liuwenji007/dsh-trust-check
Static capability disclosure for DeepSeek Harness plugins — evidence-backed, zero-token, no safety claims.
Project Overview项目介绍
dsh-trust-check is a DeepSeek Harness–native audit plugin that performs static, code-level capability disclosure against installed plugins, surfacing permission usage, injection surfaces, source provenance, and install-script presence with file/line/snippet evidence and zero token spend. It installs into DSH Web via dsh plugin --profile web add dsh-trust-check, requires host ≥ 0.1.0-rc.8 (0.1.1-rc.2 recommended) because the settings page depends on @deepseek-ai/dsh-client-store, and additionally ships a host-independent npx dsh-trust-check CLI that scans arbitrary extracted directories with --dir, emits a unified AuditResponse JSON containing schemaVersion, profile, dir, generatedAt, plugins, and errors, and supports --exit-code for scripted and CI gating with explicit semantic codes 0/1/2/3.
Typical usage is to extract a candidate plugin into a temporary directory and run the CLI as a pre-install gate, or to open Settings → Plugin Health Check in DSH Web to re-examine already-installed plugins and confirm their real outbound destinations, workspace-external paths, and credential-touching call sites. The report uses a decision-first layout with five verdicts — red line, risk acknowledged, needs review, capabilities as expected, and no static risk signal — and acknowledgement writes a trust-ack.json fingerprint that mismatches (returning HTTP 409) whenever capabilities, destinations, paths, key touches, red lines, or skill bodies change, while AI explanation is opt-in, never alters verdicts, and is unavailable when no model is configured.
Dependencies include a tsdown build that emits a node half (lib/index.js) and a client half (lib/client.js), vitest covering the core engine, and tsc --noEmit for typechecking under MIT licence, with rules stored as a hot-updatable data table at src/core/seams.ts. Known limits: node_modules is skipped, remote tarballs are not fetched, runtime-concatenated URLs and obfuscated eval/Function may evade rules, the new URL base exemption is deliberate and must not be widened, link/file-local plugins without a repository field display as "undeclared repo", and profile mode audits post-install so install/postinstall/prepare may have already run, which is why the recommended pre-install flow extracts the package first, then runs npx dsh-trust-check --dir ./pkg --spec npm:foo@1.0.0 --json and validates via the bundled scripts/market-gate-demo.mjs.
dsh-trust-check 是面向 DeepSeek Harness 的安全审计插件,对已安装插件做静态代码层面的能力披露,覆盖权限调用、注入、来源链路、安装脚本等事实,并附文件、行号与原文片段。它通过 dsh plugin --profile web add dsh-trust-check 装入 DSH Web,需宿主 ≥ 0.1.0-rc.8;同时提供 npx dsh-trust-check 独立 CLI,可对任意已解压目录 --dir 扫描,输出统一 AuditResponse JSON,便于脚本与 CI 接入。报告采用决策优先布局,含「有红线 / 风险已确认 / 需确认 / 能力如预期 / 静态未见风险信号」五级裁决,且确认请求须带 ackFingerprint,能力变化时 409 要求重确认,AI 解释只改摘要不改裁决。
