What it doesAI
DSH宿主级图片理解插件,提供vision_describe工具,多后端自动降级识别图片。
- vision_describe工具随DSH启动自动挂载
- MiniMax→智谱→Ollama三层后端自动降级
- 密钥安全存储,错误信息剥离图片数据
AI-generated from the repo README — for reference only.
Installation
dsh plugin --profile web add github:YNM10086/deepseek-mcp-pluginInstall method: GitHub · not yet tested in container (L3+)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
Requirements
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
No critical or warning findings in the automated scan. The result is valid only for the commit hash shown.
1.0.0dsh manifest8cb84e4591cd2026-08-208cb84e4591cdThe scan result is valid for the scanned commit. New commits within 7 days are tolerated (the rating still counts); after 7 days without a rescan the badge shows outdated.
Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
vet verdict: vet: suspicious · score 78
- R14 · high [likely] — 脚本下载即执行:PowerShell Invoke-Expression(脚本随包分发,安装/运行期任意代码执行面)
- R10 · info [heuristic] — 依赖清单:2 项(@modelcontextprotocol/sdk, zod,供 LLM 审计供应链;已知漏洞核对见后续 OSV 精确版本查询(网络失败静默降级))
- R3 · info [certain] — 只读 process 成员(能力触达面):process.env
- R3 · info [certain] — 只读 process 成员(能力触达面):process.env
- R3 · info [certain] — 只读 process 成员(能力触达面):process.env
vet is advisory and does not change dsh’s four-tier level.
• Static heuristic scan: done (4 files)
• Dependency vulnerabilities: requires deep audit (L3+)
• Permission sandboxing: requires runtime testing (L4+)
Activity
Last commit 2026-08-15 · activity: Active
• Repo created: 2026-08-20
• Stars: ★ 0 · Forks: 0
• Health: Active — committed within last 30 days
