dsh-plugin-hub avatar

dsh-plugin-hub

Minimal jelly Plugin Hub and equipment sidebar for DeepSeek Harness

PluginUI & SkinsDesktop
Verification
L4 · Install tested
Passed
Risk
Medium
Health
Active
Trust
Silver

What it doesAI

A minimal web UI sidebar for managing, equipping, and trying out plugins in DeepSeek Harness.

  • Equip or dispose plugins via drag-and-drop
  • Temporarily run and test plugins before disposal
  • Creates an isolated .runtime home to avoid changes

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add github:Fogggy-Chao/dsh-plugin-hub
verified

Install method: GitHub · sandbox install verified (L4) · L5 pending

Verification & Compatibility

Records are archived per dsh version under test: each card shows the newest real L1–L5 verdicts on that version (static levels included; fall back to all-time newest with a carried note when absent).

External credentials (plugin-level): none detected

Per-dsh-version verification (L1–L5)
dsh 0.1.3-alpha.1current2026-09-07L5 pending
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.3-alpha.1
  • • Plugin artifact: github · https://github.com/Fogggy-Chao/dsh-plugin-hub (version unstated)
Levels (newest real verdicts on this version)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Passed
L5 runtime
Not tested
Sandbox install passed (L4)
L5 pending

ID: dsh-plugin-hub-11@2f24e7@dsh0.1.3-alpha.1 · profile: l4-sandbox

Issued: 2026-09-07 · expires: 2026-09-14

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-07
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-07
L4 · Install tested✓ Passed
Install executed in confined sandbox✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-07
spec github:Fogggy-Chao/dsh-plugin-hub · channel GitHub source · outcome ran · exit 0
check took: 3.7s
Install succeeded✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-07
spec github:Fogggy-Chao/dsh-plugin-hub · channel GitHub source · outcome ran · exit 0
check took: 3.7s
Installed artifact confirmed✓ Passed
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-07
spec github:Fogggy-Chao/dsh-plugin-hub · channel GitHub source · outcome ran · exit 0
check took: 3.7s
L5 · Run tested– Not tested

This level was not executed in this scan.

Author badges

Embed the official badges in your README to showcase security & install-test status:

dsh.so risk
`[![dsh.so risk](https://www.dsh.so/badge/dsh-plugin-hub-11.svg)](https://www.dsh.so/artifact/dsh-plugin-hub-11/)`
dsh.so install
`[![dsh.so install](https://www.dsh.so/badge/install/dsh-plugin-hub-11.svg)](https://www.dsh.so/artifact/dsh-plugin-hub-11/)`

Security Report

Automated static scan, not manual review.

DSH.SO VETMEDIUM74acde
Automated review · daily
MEDIUM

Vet verdict is suspicious: findings need human review (exfiltration endpoints, file deletion, etc.).

0 critical·1 high·0 medium
plugin version0.6.4dsh manifest
scanned commit74acdec007a02026-09-07
latest commit74acdec007a0
vet verdictsuspicious · git

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

RiskRuleLocationDescription
high
R3
marketplace.js:26
直接访问 process.kill
Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-09-06 · activity: Active

• Repo created: 2026-09-06

• Stars: ★ 0 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/Fogggy-Chao/dsh-plugin-hub

Was this page helpful?