Verification
L1 · Found
Security
Medium
Health
Active
Trust
Unrated
What it does
A dsh plugin security audit agents team can trigger a security audit and provide a security audit report by submitting an issue
Installation
dsh plugin --profile web add github:SoberReport-AI/DeepGuardInstall method: GitHub · no verification record (L1-L5)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | no verification record |
Requirements
- • Node.js: not stated
- • DSH: not stated
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
DSH.SO VETMEDIUMfd31b3
Security reviewAutomated review · daily
MEDIUM
Vet verdict is suspicious: findings need human review (exfiltration endpoints, file deletion, etc.).
0 critical·3 high·14 medium·0 score
plugin version
—scanned commit
fd31b3e092532026-08-23latest commit
fd31b3e09253vet verdict
suspicious · gitscore 0Vet is an AST static scan (npm artifact or git source).
`[](https://www.dsh.so/artifact/deepguard/)`Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
Risk details
| Risk | Rule | Location | Description |
|---|---|---|---|
| high | R2 | collect-plugins.js:21 | require('child_process') 危险内置模块(执行/网络能力触达) |
| high | R2 | collect-plugins.js:57 | require('https') 危险内置模块(执行/网络能力触达) |
| high | R2 | prescreen-submission.js:31 | require('child_process') 危险内置模块(执行/网络能力触达) |
| medium | R9 | install-command.js:36 | 正则嵌套量词(ReDoS 风险:(a+)+ 类指数回溯) |
| medium | R2 | collect-plugins.js:22 | require('fs') 标准内置模块 |
Heuristic static scan — may produce false positives. Review the source yourself before trusting.
Activity
Last commit 2026-08-23 · activity: Active
• Repo created: 2026-08-23
• Stars: ★ 0 · Forks: 0
• Health: Active — committed within last 30 days
