dsh-remote avatar

dsh-remote

Remote access for DeepSeek Harness: account/password auth + MFA (TOTP) login gate, signed session cookies, role-based access, in-browser directory picker, and a Settings page for account management.

PluginSecurityBrowserStorageWeb search
Verification
L2 · Structured
Security
Low
Health
Active
Trust
Silver

What it does

Remote access for DeepSeek Harness: account/password auth + MFA (TOTP) login gate, signed session cookies, role-based access, in-browser directory picker, and a Settings page for account management.

Installation

dsh plugin --profile web add dsh-remote-3

Install method: npm · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SOPASSEDSCAN7 FILES
ea4875
Automated review · daily
PASSED

No critical or warning findings in the automated scan. The result is valid only for the commit hash shown.

0 critical·0 warning·5 info·7 files scanned
scanned commitea4875bf83f72026-08-17
latest commitea4875bf83f7

The scan result is only valid for the scanned commit. If the latest commit differs, the badge shows outdated until the daily pipeline rescans.

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk: Low0 critical · 0 warning · 5 info

• Static heuristic scan: done (7 files)

• Dependency vulnerabilities: requires deep audit (L3+)

• Permission sandboxing: requires runtime testing (L4+)

Scan findings · 5

  • infoMakes network requests (fetch / axios)lib/client.js:237
    res = await fetch(path, {
  • infoHardcoded IP addresslib/index.js:420
    const authority = `127.0.0.1:${webServer.port ?? "3080"}`;
  • infoMakes network requests (fetch / axios)lib/login-page.js:307
    var res = await fetch("/auth/mfa/setup", {
  • infoMakes network requests (fetch / axios)lib/login-page.js:350
    var res = await fetch("/auth/mfa/verify", {
  • infoMakes network requests (fetch / axios)lib/login-page.js:401
    var res = await fetch(phase === "code" ? "/auth/mfa/login" : endpoint, {

Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-08-17 · activity: Active

• Repo created: 2026-08-17

• Stars: ★ 4 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/xgone/dsh-remote

Was this page helpful?