dsh-plugin-audit

Security audit for DeepSeek Harness plugins: static permission profile with file/line evidence + a runtime sentinel gating credential access and unknown-host egress · DSH 插件安全审计:静态权限画像(附文件/行号证据)+ 运行时哨兵,触及凭证或向未知主机外发数据时先请你批准

PluginSecurityDataCode reviewFileNotifications
Verification
L2 · Structured
Security
Pending
Health
Active
Trust
Bronze

What it doesAI

Security audit for DSH plugins: static permission profiling with evidence and runtime sentinel for credential/egress approval.

  • Static permission profile with file/line evidence
  • Runtime sentinel gates credential access
  • Blocks unknown-host egress until approval

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add dsh-plugin-audit

Install method: npm · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated scan, not manual review.

• Dependency vulnerabilities: — (pending)

• Suspicious permissions: — (pending)

• Hardcoded secrets: — (pending)

• Supply chain risks: — (pending)

⚠ Security audit scheduled — results will appear here after the next scan.

Activity

Last commit 2026-08-14 · activity: active

6 mo

Source

GitHub: github.com/jkrandom-sudo/dsh-plugin-audit