dsh-qa avatar

dsh-qa

dsh-qa · QA Workbench — A local software testing workbench plugin for DeepSeek Harness. Zero-dependency test project & iteration management with AI-assisted requirements, test cases, defects, milestones, reports, kanban and calendar.

PluginDesktopProductivity
Verification
L1 · Found
Security
High
Health
Active
Trust
Unrated

What it does

dsh-qa · QA Workbench — A local software testing workbench plugin for DeepSeek Harness. Zero-dependency test project & iteration management with AI-assisted requirements, test cases, defects, milestones, reports, kanban and calendar.

Installation

dsh plugin --profile web add dsh-qa

Install method: npm · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SOHIGH-RISKSCAN15 FILES
43a19b
Automated review · daily
HIGH-RISK

Critical findings in non-blocking categories (dynamic code execution, shell execution, install scripts, obfuscation). Common in CLI/terminal plugins but worth reviewing.

2 critical·8 warning·11 info·15 files scanned
code-exec ×2
plugin version0.1.2dsh manifest
scanned commit43a19b18e7612026-08-19
latest commit43a19b18e761

The scan result is only valid for the scanned commit. If the latest commit differs, the badge shows outdated until the daily pipeline rescans.

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk: High2 critical · 8 warning · 11 info

• Static heuristic scan: done (15 files)

• Dependency vulnerabilities: requires deep audit (L3+)

• Permission sandboxing: requires runtime testing (L4+)

High-risk findings · 10 / 10

  • criticalChild process module usage (Node.js)server/index.js:35
    try { import('node:child_process').then(({ execFile }) => execFile('open', [`http://127.0.0.1:${port}`])); } catch { /* ignore */ }
  • criticalChild process module usage (Node.js)server/routes.js:4
    import { spawn } from 'node:child_process';
  • warningHTTP request to a raw IP addresslib/index.js:80
    writeJson(res, 200, { ok: true, url: `http://127.0.0.1:${state.port}/`, port: state.port, dataDir: state.config?.dataDir || PLUGIN_DATA_DIR
  • warningHTTP request to a raw IP addresslib/index.js:116
    log(`[dsh-qa] 插件就绪${state.error ? `(降级:${state.error})` : `:http://127.0.0.1:${state.port}`}`);
  • warningFilesystem write operationsserver/config.js:36
    fs.writeFileSync(CONFIG_PATH, JSON.stringify(cfg, null, 2), { mode: 0o600 });
  • warningShell command execution (exec / execSync)server/index.js:35
    try { import('node:child_process').then(({ execFile }) => execFile('open', [`http://127.0.0.1:${port}`])); } catch { /* ignore */ }
  • warningHTTP request to a raw IP addressserver/index.js:33
    log(`[dsh-qa] 质量工作台已启动:http://127.0.0.1:${port}(DSH 测试模式,数据 ${DATA_DIR})`);
  • warningHTTP request to a raw IP addressserver/index.js:35
    try { import('node:child_process').then(({ execFile }) => execFile('open', [`http://127.0.0.1:${port}`])); } catch { /* ignore */ }
  • warningFilesystem write operationsserver/store.js:62
    fs.writeFileSync(tmp, JSON.stringify(db, null, 1));
  • warningFilesystem write operationsserver/store.js:206
    fs.writeFileSync(path.join(CONV_DIR, projectId + '.json'), JSON.stringify(conv, null, 1));

Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-08-19 · activity: Active

• Repo created: 2026-08-19

• Stars: ★ 0 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/naodeng/dsh-qa

Was this page helpful?