dsh-composer-markdown avatar

dsh-composer-markdown

PluginUI & SkinsKnowledge
Verification
L4 · Install tested
Passed
Risk
Medium
Health
Active
Trust
Silver

What it doesAI

A pure client-side DSH Web plugin adding Markdown editing aids (list continuation, code styling, fence auto-close) to the composer.

  • List auto-continuation and automatic renumbering
  • Inline code styling with hidden backticks
  • Automatic closing of code fences

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add dsh-composer-markdown@0.1.1

security scan passed · npm package v0.1.1

Install method: npm · sandbox install verified (L4) · L5 pending

Verification & Compatibility

Records are archived per dsh version under test: each card shows the newest real L1–L5 verdicts on that version (static levels included; fall back to all-time newest with a carried note when absent).

External credentials (plugin-level): none detected

Per-dsh-version verification (L1–L5)
dsh 0.1.3-alpha.1current2026-09-07L5 pending
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.3-alpha.1
  • • Plugin artifact: npm · dsh-composer-markdown@0.1.1
Levels (newest real verdicts on this version)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Not tested
Sandbox install passed (L4)
L5 pending

ID: dsh-composer-markdown@0.1.1@dsh0.1.3-alpha.1 · profile: l4-sandbox

Issued: 2026-09-07 · expires: 2026-09-14

View checks & evidence
L1 · Found✓ Passed

↳ carried from earlier record dsh-composer-markdown@856ce4@dsh0.1.3-alpha.1 (l3-fullscan)

Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed

↳ carried from earlier record dsh-composer-markdown@856ce4@dsh0.1.3-alpha.1 (l3-fullscan)

Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed

↳ carried from earlier record dsh-composer-markdown@856ce4@dsh0.1.3-alpha.1 (l3-fullscan)

Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-07
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-07
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-07
spec dsh-composer-markdown · channel npm package · outcome ran · exit 0
check took: 3.2s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-07
spec dsh-composer-markdown · channel npm package · outcome ran · exit 0
check took: 3.2s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-07
spec dsh-composer-markdown · channel npm package · outcome ran · exit 0
check took: 3.2s
Resolved version recorded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-07
spec dsh-composer-markdown · channel npm package · outcome ran · exit 0
check took: 3.2s
L5 · Run tested– Not tested

This level was not executed in this scan.

Author badges

Embed the official badges in your README to showcase security & install-test status:

dsh.so risk
`[![dsh.so risk](https://www.dsh.so/badge/dsh-composer-markdown.svg)](https://www.dsh.so/artifact/dsh-composer-markdown/)`
dsh.so install
`[![dsh.so install](https://www.dsh.so/badge/install/dsh-composer-markdown.svg)](https://www.dsh.so/artifact/dsh-composer-markdown/)`

Security Report

Automated static scan, not manual review.

DSH.SO VETMEDIUM3a8ee7
Automated review · daily
MEDIUM

Vet verdict is suspicious: findings need human review (exfiltration endpoints, file deletion, etc.).

0 critical·1 high·52 medium
plugin version0.1.1dsh manifest
scanned commit3a8ee7743c8c2026-09-07
latest commit3a8ee7743c8c
vet verdictsuspicious · npm

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

RiskRuleLocationDescription
high
R10
package.json
install 钩子:package.json scripts.prepare(安装期任意代码执行面)
medium
R2
analysis.js:16
require() 动态模块加载(npm 包内能力触达)
medium
R2
analysis.js:17
require() 动态模块加载(npm 包内能力触达)
medium
R2
analysis.js:18
require() 动态模块加载(npm 包内能力触达)
medium
R2
analysis.js:19
require() 动态模块加载(npm 包内能力触达)
Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-09-07 · activity: Active

• Repo created: 2026-09-07

• Stars: ★ 0 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/chendefine/dsh-composer-markdown

Was this page helpful?