Dsh Plugin Security Review · security review
ateen18/dsh-plugin-security-review · skills
Security review gate for DeepSeek Harness (dsh) plugins: static pre-install vetting of malicious code, vulnerabilities and supply-chain risks (with deobfuscation decoding), runtime audit, optional tool-call guard, and a.
★ 2GitHub stars
0Forks
2026-08-28Last updated
JavaScriptLanguage
—License
Key features
- Score (0-100), verdict pass / warn / block / audit, per-finding detail (severity, category, file:line, snippet, recommendation) and an install recommendation.
- Persisted under $DSH_HOME/security-review/: reports/latest/ .md (markdown), reports/history/.json, index.json.
- The web settings UI gains a security-review section (policy, auto-disable switch, allowlist).
Requirements
- Static analysis cannot cover native binaries, runtime-downloaded code, or heavily obfuscated payloads
- block means strong risk signals, not proof of malice.
Install command
dsh plugin --profile web add github:ateen18/dsh-plugin-security-review