harness if needed

> To pin a revision, append #commit to the repository spec.

## Audit before installing

Plugins run with your dsh process permissions and may execute code during installation. Read the repository source and license first, check for destructive commands or excessive access, and pin a commit hash for reproducible installs. This manifest is compiled by DeepseekModel from a public plugin catalog for reference only and does not vouch for third-party plugins.

---

- Repository: https://github.com/sensedeal/cue-skills#cue-omni-reader-guard
- Plugin page: https://deepseekmodel.com/plugin-detail?id=sensedeal%2Fcue-skills-cue-omni-reader-guard
- Source: https://deepseek-harness-plugin.com/zh-CN/plugins/ · Generated 2026-09-16
