dsh-plugin-audit avatar

dsh-plugin-audit

PluginSecurityCode reviewFile
Verification
L1 · Found
Security
Low
Health
Active
Trust
Unrated

What it doesAI

Audits source code of third-party DSH plugins before installation to judge safety.

  • Locates dangerous signals via deterministic scan script
  • Forces evidence-based conclusions with file, line, semantics
  • States coverage boundaries and reminds locking versions

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add github:wefio/dsh-plugin-audit

Install method: GitHub · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SO VETPASSED5ca7f2
Automated review · daily
PASSED

Vet static analysis found no suspicious behavior — verdict is clean.

0 critical·0 high·0 medium·100 score
plugin version
scanned commit5ca7f2b016d52026-08-21
latest commit5ca7f2b016d5
vet verdictclean · gitscore 100

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

No critical or warning findings.

Activity

Last commit 2026-08-14 · activity: Active

• Repo created: 2026-08-21

• Stars: ★ 2 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/wefio/dsh-plugin-audit

Was this page helpful?