truelove-dreamer/dsh-plugin-vetting
DeepSeek Harness插件:对已安装的第三方插件进行启发式恶意软件审查
Project Overview项目介绍
dsh-plugin-vetting is a security scanning tool built exclusively for DeepSeek Harness, designed to check third-party DSH plugins for potential security risks before installation. It ships with a native DSH bundle manifest, so users can install it with a single command: dsh plugin --profile web add dsh-plugin-vetting. It works as a heuristic tripwire similar to antivirus software, performing static scans on plugin source code without executing any of the scanned plugin’s code. It flags suspicious patterns and does not block plugin installation to avoid false positives that break legitimate plugins.
After installation, users can trigger a full scan either by calling the plugin_vet model tool or running the /plugin-vet slash command. The tool automatically scans all third-party DSH plugins stored in the $DSH_HOME/profiles/*/node_modules directory, including scoped plugins under @scope/dsh-plugin-*. It generates a clear text report that lists risk scores, locations of suspicious code, suggested permission narrowings, and the number of unvetted transitive dependencies. This tool is intended for any DSH user who installs third-party plugins from outside the official curated list, helping them make informed installation decisions.
Development and testing of this plugin only uses the Node.js built-in test module, so no extra external dependencies are required to run or modify it. The project clearly outlines its limitations: it cannot detect dynamically loaded runtime code, and it cannot block plugins from calling dangerous primitives directly within the DSH process. It explicitly notes that a clean scan result does not equal a guarantee of complete safety. Version 0.5.1 has a known critical bug that breaks DSH profile startup, so all users must update to version 0.5.6 or newer to use it.
这是一款专为DeepSeek Harness打造的原生插件,核心作用是在用户安装第三方DSH插件前对插件进行静态安全体检,帮助用户将原本的“盲目安装”转变为知情安装。它会扫描插件源码中的可疑恶意模式、越权路径写法和未检查依赖,将各类风险清晰展示给用户。它遵循启发式扫描逻辑,全程不执行待扫描插件的代码,也不拦截插件安装,仅做风险提示和权限优化建议。
安装完成后,用户可以通过调用 plugin_vet 工具或者执行 /plugin-vet 斜杠命令,触发对 $DSH_HOME/profiles/*/node_modules 下所有 dsh-plugin-* 格式第三方插件的扫描。扫描完成后会输出清晰的风险报告,标注风险等级、可疑位置、建议收窄的权限范围和未检查依赖数量。这款工具面向所有自行安装第三方DSH插件的用户,帮助用户提前排查插件安全风险。
本插件开发测试仅依赖Node.js内置测试模块,无额外外部依赖。它明确声明了自身的能力边界:无法检测运行时动态加载的代码,也不能拦截插件在进程内直接调用危险原语,干净的扫描结果不代表绝对安全。旧版本0.5.1存在启动错误,用户需要升级到0.5.6及以上版本才可正常使用。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-plugin-vetting(truelove-dreamer/dsh-plugin-vetting)
仓库:https://github.com/truelove-dreamer/dsh-plugin-vetting
