dsh-ccs-security avatar

dsh-ccs-security

PluginSecurity
Verification
L1 · Found
Security
Medium
Health
Active
Trust
Unrated

What it doesAI

Zero-dependency runtime security plugin for DeepSeek Harness with bidirectional scanning and Ed25519 receipts.

  • Zero dependency runtime security gate
  • 16 rule bidirectional scanning
  • Ed25519 cryptographic receipts under 3μs

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add github:DSHCorrectover/dsh-ccs-security

Install method: GitHub · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SO VETMEDIUM02cc49
Automated review · daily
MEDIUM

Vet verdict is suspicious: findings need human review (exfiltration endpoints, file deletion, etc.).

0 critical·6 high·0 medium·4 score
plugin version1.0.1dsh manifest
scanned commit02cc4928e4892026-08-22
latest commit02cc4928e489
vet verdictsuspicious · npmscore 4

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

RiskRuleLocationDescription
high
R13
ssrf.js:32
硬编码外联端点:AWS 云元数据端点(IAM 凭据外泄面)
high
R13
ssrf.js:32
硬编码外联端点:AWS 云元数据端点(IAM 凭据外泄面)
high
R13
ssrf.js:32
硬编码外联端点:AWS 云元数据端点(IAM 凭据外泄面)
high
R13
ssrf.js:33
硬编码外联端点:阿里云元数据端点(凭据外泄面)
high
R13
ssrf.js:33
硬编码外联端点:阿里云元数据端点(凭据外泄面)
Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-08-22 · activity: Active

• Repo created: 2026-08-22

• Stars: ★ 0 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/DSHCorrectover/dsh-ccs-security

Was this page helpful?