dsh-native-playbook avatar

dsh-native-playbook

Task-aware native capability manager for DeepSeek Harness — use, prepare, and verify built-in DSH tools before adding another plugin.

PluginAutomationDeveloperStorage
Verification
L2 · Structured
Security
High
Health
Active
Trust
Silver

What it does

Task-aware native capability manager for DeepSeek Harness — use, prepare, and verify built-in DSH tools before adding another plugin.

Installation

dsh plugin --profile web add github:cyanseek/dsh-native-playbook

Install method: GitHub · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SOHIGH-RISKSCAN15 FILES
994465
Automated review · daily
HIGH-RISK

Critical findings in non-blocking categories (dynamic code execution, shell execution, install scripts, obfuscation). Common in CLI/terminal plugins but worth reviewing.

2 critical·0 warning·2 info·15 files scanned
code-exec ×2
plugin version0.2.1dsh manifest
scanned commit994465be9fff2026-08-17
latest commit994465be9fff

The scan result is only valid for the scanned commit. If the latest commit differs, the badge shows outdated until the daily pipeline rescans.

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk: High2 critical · 0 warning · 2 info

• Static heuristic scan: done (15 files)

• Dependency vulnerabilities: requires deep audit (L3+)

• Permission sandboxing: requires runtime testing (L4+)

Scan findings · 4

  • criticalChild process module usage (Node.js)scripts/prepack.mjs:2
    import { spawnSync } from 'node:child_process'
  • criticalChild process module usage (Node.js)src/dsh-process.ts:1
    import { execFile } from 'node:child_process'
  • infoReads process.envsrc/dsh-process.ts:26
    const result = await execFileAsync(process.env.ComSpec ?? 'cmd.exe', ['/d', '/s', '/c', dshCommand, ...args], {
  • infoReads process.envsrc/install.ts:19
    : join(options.dshHome ?? process.env.DSH_HOME ?? join(homedir(), '.dsh'), 'skills')

Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-08-15 · activity: Active

• Repo created: 2026-08-17

• Stars: ★ 4 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/cyanseek/dsh-native-playbook

Was this page helpful?