dsh-plugin-sentinel
插件安装前静态安全审计:生命周期脚本、动态执行、凭据外传组合特征与 patch 层风险;零依赖,tar 包全程内存解析不落盘。
Static pre-install security auditor for plugin bundles: lifecycle scripts, dynamic execution, credential-exfiltration combos, and patch-layer hazards, with zero dependencies and in-memory tar parsing.
怎么安装
dsh plugin add github:BotonJ/dsh-plugin-sentinel 简介
dsh-plugin-sentinel 🔒 **DSH 插件安检机** — 给 DeepSeek Harness 装一台插件安检机:在安装任何社区插件**之前**做纯静态安全审计,输出按严重度排序的结构化风险报告。 官方文档对 GitHub 安装方式的警告原话:prepare 脚本授权是 *"permission to execute the package's code on your machine at install time, outside any sandbox the agent runs under"*。DSH 生态 24 小时收录 288+ 社区插件——这台安检机就是为了让"先过安检再安装"成为一句话的事。 安装 sh dsh plugin --profile <你的profile> add github:<你的fork>/dsh-plugin-sentinel 或本地安装 dsh plugin --profile <你的profile> add ./dsh-plugin-sentinel 装好后对 DSH 说: 「帮我装 github:xxx/yyy 这个插件」→ 模型会先调 audit_plugin 过安检,block 则拒绝安装并说明风险 「巡检我当前 profile 装过的插件安不安全」→ audit_installed 提供的工具 | 工具 | 用途…
推荐参考
信息
- 协议
- MIT
- 语言
- JavaScript
- GitHub 星标
- 1
- 月下载
- –
- 最近更新
- 2026-08-15
- 创建于
- 2026-08-15
基础安全检查
- 检查结果
- curated 收录但无 npm 包/安装命令
- 收录来源
- curated:awesome-dsh-plugin.com, curated:awesome-dsh-plugin/awesome-dsh-plugin
- 主题标签
- deepseek-harness, dsh-plugin, security
同类推荐
dsh-auto-mode
NanmiCoder/dsh-auto-mode
在 Workspace Write 与 Full access 之间增加 Auto 权限档:日常操作留在官方 workspace-write 沙箱内,由当前会话模型复核升权与破坏性调用,精确的越界访问按次放行一次,意图不明时询问,命中关键路径则拒绝。
dsh-passwords
slywalker2006/dsh-passwords
让 DeepSeek Harness 变成服务器级多租户平台:远程访问 + 自动 HTTPS、子用户权限与配额、沙盒强制、加密认证与审计日志。
sofagent
KongFangXun/sofagent/tree/main/engine/dsh-plugins/cordis-plugin-sofagent-audit
面向 AI 编程 agent 的提交时审计 harness——24 条 git diff 规则(密钥泄漏、越界改动、提示注入)、HMAC 签名审计链、快照回滚、84 工具 MCP server;dsh plugin add 即装。
dsh-vault
Ox0400/dsh-vault
Harness 的本地加密凭据保险库:Web 设置页与 vault_* 工具,可存取与复制密码、API 密钥、TOTP 与银行卡信息,支持健康审计、到期轮换、导入导出以及只读/询问访问模式。