DSH HUB
HomePlugin StorePlugin PacksCommunityRankingsResourcesPublish Guide
Plugin source
Back to catalog

dushaobindoudou /

dushaobindoudou/dsh-plugin-security

Verified

Plugin security review for DeepSeek Harness: dependency advisories, contextual evidence, AI-assisted review, and reversible enforcement.

★ 2 Stars0 Forks0 IssuesN/A Community rating0 Confirmed installs
View on GitHubProject homepage
READMESource: main@a10f5c91

dsh-plugin-security

中文 · npm · Changelog

Plugin security review for DeepSeek Harness: dependency advisories, source evidence, AI-assisted contextual review, and reversible enforcement. Includes a Web settings page and agent tools.

Using fetch, process.env, filesystem APIs, or subprocesses is not a malware verdict. Ordinary API matches are capability records. Local data and execution links identify evidence to investigate; an agent reviews the purpose, destination, and authorization before recording a verdict.

Install

Use a current dsh installation with @deepseek-ai/dsh-typert-protocol@0.2.0-rc.2. The plugin requires Node.js 20+; use the Node.js version required by your dsh distribution (Node.js 24 recommended).

# Add to your existing Web profile, then restart its running host.
dsh plugin --profile web add dsh-plugin-security@latest
dsh --profile web

Open Settings → Security Gate. The package declares the standard dsh.bundle patch and dsh.client Web entry point; you do not need to edit the profile manifest manually. For another existing profile, replace web with its name. Agent tools work without the Web connection service; the host must provide tools, pluginManager, and typert.

To enable the bundled review skill for your agent, link it from the installed package (adjust the profile and DSH_HOME if needed):

mkdir -p "${DSH_HOME:-$HOME/.dsh}/skills"
ln -sfn "${DSH_HOME:-$HOME/.dsh}/profiles/web/node_modules/dsh-plugin-security/skills/dsh-plugin-security" \
  "${DSH_HOME:-$HOME/.dsh}/skills/dsh-plugin-security"

To remove the plugin:

dsh plugin --profile web remove dsh-plugin-security

The separately linked skill and stored reports remain until you remove them.

What it does

  • Audits installed dependency versions against npm advisories; looks up fix versions through OSV. Network failures remain unknown, rather than becoming clean cached results.
  • Reads source and text files without executing target code. Evidence includes file, line, snippet, and whether it comes from runtime, support material, or dependency code.
  • Uses bounded JavaScript AST analysis to identify local links such as whole-environment data entering a request body or decoded text entering an execution API. Package-wide co-occurrence alone does not escalate risk.
  • Reuses scans by package version, content fingerprint, and screening-rule revision. Content or rule changes trigger another scan; force rescan is available.
  • Provides searchable risk and action tabs, a whitelist, per-plugin actions, JSON/Markdown export, compact scan statistics, and bilingual settings metadata.
  • Offers reversible disabling after a high-confidence malicious review, with profile backups and a bounded action log.

Risk labels and actions

Label Meaning
High risk High-confidence malicious review, or a high/critical dependency advisory.
At risk Behavior requiring review, other advisories, uncertain reviews, incomplete scans, or failed checks.
No risk found No actionable risk found within this scan's scope. Capability records alone do not change this label. This is not a safety guarantee.
Whitelist Checks were skipped. These entries are separate from “No risk found.”

Risk labels and actions are independent. A high-risk label does not automatically disable a plugin. The old A–F grades are no longer shown; legacy report fields remain for compatibility.

Configuration

Configure these options in the settings page; configuration is stored under $DSH_HOME/plugin-security/state.json (default ~/.dsh/plugin-security/state.json).

Option Default Behavior
Mode report-only off: no scans or enforcement. report-only: scan and save reports without changing target plugins. enforce: apply review-gated disabling.
Automatic disable threshold critical never disables automatic enforcement. critical and high both cover a confirmed high-confidence malicious review, treated as critical for enforcement. Static matches and advisories alone never trigger automatic quarantine.
Upgrade suggestions false Suggest dependency upgrade commands when enabled; commands are not silently executed.
Whitelist Built-in protected entries Add/remove custom package names through the whitelist tab or each plugin row. Entries skip checks; built-in protected entries cannot be removed in the UI.

Automatic disabling also requires enforce mode and an unprotected target. It removes the bundle from the profile and renames the package directory with a .security-quarantined suffix. Restart dsh for the change to take effect. Undo restores the bundle and directory. Self and built-in protected packages cannot be disabled or uninstalled through this plugin; the server enforces this restriction.

The scan state and action log are local. Profile edits use atomic writes and keep up to five rolling snapshots; the state retains up to 200 action-log entries. State directories/files use permissions 0700/0600 where supported.

Agent tools

security_scan { package?, force?, evidence? }
security_review { package, verdict, confidence?, reason? }

verdict is malicious, suspicious, or benign; confidence is high, medium, or low. A high-confidence benign review can resolve static concerns, but does not remove dependency advisory facts. Suspicious or uncertain reviews require human follow-up.

The bundled review skill treats target source, comments, README, and skill text as untrusted evidence. Reports do not themselves invoke a model; contextual review uses your dsh agent and its configured tools/provider.

Privacy and limits

Dependency auditing sends package names and installed versions to npm, and advisory IDs to OSV for fix lookup. These requests do not upload source code or local paths. Agent-assisted review follows your configured model provider's data handling; evidence passed to an agent may contain source snippets.

This is post-load inspection, not a sandbox or a pre-install execution barrier. The inspector and plugins share the host process and permissions. Static analysis is bounded (including file/byte budgets) and does not cover all cross-file flows, dynamic behavior, network transports, or transitive vulnerabilities. Truncated or failed checks remain visible. Whitelisting deliberately removes coverage. Review verdicts are stored locally and are not an independent cryptographic trust guarantee.

Development and release

corepack pnpm install --frozen-lockfile
pnpm test
npm pack --dry-run

Tests cover detection and false-positive cases, profiles, cache invalidation, reversible disposition, settings behavior, and real Cordis/Typert/gateway RPC lifecycles. Shared host protocol packages are declared as peer and development dependencies per the dsh packaging guide.

See CONTRIBUTING.md for development and release steps. Runtime JavaScript is shipped directly; consumers need no build script or install-time code execution from this package.

Troubleshooting HTTP 404

transport failure for /api/security/status: HTTP 404 means the host has not registered the settings RPC route. Upgrade this plugin, check the protocol peer version, and restart dsh. The plugin registers an explicit host contract and follows the Web connection service lifecycle.

Look for plugin-security: RPC contract registration failed or Fetch route registration failed in host logs. $DSH_HOME/plugin-security/remote-diag.json records observed service and route registration state. Headless profiles without a Web connection use the agent tools instead.

License

MIT © 2026 dushaobindoudou.

—/ 5

No ratings yet

Verified DSH bundle

Commit a10f5c915986

Community comments

No comments yet. Be the first to write one.

DSH HUB

A community index for DSH plugins. Not an official GitHub or DeepSeek AI product.

CommunityResourcesAPIAbout