
dsh-product
dsh-product 是一个“互联网资讯查询 + 本地项目上下文”的 DeepSeek Harness 插件,用于把已经确认的产品机会转化为可验证、可交付、可迭代的产品。 dsh-product is a web-aware DeepSeek Harness plugin that combines public internet research with local product context to turn a validated opportunity handoff into a shippable, observable and iterated product.
What it doesAI
Web-aware plugin combining internet research with local product context to develop deliverable, iterable products.
- Combines web research with local product context
- Turns validated opportunities into shippable products
- Supports observable, iterative product development
AI-generated from the repo README — for reference only.
Installation
dsh plugin --profile web add github:winyh/dsh-productInstall method: GitHub · not yet tested in container (L3+)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
Requirements
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
No critical or warning findings in the automated scan. The result is valid only for the commit hash shown.
0.1.0dsh manifested21d4eae5232026-08-20ed21d4eae523The scan result is valid for the scanned commit. New commits within 7 days are tolerated (the rating still counts); after 7 days without a rescan the badge shows outdated.
Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
vet verdict: vet: clean · score 100
- R10 · info [heuristic] — 依赖清单:29 项(@deepseek-ai/dsh-web, @deepseek-ai/dsh-web-fetch-http, @deepseek-ai/schemastery, @deepseek-ai/cordis, @deepseek-ai/dsh-agent, @deepseek-ai/dsh-brand, @deepseek-ai/dsh-code-runtime, @deepseek-ai/dsh-fs, @deepseek-ai/dsh-invariants, @deepseek-ai/dsh-llm, @deepseek-ai/dsh-sandbox, @deepseek-ai/dsh-scope, @deepseek-ai/dsh-session, @deepseek-ai/dsh-system-prompt, @deepseek-ai/dsh-timeout, @deepseek-ai/dsh-tools, @deepseek-ai/dsh-typert-protocol, @deepseek-ai/dsh-user-approval, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, eslint, tsdown, typescript, vitest, @deepseek-ai/cordis, @deepseek-ai/dsh-fs, @deepseek-ai/dsh-scope, @deepseek-ai/dsh-tools,供 LLM 审计供应链;已知漏洞核对见后续 OSV 精确版本查询(网络失败静默降级))
- R12 · info [certain] (downgraded) — 入口文件缺失:./lib/index.mjs
- R3 · info [certain] — 只读 process 成员(能力触达面):process.cwd
- R9 · info [heuristic] — 循环内 += 累加(字符串拼接可能 O(n²))
- R9 · info [heuristic] — 循环内 += 累加(字符串拼接可能 O(n²))
vet is advisory and does not change dsh’s four-tier level.
• Static heuristic scan: done (15 files)
• Dependency vulnerabilities: requires deep audit (L3+)
• Permission sandboxing: requires runtime testing (L4+)
Activity
Last commit 2026-08-20 · activity: Active
• Repo created: 2026-08-20
• Stars: ★ 0 · Forks: 0
• Health: Active — committed within last 30 days
Source
GitHub: github.com/winyh/dsh-product