dsh-plugin-vetting
Vets third-party plugins before you trust them: static scan for malicious patterns (exfiltration, credential access, obfuscation, persistence) and over-privileged path use, transitive-dependency coverage, official-package hash baseline for supply-chain tamper detection, and an optional plugin-tool call gate.
为了您的电脑安全,装插件前先体检:静态扫描恶意模式(外传/凭据/混淆/持久化)与高权限误用,覆盖传递依赖与官方包哈希基线(防供应链篡改),可选插件工具调用闸。
How to install
dsh plugin add dsh-plugin-vetting About
dsh-plugin-vetting **为了您的电脑安全**,装插件前,先体检:第三方插件 = 进程内全权限代码,这个工具让"盲装"变成"知情安装"——恶意模式、越权路径、未检查依赖,一目了然。 **⚠️ 紧急升级提示**:**0.5.1 会直接导致 profile 启动失败**(正则解析错误,见 issue #1 / #3)。请升级到 **0.5.6+**: bash # 立即拿修复(显式版本绕过发布年龄策略): dsh plugin --profile web add dsh-plugin-vetting@^0.5.6 # 或等版本满 24h 后普通更新: dsh plugin --profile web update dsh-plugin-vetting 说明:插件市场(dshmarket)为 pnpm 配置了 minimumReleaseAge=1440(24h)供应链策略,新版本发布后 24h 内不会被自动选中——显式指定 @^0.5.6 可立即获取。 威胁模型(先读这个) DSH 插件在 harness 进程内执行,拥有完整权限。因此本插件**不是安全边界**——它是**启发式绊线**(类似杀毒软件):静态扫描插件源码,命中可疑模式就报告,**从不执行插件代码**,**不拦截**(拦截会误伤正常插件)。 **三类威胁,两种输出:** | 威胁 | 输出 | 含义 | …
Recommendation signals
Meta
- License
- MIT
- Language
- JavaScript
- GitHub stars
- 4
- mo. downloads
- 754
- Last push
- 2026-08-26
- Created
- 2026-08-15
Basic safety check
- Findings
- None
- Sources
- curated:awesome-dsh-plugin.com, curated:awesome-dsh-plugin/awesome-dsh-plugin
- Topics
- deepseek, dsh, dsh-plugin
Related plugins
dsh-auto-mode
NanmiCoder/dsh-auto-mode
Adds an Auto permission preset between Workspace Write and Full access: routine work stays in the official workspace-write sandbox while the current session model reviews escalation and destructive calls, granting one exact wider access once, asking when the intent is ambiguous, and denying critical paths.
dsh-passwords
slywalker2006/dsh-passwords
Turns DeepSeek Harness into a server-grade multi-tenant platform: remote access + auto HTTPS, subuser permissions & token/daily quotas, sandbox enforcement, encrypted auth & audit log.
sofagent
KongFangXun/sofagent/tree/main/engine/dsh-plugins/cordis-plugin-sofagent-audit
Commit-time audit harness for AI coding agents: 24 git-diff rules (secrets, out-of-scope edits, prompt injection), HMAC-signed audit trail, snapshot rollback, and an MCP server with 84 tools. Installable via dsh plugin add.
dsh-vault
Ox0400/dsh-vault
Encrypted local credentials vault for the Harness: a web settings page and vault_* tools to store, search and copy passwords, API keys, TOTP secrets and card data, with health audits, expiry rotation, imports/exports and read-only/ask access modes.