What it doesAI
威胁建模技能插件,支持攻击树构建、STRIDE威胁分类、缓解映射与安全需求提取。
- 攻击树构建:OR/AND/叶子节点+成本时间技能检测属性
- STRIDE六类威胁分类与缓解措施映射
- 安全需求提取与残余风险管理
AI-generated from the repo README — for reference only.
Installation
dsh plugin --profile web add github:satan9394/dsh-threat-modelingInstall method: GitHub · not yet tested in container (L3+)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
Requirements
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
No critical or warning findings in the automated scan. The result is valid only for the commit hash shown.
0.1.0dsh manifest2c16b3e21e152026-08-202c16b3e21e15The scan result is valid for the scanned commit. New commits within 7 days are tolerated (the rating still counts); after 7 days without a rescan the badge shows outdated.
Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
vet verdict: vet: clean · score 94
- R10 · info [heuristic] — 依赖清单:1 项(yaml,供 LLM 审计供应链;已知漏洞核对见后续 OSV 精确版本查询(网络失败静默降级))
- R12 · info [heuristic] (downgraded) — engines.node=>=20.0.0 低于 DSH 运行要求(>=22.19),可能不兼容
- R9 · medium [likely] — 正则嵌套量词(ReDoS 风险:(a+)+ 类指数回溯)
vet is advisory and does not change dsh’s four-tier level.
• Static heuristic scan: done (3 files)
• Dependency vulnerabilities: requires deep audit (L3+)
• Permission sandboxing: requires runtime testing (L4+)
Activity
Last commit 2026-08-19 · activity: Active
• Repo created: 2026-08-20
• Stars: ★ 0 · Forks: 0
• Health: Active — committed within last 30 days
