liuwenji007/dsh-trust-check 预览 preview

liuwenji007/dsh-trust-check

Plugin插件 Native原生 ⭐ 2 MIT Approval & Security审批与安全

Static capability disclosure for DeepSeek Harness plugins — evidence-backed, zero-token, no safety claims.

Project Overview项目介绍

dsh-trust-check is a DeepSeek Harness–native audit plugin that performs static, code-level capability disclosure against installed plugins, surfacing permission usage, injection surfaces, source provenance, and install-script presence with file/line/snippet evidence and zero token spend. It installs into DSH Web via dsh plugin --profile web add dsh-trust-check, requires host ≥ 0.1.0-rc.8 (0.1.1-rc.2 recommended) because the settings page depends on @deepseek-ai/dsh-client-store, and additionally ships a host-independent npx dsh-trust-check CLI that scans arbitrary extracted directories with --dir, emits a unified AuditResponse JSON containing schemaVersion, profile, dir, generatedAt, plugins, and errors, and supports --exit-code for scripted and CI gating with explicit semantic codes 0/1/2/3.

Typical usage is to extract a candidate plugin into a temporary directory and run the CLI as a pre-install gate, or to open Settings → Plugin Health Check in DSH Web to re-examine already-installed plugins and confirm their real outbound destinations, workspace-external paths, and credential-touching call sites. The report uses a decision-first layout with five verdicts — red line, risk acknowledged, needs review, capabilities as expected, and no static risk signal — and acknowledgement writes a trust-ack.json fingerprint that mismatches (returning HTTP 409) whenever capabilities, destinations, paths, key touches, red lines, or skill bodies change, while AI explanation is opt-in, never alters verdicts, and is unavailable when no model is configured.

Dependencies include a tsdown build that emits a node half (lib/index.js) and a client half (lib/client.js), vitest covering the core engine, and tsc --noEmit for typechecking under MIT licence, with rules stored as a hot-updatable data table at src/core/seams.ts. Known limits: node_modules is skipped, remote tarballs are not fetched, runtime-concatenated URLs and obfuscated eval/Function may evade rules, the new URL base exemption is deliberate and must not be widened, link/file-local plugins without a repository field display as "undeclared repo", and profile mode audits post-install so install/postinstall/prepare may have already run, which is why the recommended pre-install flow extracts the package first, then runs npx dsh-trust-check --dir ./pkg --spec npm:foo@1.0.0 --json and validates via the bundled scripts/market-gate-demo.mjs.

dsh-trust-check 是面向 DeepSeek Harness 的安全审计插件,对已安装插件做静态代码层面的能力披露,覆盖权限调用、注入、来源链路、安装脚本等事实,并附文件、行号与原文片段。它通过 dsh plugin --profile web add dsh-trust-check 装入 DSH Web,需宿主 ≥ 0.1.0-rc.8;同时提供 npx dsh-trust-check 独立 CLI,可对任意已解压目录 --dir 扫描,输出统一 AuditResponse JSON,便于脚本与 CI 接入。报告采用决策优先布局,含「有红线 / 风险已确认 / 需确认 / 能力如预期 / 静态未见风险信号」五级裁决,且确认请求须带 ackFingerprint,能力变化时 409 要求重确认,AI 解释只改摘要不改裁决。

典型使用场景为安装前把待装包解到临时目录用 CLI 闸门扫一遍,或在 Web 设置页的「插件体检」中复核已装插件的真实去向与凭证读取面,适合关心供应链透明度与装后行为的集成方、CI 与终端用户。它声明只下「检测到某能力」的事实结论,不下安全背书,过滤策略由集成方决定。依赖方面,tsdown 构建出 node 与 client 双半,vitest 覆盖核心引擎;MIT 许可,规则表 src/core/seams.ts 可热更,明文 HTTP 永不因白名单降级。

