Plugin health audit for DeepSeek Harness
863683348/dsh-plugin-audit · skills
Plugin health audit for DeepSeek Harness: sync the GitHub dsh-plugin topic into a local catalog, probe npm, static-scan for security, score every plugin, and rank them in a web leaderboard.
★ 2GitHub stars
0Forks
2026-08-25Last updated
JavaScriptLanguage
MITLicense
Key features
- Repos with none of these are flagged not-plugin (medium) and capped at grade C, no matter how healthy they look.
- One Cordis pluginhost face (lib/index.js) registers tools + projection + optional schedule
- This filters the half of the topic that is old projects or tag farming.
- Security (v0.2) is a veto, not a weight: audit_scan static-scans a plugin's package.json install scripts, shell scripts, and entry sources for remote-code-execution, encoded commands, rc persistence, obfuscation, and exfiltration to non-allowlisted hosts.
- High/critical findings land in the flags contract → grade D, no matter how healthy the other signals look.
Install command
dsh plugin --profile web add github:863683348/dsh-plugin-audit