本站详情页:https://www.yhbd.top/plugins/truelove-dreamer-dsh-plugin-vetting/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证未声明 · ⭐ 4 · 最近提交 2026-08-26 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- No license declared - all rights reserved by default; ask the author before commercial use or redistribution未声明开源许可证 —— 默认「保留所有权利」,商用或再分发前先问作者
- Only 4 stars - very few users, little community feedback星标只有 4,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-plugin-vetting
把 truelove-dreamer/dsh-plugin-vetting 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-plugin-vetting
为了您的电脑安全,装插件前,先体检:第三方插件 = 进程内全权限代码,这个工具让"盲装"变成"知情安装"——恶意模式、越权路径、未检查依赖,一目了然。
⚠️ 紧急升级提示:0.5.1 会直接导致 profile 启动失败(正则解析错误,见 issue #1 / #3)。请升级到 0.5.6+:
# 立即拿修复(显式版本绕过发布年龄策略): dsh plugin --profile web add dsh-plugin-vetting@^0.5.6 # 或等版本满 24h 后普通更新: dsh plugin --profile web update dsh-plugin-vetting说明:插件市场(dshmarket)为 pnpm 配置了
minimumReleaseAge=1440(24h)供应链策略,新版本发布后 24h 内不会被自动选中——显式指定@^0.5.6可立即获取。
威胁模型(先读这个)
DSH 插件在 harness 进程内执行,拥有完整权限。因此本插件不是安全边界——它是启发式绊线(类似杀毒软件):静态扫描插件源码,命中可疑模式就报告,从不执行插件代码,不拦截(拦截会误伤正常插件)。
三类威胁,两种输出:
| 威胁 | 输出 | 含义 |
|---|---|---|
| 恶意(外传凭据、eval、持久化) | risk 分数 → SAFE/LOW/MEDIUM/HIGH | 蓄意滥用,需人工核实 |
| 误伤(非恶意,但高权限路径写得太糙) | suggest narrowing 建议区 |
不扣分、不标可疑,只建议收窄权限 |
| 运行时动态加载(下载后 eval、远端模块) | 文档声明 + [REVIEW] 标记 |
静态扫描看不到,不在扫描范围 |
fail-closed 视角:任何命中 eval / new Function / vm.runInNewContext 的插件,无论总分多少都标 [REVIEW: dynamic code execution present]——eval 是静态扫描最大的盲区,它的存在本身就应降级信任,而不是等凑够分数才 HIGH。
真正的根治方案应由 harness 提供"挂载前扫描钩子"——本插件是该思路的独立原型。
功能
| 能力 | 说明 |
|---|---|
plugin_vet 工具 / /plugin-vet 命令 |
扫 $DSH_HOME/profiles/*/node_modules 下所有 dsh-plugin-*(含 @scope/dsh-plugin-*)第三方包 |
| 恶意规则(15 条) | 网络外传、凭据访问、代码执行/混淆、持久化、读会话日志、生命周期脚本(含 install/prepare/prepublishOnly——git 依赖安装时 prepare 也会执行) |
| 误伤规则(3 条) | home 目录宽松读取、字符串拼接路径、递归遍历 home——标为"建议收窄"而非可疑 |
| 传递依赖 | 统计声明依赖数 + 就地扫描嵌套 node_modules/* 的生命周期脚本,报告"N 个未检查" |
[REVIEW] 标记 |
eval/new Function 命中即降级信任,不看总分 |
| 覆盖范围报告 | 每个包报告"扫了 N 个文件、M 行代码、X 个依赖/脚本",让边界显式可见 |
| 运行时表面 | 每个包报告 child_process / fetch / eval / socket 的出现次数——静态能告诉你插件运行时能触及哪些危险原语 |
| 官方包哈希基线(默认开) | @deepseek-ai/* 豁免的同时记录内容哈希基线($DSH_HOME/.dsh-plugin-vetting/baseline.json);安装包与基线不一致 → 豁免自动失效并报警(供应链投毒检测)——从"信任名字"变"信任内容" |
| 插件工具门禁(默认关) | config.gate: "deny-unvetted" 时,tools 管线拒绝调用门禁安装后注册的工具(即插件提供的工具),除非工具名在 allowlistTools 白名单。挂载在 tools.guard(即 tools/pre-execute 同一道闸)——只拦"模型→插件工具"的调用面,不碰插件进程内代码 |
| 运行时绊线(可选,仅日志) | config.monitor: true 时监控 harness 的 ctx.subprocess 通道,可疑命令记警告日志;只记不改 |
| 官方豁免 | @deepseek-ai/* 自动豁免(但见哈希基线) |
| 白名单 | config.allowlist 放行可信插件 |
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
kenryu42/cc-safety-net
hyhmrright/brooks-lint
zhu1090093659/dsh-trading
lire1131/dsh-undo-savepoint
jigjoy-ai/baro
c3ll256/dsh-toy
huaweicloud/huaweicloud-devkit