What it doesAI
A durable, approval-gated project orchestration workbench with Web UI, CLI, and persistent local audit trail for DeepSeek Harness.
- Adds Host service, responsive Web workbench, and loopback CLI
- Tracks Projects, Issues, TaskRuns, human Decisions, and Agent capacity
- Stores Transcripts, Artifacts, and automation receipts in local audit trail
AI-generated from the repo README — for reference only.
Installation
dsh plugin --profile web add dsh-project-orchestratorInstall method: npm · not yet tested in container (L3+)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
Requirements
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
Critical findings in non-blocking categories (dynamic code execution, shell execution, install scripts, obfuscation). Common in CLI/terminal plugins but worth reviewing.
code-exec ×21.2.0dsh manifest0fd794a518782026-08-200fd794a51878The scan result is valid for the scanned commit. New commits within 7 days are tolerated (the rating still counts); after 7 days without a rescan the badge shows outdated.
Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
vet verdict: vet: clean · score 94
- R3 · info [certain] — 只读 process 成员(能力触达面):process.argv
- R3 · info [certain] — 只读 process 成员(能力触达面):process.env
- R3 · info [certain] — 只读 process 成员(能力触达面):process.stdout
- R3 · info [certain] — 只读 process 成员(能力触达面):process.stdout
- R3 · info [certain] — 只读 process 成员(能力触达面):process.stderr
vet is advisory and does not change dsh’s four-tier level.
• Static heuristic scan: done (14 files)
• Dependency vulnerabilities: requires deep audit (L3+)
• Permission sandboxing: requires runtime testing (L4+)
High-risk findings · 3 / 3
- criticalChild process module usage (Node.js)scripts/package-smoke.mjs:1import { execFile } from 'node:child_process'
- criticalChild process module usage (Node.js)src/service.ts:4import { spawn } from 'node:child_process'
- warningHTTP request to a raw IP addresssrc/cli.ts:10const baseUrl = takeOption(args, '--url') ?? process.env.DSH_PROJECT_ORCHESTRATOR_URL ?? 'http://127.0.0.1:3080/project-orchestrator/api'
Heuristic static scan — may produce false positives. Review the source yourself before trusting.
Activity
Last commit 2026-08-20 · activity: Active
• Repo created: 2026-08-20
• Stars: ★ 3 · Forks: 0
• Health: Active — committed within last 30 days
