dsh-port-inspector avatar

dsh-port-inspector

DeepSeek Harness 的 Windows Web 插件,可将本地 TCP 监听回溯至进程、会话与工具调用,保障编程助手安全处理端口冲突/A Windows DSH Web plugin for DeepSeek Harness that traces local TCP listeners back to processes, Sessions, and Tool Calls for safe Coding Agent port-conflict handling.

PluginDeveloperDesktopSecurityTerminal / ShellWeb search
Verification
L3 · Install spec
No plugin features
Risk
Medium
Health
Active
Trust
Silver

What it doesAI

Windows DSH Web plugin that traces local TCP listeners to processes, sessions, and tool calls for safe port-conflict handling in coding agents.

  • Traces TCP listeners to originating processes
  • Maps listeners to Sessions and Tool Calls
  • Prevents coding agent port conflicts

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add dsh-port-inspector@0.1.2

security scan passed · npm package v0.1.2

Install method: npm · sandbox install verified (L4) · L5 pending

Verification & Compatibility

Grouped by plugin version: each card lists the dsh versions actually tested against that artifact version and their install verdicts (L5 wins). Untested combinations are omitted — absence means untested, never assumed compatible. L1–L3 are a plugin-level static archive (independent of the dsh version — the same verdict on every dsh row): they sit in each row's level grid next to L4/L5, marked "static", while their evidence is stored once per plugin inside that row's "checks & evidence" instead of being duplicated per version.

External credentials (plugin-level): none detected

Install compatibility matrix (rows = plugin versions〔latest 5〕, columns = dsh versions〔latest 5〕)
At-a-glance → evidence in the cards below
plugin \ dshdsh 0.1.3-alpha.2
current
v0.1.2·
artifact version unstated

✓ = L5 runtime verified · ◐ = L4 testing (install passed · L5 runtime pending) · ○ not a dsh plugin (nothing mounts) · ✗ failed · · untested (never assumed compatible)

Install compatibility (by plugin version, dsh versions within)
Legend:✓ L5 runtime verified◐ L4 testing · install passed○ no plugin features✗ failed
v0.1.2github2026-09-08

https://github.com/ianho7/dsh-port-inspector

No runtime install test for this version (static scan only) — compatibility unknown, never assumed.

artifact version unstatedgithub2026-09-09

https://github.com/ianho7/dsh-port-inspector

dsh 0.1.3-alpha.2current2026-09-09no plugin features
Environment & artifact
  • • Node.js: v24.14.0
  • • DSH: 0.1.3-alpha.2
  • • Plugin artifact: github · https://github.com/ianho7/dsh-port-inspector (version unstated)
Levels (L1–L3 plugin-level static archive · L4/L5 newest real verdicts for this combination)
L1 static
Passed
L2 static
Passed
L3 static
Passed
L4 sandbox
Unknown
L5 runtime
Not tested
Install test ran: the package installs, but declares no dsh.bundle and mounts no capability — an ordinary npm dependency without plugin features
no plugin features

ID: dsh-port-inspector@ea6b5e@dsh0.1.3-alpha.2 · profile: l4-sandbox

Issued: 2026-09-09 · expires: 2026-09-16

View checks & evidence
L1 · Found✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L2 · Structured✓ Passed
Defaulted from L3✓ Passed
defaulted to passed — L3 install spec passed (full-registry L3 sweep policy)
L3 · Install spec✓ Passed
Install command parsed✓ Passed
Source: registry verification · Method: install spec parse · Captured 2026-09-09
DSH version declared✓ Passed
Source: registry verification · Method: DSH version declaration · Captured 2026-09-09
L4 · Install tested? Unknown
Sandbox install verdict? Unknown
Source: Windows ACL sandbox · Method: sandbox install run · Captured 2026-09-09
spec github:ianho7/dsh-port-inspector · channel GitHub source · outcome unknown
check took: 54.3s
L5 · Run tested– Not tested

This level was not executed in this scan.

L1–L3 are plugin-level static conclusions (baseline, identical across dsh versions): evidence is stored once per plugin.

Author badges

Embed the official badges in your README to showcase security & install-test status:

dsh.so risk
`[![dsh.so risk](https://www.dsh.so/badge/dsh-port-inspector.svg)](https://www.dsh.so/artifact/dsh-port-inspector/)`
dsh.so install
`[![dsh.so install](https://www.dsh.so/badge/install/dsh-port-inspector.svg)](https://www.dsh.so/artifact/dsh-port-inspector/)`

Security Report

Automated static scan, not manual review.

DSH.SO VETMEDIUM5ad914
Automated review · daily
MEDIUM

Vet verdict is suspicious: findings need human review (exfiltration endpoints, file deletion, etc.).

0 critical·3 high·4 medium
plugin version0.1.2dsh manifest
scanned version0.1.2npm2026-09-10
current version0.1.2same version
vet verdictsuspicious · npm

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

RiskRuleLocationDescription
high
R3
windows-scanner.js:160
直接访问 process.parentPid
high
R3
windows-scanner.js:160
直接访问 process.parentPid
high
R10
package.json
install 钩子:package.json scripts.prepare(安装期任意代码执行面)
medium
R2
process-actions.js:23
require() 动态模块加载(npm 包内能力触达)
medium
R2
process-identity.js:17
require() 动态模块加载(npm 包内能力触达)
Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-08-31 · activity: Active

• Repo created: 2026-09-08

• Stars: ★ 2 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/ianho7/dsh-port-inspector

Was this page helpful?