dsh plugins中文
← Back to popular plugin directory

DSH plug-in development tool

omdsh-dev/dsh-security-audit · tools

DSH native security audit plug-in: Configuration/Plug-in Source/Session/Network Exposure, read-only desensitization risk report

★ 14GitHub stars
0Forks
2026-08-15Last updated
TypeScriptLanguage
MITLicense

Key features

  • Read-onlyNever modify/delete any files, never execute the code of the audited plug-in, and never actively connect to remote targets.
  • Desensitization protocolThe suspected secret (token/key/private key/password) is immediately used as an HMAC fingerprint with an in-process random key after reading. The original value is only used for fingerprint calculation and is not entered into canonical output
  • Secret desensitizationSuspected secrets only return type/length/in-process random HMAC fingerprint/path/line number, and the complete value never appears in canonical output (design-level guarantee, non-truncation)
  • Path fenceAll paths are checked by lstat → realpath → containment
  • root is fixed to $DSH_HOME parsed when the process is started (or allowedRoot declared by the administrator), and the model parameters cannot expand the reading range.

Requirements

  • Consumption verificationtarball is loaded into rc.6 consumer → dsh --profile compat --dump-config This plug-in row appears → the actual registration and execution of the tool pass

Install command

dsh plugin --profile web add github:omdsh-dev/dsh-security-audit
View GitHub repository ↗Back to popular plugin directory