典型使用场景为安装前把待装包解到临时目录用 CLI 闸门扫一遍,或在 Web 设置页的「插件体检」中复核已装插件的真实去向与凭证读取面,适合关心供应链透明度与装后行为的集成方、CI 与终端用户。它声明只下「检测到某能力」的事实结论,不下安全背书,过滤策略由集成方决定。依赖方面,tsdown 构建出 node 与 client 双半,vitest 覆盖核心引擎;MIT 许可,规则表 src/core/seams.ts 可热更,明文 HTTP 永不因白名单降级。
已知局限包括:不展开 node_modules、不解压远程 tarball、不对运行时拼接与混淆做判断;静态扫描存在漏判与误判可能,已记录 new URL base 豁免、解构到函数名、内网 IP 仅列入去向不判红线、link:/file: 本地安装可能未声明仓库等已知代价。profile 模式审的是已装插件,install/postinstall/prepare 在首次扫描前可能已执行;--dir 模式可在安装前对解压目录扫描,但市场侧脚本仍可能先跑,建议先解包再 --dir 并配合 market-gate-demo.mjs 验证。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-trust-check(liuwenji007/dsh-trust-check)
仓库:https://github.com/liuwenji007/dsh-trust-check
本站详情页:https://www.yhbd.top/plugins/liuwenji007-dsh-trust-check/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 2 · 最近提交 2026-10-03 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-trust-check
把 liuwenji007/dsh-trust-check 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-trust-check
DeepSeek Harness 插件静态能力披露:权限、注入、来源、安装脚本——代码判定、可复现、零 token。
不是"杀毒软件",也不做安全承诺。它只做能证明的事:把插件真实会碰什么、注入了什么、来源是否可核对摊开给你看,结论每一条都附证据(文件 + 行号 + 片段),你可以自己复核。
本项目只产出事实,不下"安全 / 可信"结论,也不提供背书;过滤策略由集成方和用户决定。详见 产品定位与边界。
安装
设置页需要 dsh ≥ 0.1.0-rc.8(建议 0.1.1-rc.2)。 Web UI 依赖宿主模块表里的 @deepseek-ai/dsh-client-store;市场不会拦不匹配的升级,老宿主上装了设置页也会加载失败(dsh-client-store missed the module table)。
CLI 不依赖 DSH 宿主,旧 dsh 上仍可用 npx dsh-trust-check。
先确认宿主(只影响设置页):
dsh --version
# 过旧则:npm i -g @deepseek-ai/dsh@latest
dsh plugin --profile web add dsh-trust-check
重启 dsh web,打开 设置 → 插件体检。已安装要升级:市场一键更新,或 dsh plugin --profile web add dsh-trust-check@latest,再重启。
同时提供独立 CLI,不依赖 DSH 宿主:
npx dsh-trust-check # 审计默认 profile `web`
npx dsh-trust-check --profile work # 审计其他 profile
npx dsh-trust-check --json # 机器可读输出
# 审计任意已解压的包目录(无需 profile、无需 DSH)
npx dsh-trust-check --dir ./path/to/plugin
npx dsh-trust-check --dir ./pkg --spec npm:foo@1.0.0 --json
# 用退出码做脚本 / CI 闸门(可选)
npx dsh-trust-check --dir ./pkg --exit-code
--dir 与 --profile 互斥。两种模式的 --json 输出同为 AuditResponse 形状 { schemaVersion, profile, dir?, generatedAt, plugins, errors };单目录模式下 profile 为空字符串,dir 为绝对路径。详见 docs/audit-schema.md / docs/INTEGRATION.md。
默认退出码始终为 0。加 --exit-code 后:0 未检出(profile 模式含已确认),1 需确认,2 有红线,3 扫描失败;profile 模式取所有插件中最严重的一项。0 只代表本次静态扫描没有检出,不代表安全。 参数写错(未知参数、--dir 等缺值)会直接报错并以 1 退出。
| 设置 → 插件体检 | CLI --dir --json |
|---|---|
![]() |
![]() |
排障
| 碰到 | 怎么处理 |
|---|---|
设置页 dsh-client-store missed the module table |
宿主过旧:先升 dsh ≥ 0.1.0-rc.8,再重启 Web;审计可先用上面的 CLI |
| 设置里没有「插件体检」 | 确认已 add、已重启;或宿主太旧导致客户端未加载 |
怎么读报告
设置页与 CLI 采用决策优先布局,阅读顺序:
- 决策:徽章 + 动作句 +「为什么要小心」(最多 3 条)
- 扫描:能力芯片 → 注入摘要(默认折叠)→ 来源
- 取证:证据按能力分组,默认折叠
| 裁决 | 含义 | 何时出现 |
|---|---|---|
| 有红线 | 命中硬红线,默认应停用;可「确认风险」后继续 | redLines 非空,且未确认当前指纹 |
| 风险已确认 | 已确认当前红线风险 | 有红线,trust-ack.json 与本次扫描一致 |
| 需确认 | 未见硬红线,但有特权能力或 patch 改动 | 有能力或 override/disable,无红线 |
| 能力如预期 | 已确认当前能力与去向指纹 | trust-ack.json 与本次扫描一致(无红线) |
| 静态未见风险信号 | 未见红线或特权能力;不是安全保证 | 其余 |
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →


Minglink/dsh-infinite-gen-4
kenryu42/cc-safety-net
hyhmrright/brooks-lint
toby-bridges/api-relay-audit
hashgraph-online/hol-guard
SeaOf0/dsh-redteam-model
howmp/dsh-pentest
saya-ch/dsh-mobile