dsh plugins中文
← Back to popular plugin directory

Trust pipeline for deepseek-harness plugins

wulun811/dsh-plugin-vet · skills

Trust pipeline for deepseek-harness plugins: deterministic static scan (11 rules) + LLM-driven audit protocol + two-part scorecard, with optional runtime guard (T1 sentinel / T2 fs & childprocess hooks) and honeypot deco.

★ 3GitHub stars
1Forks
2026-09-04Last updated
TypeScriptLanguage
MITLicense

Key features

  • Static scanning is a "speed bump + forensics layer", not a security boundary.
  • R5ctx-escape attempt signal: accessing sandbox-withheld framework members / undeclared services (ctx.plugin, etc.): code scenario only
  • Non-source files.jsx/.tsx/.vue/binaries/wasm, arbitrary .md/.yml, and .json outside package.json: Not in the general scan surface
  • 13-0.1.15Landed the NEXT-GEN-PLAN (N1-N6): hidden capability detection (N1), upgrade behavioral diff (N6), anti-obfuscation decoding, environment snapshot tamper-proofing.
  • The following is split by impact on the verdict, and the forms it explicitly does not detect are listed truthfully (all empirically verified).

Requirements

  • Static scanning is not a security boundary: obfuscated/encoded/dynamically generated code can bypass the AST rules
  • R6 only provides a "suspicious" signal.

Install command

dsh plugin --profile web add github:wulun811/dsh-plugin-vet
View GitHub repository ↗Back to popular plugin directory