Heuristic malware review of installed third-party plug-ins
truelove-dreamer/dsh-plugin-vetting · skills
DeepSeek Harness Plugin: Heuristic malware review of installed third-party plugins.
★ 5GitHub stars
2Forks
2026-08-16Last updated
JavaScriptLanguage
—License
Key features
- Malicious rules (15)network outgoing, credential access, code execution/obfuscation, persistence, reading session logs, life cycle scripts (including install/prepare/prepublishOnly - prepare will also be executed when git depends on installation)
- Three types of threats, two outputs
- Heuristic scanningMalicious code disguised as normal writing may still be missed
- Accidental injury rules (3)loose reading of home directory, string splicing path, recursive traversal of home - marked as "recommended to narrow" instead of suspicious
- Transitive dependenciesStatistics of declared dependencies + in-place scanning of nested node_modules/ lifecycle scripts, reporting "N unchecked"
Install command
dsh plugin --profile web add github:truelove-dreamer/dsh-plugin-vetting