dsh-ugui-preset avatar

dsh-ugui-preset

UGUI制作模式:让 AI agent 在浏览器设计/预览 uGUI,并一键构建工程内可交互、自带测试数据的 uGUI prefab(DSH agent preset)

PluginUI & SkinsBrowserDataVision / OCRFile
Verification
L2 · Structured
Security
Medium
Health
Active
Trust
Silver

What it doesAI

A DSH agent preset for designing and previewing UGUI in the browser and generating interactive prefabs with test data.

  • Browser-based uGUI design/preview
  • One-click interactive prefab generation
  • Includes built-in test data

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add github:BaronCyrus/dsh-ugui-preset

Install method: GitHub · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SO AUDITMEDIUMf6ab3d
Automated review · daily
MEDIUM

Critical findings in non-blocking categories (dynamic code execution, shell execution, install scripts, obfuscation). Common in CLI/terminal plugins but worth reviewing.

5 critical·3 warning·8 info·5 files scanned
code-exec ×3shell ×2
plugin version
scanned commitf6ab3d326fc82026-08-20
latest commitbe35f650e57f

The scan result is valid for the scanned commit. New commits within 7 days are tolerated (the rating still counts); after 7 days without a rescan the badge shows outdated.

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Second-opinion scan (vet · parallel evaluation)
vet: suspicious

vet verdict: vet: suspicious · score 80

  • R3 · info [certain] — 只读 process 成员(能力触达面):process.env
  • R3 · info [certain] (downgraded) — 直接访问 process.exit(Node 能力逃逸通道)
  • R3 · info [certain] (downgraded) — 直接访问 process.exit(Node 能力逃逸通道)
  • R3 · info [certain] — 只读 process 成员(能力触达面):process.platform
  • R6 · info [heuristic] — 字符串特征:child_process 引用

vet is advisory and does not change dsh’s four-tier level.

Risk: Medium5 critical · 3 warning · 8 info

• Static heuristic scan: done (5 files)

• Dependency vulnerabilities: requires deep audit (L3+)

• Permission sandboxing: requires runtime testing (L4+)

High-risk findings · 8 / 8

  • criticalDynamic code execution via the Function constructorplugins/dsh-ugui-tools/lib/client.js:2051
    const factory = new Function("module", "exports", "'use strict';\n" + source + "\n;return module.exports;");
  • criticalChild process module usage (Node.js)plugins/dsh-ugui-tools/lib/host.js:15
    import { execFile } from 'node:child_process'
  • criticalShell command execution (exec / execSync)plugins/dsh-ugui-tools/lib/host.js:238
    execFile(
  • criticalChild process module usage (Node.js)setup/install.mjs:12
    import { execFileSync } from 'node:child_process'
  • criticalShell command execution (exec / execSync)setup/install.mjs:46
    execFileSync(process.platform === 'win32' ? 'pnpm.cmd' : 'pnpm', ['install'], { cwd: dirname(PROFILE_PKG), stdio: 'inherit' })
  • warningmanifest-fs-unfencedagent.cordis.yml
    Mutating filesystem tool has no explicit fs backend in realm
  • warningmanifest-search-unfencedagent.cordis.yml
    Search tool reads without an explicit fs mount
  • warningmanifest-shell-unfencedagent.cordis.yml
    Shell tool without a sandbox runner or policy in realm

Heuristic static scan — may produce false positives. Review the source yourself before trusting.

Activity

Last commit 2026-08-20 · activity: Active

• Repo created: 2026-08-20

• Stars: ★ 0 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/BaronCyrus/dsh-ugui-preset

Was this page helpful?