What it does
Sticky notes for DeepSeek Harness: draggable notes with text & image support, 9 skins, and AI-powered read/write. DeepSeek Harness 便签插件:可拖拽,支持文字与图片、9 款皮肤,AI 可读写。
Installation
dsh plugin --profile web add dsh-sticky-notesInstall method: npm · not yet tested in container (L3+)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
Requirements
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
No critical or warning findings in the automated scan. The result is valid only for the commit hash shown.
edd0c975b34a2026-08-17edd0c975b34aThe scan result is only valid for the scanned commit. If the latest commit differs, the badge shows outdated until the daily pipeline rescans.
Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
• Static heuristic scan: done (4 files)
• Dependency vulnerabilities: requires deep audit (L3+)
• Permission sandboxing: requires runtime testing (L4+)
Scan findings · 4
- infoUses localStoragelib/client.js:136const raw = localStorage.getItem(BOARD_KEY)
- infoUses localStoragelib/client.js:140console.log('[dsh-sticky-notes] 从 localStorage 加载', notes.length, '张便签')
- infoUses localStoragelib/client.js:144console.log('[dsh-sticky-notes] localStorage 无便签数据,创建默认空便签')
- infoMakes network requests (fetch / axios)lib/client.js:191const res = await fetch(path, body === undefined ? {} : {
Heuristic static scan — may produce false positives. Review the source yourself before trusting.
Activity
Last commit 2026-08-17 · activity: Active
• Repo created: 2026-08-17
• Stars: ★ 4 · Forks: 1
• Health: Active — committed within last 30 days
