DSH-Desktop avatar

DSH-Desktop

Electron desktop shell for DeepSeek Harness, bundling node, pnpm, and the DSH runtime for one-click access to the dsh web UI.

PluginAI ModelsDesktopBrowserTerminalWeb searchTerminal / Shell
Verification
L2 · Structured
Security
High
Health
Active
Trust
Silver

What it does

Electron desktop shell for DeepSeek Harness, bundling node, pnpm, and the DSH runtime for one-click access to the dsh web UI.

Installation

dsh plugin --profile web add github:harismuna5268/DSH-Desktop

Install method: GitHub · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SOHIGH-RISKSCAN10 FILES
d26c6a
Automated review · daily
HIGH-RISK

Critical findings in non-blocking categories (dynamic code execution, shell execution, install scripts, obfuscation). Common in CLI/terminal plugins but worth reviewing.

9 critical·2 warning·17 info·10 files scanned
code-exec ×9
plugin version0.1.1
scanned commitd26c6a4fa0fa2026-08-19
latest commitd26c6a4fa0fa

The scan result is only valid for the scanned commit. If the latest commit differs, the badge shows outdated until the daily pipeline rescans.

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk: High9 critical · 2 warning · 17 info

• Static heuristic scan: done (10 files)

• Dependency vulnerabilities: requires deep audit (L3+)

• Permission sandboxing: requires runtime testing (L4+)

High-risk findings · 11 / 11

  • criticalChild process module usage (Node.js)scripts/collect-runtime.mjs:9
    import { execFileSync } from 'node:child_process'
  • criticalChild process module usage (Node.js)scripts/install-desktop-plugin.mjs:30
    import { spawn } from 'node:child_process'
  • criticalChild process module usage (Node.js)src/dsh-host.ts:7
    import { spawn, type ChildProcess } from 'node:child_process'
  • criticalChild process module usage (Node.js)src/dsh-host.ts:40
    export function startDsh(port: number, bin: string): ChildProcess {
  • criticalChild process module usage (Node.js)src/main.ts:12
    import { type ChildProcess } from 'node:child_process'
  • criticalChild process module usage (Node.js)src/main.ts:23
    let dshProcess: ChildProcess | null = null
  • criticalChild process module usage (Node.js)src/plugin-installer.ts:29
    const { spawn } = await import('node:child_process')
  • criticalChild process module usage (Node.js)src/runtime-manager.ts:7
    import { spawn, type ChildProcess } from 'node:child_process'
  • criticalChild process module usage (Node.js)src/runtime-manager.ts:71
    const child: ChildProcess = spawn(bundledNodeBin(), [bundledPnpmCjs(), ...args], {
  • warningShell command execution (exec / execSync)scripts/collect-runtime.mjs:54
    execFileSync('tar', ['-xf', archive, '-C', target])
  • warningShell command execution (exec / execSync)scripts/collect-runtime.mjs:67
    execFileSync('tar', ['-xzf', tgz, '-C', target, 'package'])

Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-08-17 · activity: Active

• Repo created: 2026-08-19

• Stars: ★ 1 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/harismuna5268/DSH-Desktop

Was this page helpful?