What it does
dsh-qa · QA Workbench — A local software testing workbench plugin for DeepSeek Harness. Zero-dependency test project & iteration management with AI-assisted requirements, test cases, defects, milestones, reports, kanban and calendar.
Installation
dsh plugin --profile web add dsh-qaInstall method: npm · not yet tested in container (L3+)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
Requirements
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
Critical findings in non-blocking categories (dynamic code execution, shell execution, install scripts, obfuscation). Common in CLI/terminal plugins but worth reviewing.
code-exec ×20.1.2dsh manifest43a19b18e7612026-08-1943a19b18e761The scan result is only valid for the scanned commit. If the latest commit differs, the badge shows outdated until the daily pipeline rescans.
Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
• Static heuristic scan: done (15 files)
• Dependency vulnerabilities: requires deep audit (L3+)
• Permission sandboxing: requires runtime testing (L4+)
High-risk findings · 10 / 10
- criticalChild process module usage (Node.js)server/index.js:35try { import('node:child_process').then(({ execFile }) => execFile('open', [`http://127.0.0.1:${port}`])); } catch { /* ignore */ }
- criticalChild process module usage (Node.js)server/routes.js:4import { spawn } from 'node:child_process';
- warningHTTP request to a raw IP addresslib/index.js:80writeJson(res, 200, { ok: true, url: `http://127.0.0.1:${state.port}/`, port: state.port, dataDir: state.config?.dataDir || PLUGIN_DATA_DIR
- warningHTTP request to a raw IP addresslib/index.js:116log(`[dsh-qa] 插件就绪${state.error ? `(降级:${state.error})` : `:http://127.0.0.1:${state.port}`}`);
- warningFilesystem write operationsserver/config.js:36fs.writeFileSync(CONFIG_PATH, JSON.stringify(cfg, null, 2), { mode: 0o600 });
- warningShell command execution (exec / execSync)server/index.js:35try { import('node:child_process').then(({ execFile }) => execFile('open', [`http://127.0.0.1:${port}`])); } catch { /* ignore */ }
- warningHTTP request to a raw IP addressserver/index.js:33log(`[dsh-qa] 质量工作台已启动:http://127.0.0.1:${port}(DSH 测试模式,数据 ${DATA_DIR})`);
- warningHTTP request to a raw IP addressserver/index.js:35try { import('node:child_process').then(({ execFile }) => execFile('open', [`http://127.0.0.1:${port}`])); } catch { /* ignore */ }
- warningFilesystem write operationsserver/store.js:62fs.writeFileSync(tmp, JSON.stringify(db, null, 1));
- warningFilesystem write operationsserver/store.js:206fs.writeFileSync(path.join(CONV_DIR, projectId + '.json'), JSON.stringify(conv, null, 1));
Heuristic static scan — may produce false positives. Review the source yourself before trusting.
Activity
Last commit 2026-08-19 · activity: Active
• Repo created: 2026-08-19
• Stars: ★ 0 · Forks: 0
• Health: Active — committed within last 30 days
Source
GitHub: github.com/naodeng/dsh-qa
