dsh-malware-audit
Real AST-based scan of installed plugins for malicious-intent patterns (dynamic eval, cross-plugin writes, exfiltration-shaped network calls), with an optional periodic schedule and auto-quarantine on critical findings.
基于 AST 的已装插件恶意行为扫描:识别动态 eval、跨插件写入、外泄型网络调用等模式,并给出可复核的报告。
How to install
dsh plugin add github:rand0wn/dsh-malware-audit About
dsh-malware-audit A DeepSeek Harness (dsh) plugin that scans installed plugins' real syntax trees for patterns shaped like malicious intent — the one thing every other dsh audit tool explicitly declines to do — with an optional periodic schedule and opt-in auto-quarantine on critical findings. Why dsh plugins run with real filesystem and process access, and installing one is a one-line command. Existing audit tools (dsh-security-audit, dsh-plugin-audit) do this well for *capability* — they report that a plugin *can* touch the filesystem, network, or credentials, then explicitly stop short of j…
Recommendation signals
Meta
- License
- MIT
- Language
- TypeScript
- GitHub stars
- 0
- mo. downloads
- –
- Last push
- 2026-08-21
- Created
- 2026-08-21
Links
Basic safety check
- Findings
- curated 收录但无 npm 包/安装命令
- Sources
- curated:awesome-dsh-plugin.com, curated:awesome-dsh-plugin/awesome-dsh-plugin
- Topics
- cordis, deepseek-harness, dsh-plugin, security
Related plugins
claude-code-templates
davila7/claude-code-templates
CLI tool for configuring and monitoring Claude Code
semiotic
nteract/semiotic
React data visualization library for streaming, networks, and AI-assisted development
loki-mode
asklokesh/claudeskill-loki-mode
Multi-agent autonomous SDLC framework. Spec to deployed app. PRD, GitHub issue, OpenAPI/JSON/YAML, or one-line brief. 5 AI providers, 8 quality gates.
deepseek-harness-desktop
dsh-tauri-desk/deepseek-harness-desktop
DeepSeek Harness Tauri 桌面版 | Only 5mb installer, zero environment setup, preset plugins, Windows / macOS / Linux.