dsh-model-plus avatar

dsh-model-plus

PluginAI ModelsStorage
Verification
L1 · Found
Security
Medium
Health
Active
Trust
Unrated

What it doesAI

A DSH Web plugin that adds a Model Plus settings page for model management and synchronization.

  • Adds Model Plus entry to settings page
  • Provides sync source options: official source, etc.
  • Publishable DSH Web plugin package

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add @kingsunb/dsh-model-plus

Install method: npm · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SO VETMEDIUMc0ca27
Automated review · daily
MEDIUM

Vet verdict is suspicious: findings need human review (exfiltration endpoints, file deletion, etc.).

0 critical·4 high·2 medium·19 score
plugin version
scanned commitc0ca2754165c2026-08-21
latest commitc0ca2754165c
vet verdictsuspicious · gitscore 19

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

RiskRuleLocationDescription
high
R2
security-smoke.mjs:24
new Function / new AsyncFunction 动态执行
high
R13
security-smoke.mjs:62
硬编码外联端点:AWS 云元数据端点(IAM 凭据外泄面)
high
R13
index.js:162
硬编码外联端点:云元数据端点(IAM 凭据外泄面)
high
R13
index.js:163
硬编码外联端点:AWS 云元数据端点(IAM 凭据外泄面)
medium
R9
index.js:62
正则嵌套量词(ReDoS 风险:(a+)+ 类指数回溯)
Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-08-16 · activity: Active

• Repo created: 2026-08-21

• Stars: ★ 0 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/kingsunb/dsh-model-plus

Was this page helpful?