What it doesAI
DSH plugin compatibility audit and bounded Loader lifecycle observation service.
- Audits plugin manifests and dsh.bundle.patch files
- Checks DSH/Cordis/Node ranges and dependencies
- Registers read-only tools via public interfaces
AI-generated from the repo README — for reference only.
Installation
dsh plugin --profile web add dsh-plugin-observatoryInstall method: npm · not yet tested in container (L3+)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
Requirements
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
No critical or warning findings in the automated scan. The result is valid only for the commit hash shown.
0.1.0dsh manifest3fc8f9aeda532026-08-203fc8f9aeda53The scan result is valid for the scanned commit. New commits within 7 days are tolerated (the rating still counts); after 7 days without a rescan the badge shows outdated.
Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
vet verdict: vet: clean · score 100
- R3 · info [certain] — 只读 process 成员(能力触达面):process.version
- R3 · info [certain] — 只读 process 成员(能力触达面):process.version
- R3 · info [certain] — 只读 process 成员(能力触达面):process.version
- R6 · info [heuristic] — 字符串特征:process 敏感成员引用
- R9 · info [heuristic] — 无出口常驻循环(含 await,可能是合法服务循环;交由 LLM 审计复核上下文)
vet is advisory and does not change dsh’s four-tier level.
• Static heuristic scan: done (6 files)
• Dependency vulnerabilities: requires deep audit (L3+)
• Permission sandboxing: requires runtime testing (L4+)
Activity
Last commit 2026-08-19 · activity: Active
• Repo created: 2026-08-20
• Stars: ★ 1 · Forks: 0
• Health: Active — committed within last 30 days