已知局限包括:不展开 node_modules、不解压远程 tarball、不对运行时拼接与混淆做判断;静态扫描存在漏判与误判可能,已记录 new URL base 豁免、解构到函数名、内网 IP 仅列入去向不判红线、link:/file: 本地安装可能未声明仓库等已知代价。profile 模式审的是已装插件,install/postinstall/prepare 在首次扫描前可能已执行;--dir 模式可在安装前对解压目录扫描,但市场侧脚本仍可能先跑,建议先解包再 --dir 并配合 market-gate-demo.mjs 验证。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add dsh-trust-check

把 liuwenji007/dsh-trust-check 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-trust-check

English

DeepSeek Harness 插件静态能力披露:权限、注入、来源、安装脚本——代码判定、可复现、零 token。

不是"杀毒软件",也不做安全承诺。它只做能证明的事:把插件真实会碰什么、注入了什么、来源是否可核对摊开给你看,结论每一条都附证据(文件 + 行号 + 片段),你可以自己复核。

本项目只产出事实,不下"安全 / 可信"结论,也不提供背书;过滤策略由集成方和用户决定。详见 产品定位与边界。

安装

设置页需要 dsh ≥ 0.1.0-rc.8(建议 0.1.1-rc.2)。 Web UI 依赖宿主模块表里的 @deepseek-ai/dsh-client-store;市场不会拦不匹配的升级,老宿主上装了设置页也会加载失败(dsh-client-store missed the module table)。

CLI 不依赖 DSH 宿主,旧 dsh 上仍可用 npx dsh-trust-check。

先确认宿主(只影响设置页):

dsh --version
# 过旧则:npm i -g @deepseek-ai/dsh@latest
dsh plugin --profile web add dsh-trust-check

重启 dsh web,打开 设置 → 插件体检。已安装要升级:市场一键更新,或 dsh plugin --profile web add dsh-trust-check@latest,再重启。

同时提供独立 CLI,不依赖 DSH 宿主:

npx dsh-trust-check                 # 审计默认 profile `web`
npx dsh-trust-check --profile work  # 审计其他 profile
npx dsh-trust-check --json          # 机器可读输出

# 审计任意已解压的包目录(无需 profile、无需 DSH)
npx dsh-trust-check --dir ./path/to/plugin
npx dsh-trust-check --dir ./pkg --spec npm:foo@1.0.0 --json

# 用退出码做脚本 / CI 闸门(可选)
npx dsh-trust-check --dir ./pkg --exit-code

--dir 与 --profile 互斥。两种模式的 --json 输出同为 AuditResponse 形状 { schemaVersion, profile, dir?, generatedAt, plugins, errors };单目录模式下 profile 为空字符串,dir 为绝对路径。详见 docs/audit-schema.md / docs/INTEGRATION.md。

默认退出码始终为 0。加 --exit-code 后:0 未检出(profile 模式含已确认),1 需确认,2 有红线,3 扫描失败;profile 模式取所有插件中最严重的一项。0 只代表本次静态扫描没有检出,不代表安全。 参数写错(未知参数、--dir 等缺值)会直接报错并以 1 退出。

设置 → 插件体检 CLI --dir --json
设置页插件体检 CLI JSON 输出

排障

碰到 怎么处理
设置页 dsh-client-store missed the module table 宿主过旧:先升 dsh ≥ 0.1.0-rc.8,再重启 Web;审计可先用上面的 CLI
设置里没有「插件体检」 确认已 add、已重启;或宿主太旧导致客户端未加载

怎么读报告

设置页与 CLI 采用决策优先布局,阅读顺序:

  1. 决策:徽章 + 动作句 +「为什么要小心」(最多 3 条)
  2. 扫描:能力芯片 → 注入摘要(默认折叠)→ 来源
  3. 取证:证据按能力分组,默认折叠
裁决 含义 何时出现
有红线 命中硬红线,默认应停用;可「确认风险」后继续 redLines 非空,且未确认当前指纹
风险已确认 已确认当前红线风险 有红线,trust-ack.json 与本次扫描一致
需确认 未见硬红线,但有特权能力或 patch 改动 有能力或 override/disable,无红线
能力如预期 已确认当前能力与去向指纹 trust-ack.json 与本次扫描一致(无红线)
静态未见风险信号 未见红线或特权能力;不是安全保证 其余

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-codex-approval 下一个 Next dsh-sessions-diagnosis →