Verification
L1 · Found
Security
Medium
Health
Active
Trust
Unrated
What it does
Installation
dsh plugin --profile web add github:knGear/dsh-AgentTaskInstall method: GitHub · not yet tested in container (L3+)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
Requirements
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
DSH.SO AUDITWARNING8c1c97
Security reviewAutomated review · daily
WARNING
No critical findings, but warning-level issues were detected (file writes, remote imports, base64 decoding, downloads).
0 critical·2 warning·2 info·6 files scanned
plugin version
1.1.0dsh manifestscanned commit
8c1c97507cf02026-08-21latest commit
8c1c97507cf0The scan result is valid for the scanned commit. New commits within 7 days are tolerated (the rating still counts); after 7 days without a rescan the badge shows outdated.
`[](https://www.dsh.so/artifact/dsh-agenttask/)`Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
Risk details
| Risk | Rule | Location | Description |
|---|---|---|---|
| warning | Downloads a file from the network | scripts/install-agenttask.sh:30 | curl -fsSL -o "$PLUGIN_DIR/$f" "$BASE/$f" && echo " $f ✓ (raw)" || echo " $f 下载失败 ⚠️" |
| warning | Downloads a file from the network | scripts/install-agenttask.sh:49 | elif curl -fsSL -o "$SKILL_FILE" "$BASE/SKILL.md"; then echo " SKILL.md ✓ (raw)" |
Heuristic static scan — may produce false positives. Review the source yourself before trusting.
Activity
Last commit 2026-08-19 · activity: Active
• Repo created: 2026-08-21
• Stars: ★ 0 · Forks: 0
• Health: Active — committed within last 30 days
Source
GitHub: github.com/knGear/dsh-AgentTask
