dsh-plugin-security-audit avatar

dsh-plugin-security-audit

Static security audit for dynamic Cordis plugins in DeepSeek Harness (DSH): rule-based source scanning, risk reports injected into tool results, and user-approval escalation before activating high-risk plugin packages. 动态 Cordis 插件静态安全审查。

PluginSecurityCode review
Verification
L2 · Structured
Security
Pending
Health
Active
Trust
Bronze

What it does

Static security audit for dynamic Cordis plugins in DeepSeek Harness (DSH): rule-based source scanning, risk reports injected into tool results, and user-approval escalation before activating high-risk plugin packages. 动态 Cordis 插件静态安全审查。

Installation

dsh plugin --profile web add github:chendengyuanxm/dsh-plugin-security-audit

Install method: GitHub · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SONOT SCANNEDSCAN— FILES
------
Automated review · daily
NOT SCANNED

No security scan record for this plugin yet. Newly indexed plugins are scanned by the daily pipeline.

0 critical·0 warning·0 info· files scanned
plugin version
scanned commit
latest commitb80b3e28bbec

The scan result is only valid for the scanned commit. If the latest commit differs, the badge shows outdated until the daily pipeline rescans.

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

• Static heuristic scan: pending

• Dependency vulnerabilities:

• Hardcoded secrets:

• Supply chain risks:

⚠ Static scan not run yet — results will appear here.

Activity

Last commit 2026-08-15 · activity: Active

• Repo created: 2026-08-18

• Stars: ★ 0 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/chendengyuanxm/dsh-plugin-security-audit

Was this page helpful?