What it doesAI
A DSH agent preset for designing and previewing UGUI in the browser and generating interactive prefabs with test data.
- Browser-based uGUI design/preview
- One-click interactive prefab generation
- Includes built-in test data
AI-generated from the repo README — for reference only.
Installation
dsh plugin --profile web add github:BaronCyrus/dsh-ugui-presetInstall method: GitHub · not yet tested in container (L3+)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
Requirements
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
Critical findings in non-blocking categories (dynamic code execution, shell execution, install scripts, obfuscation). Common in CLI/terminal plugins but worth reviewing.
code-exec ×3shell ×2—f6ab3d326fc82026-08-20be35f650e57fThe scan result is valid for the scanned commit. New commits within 7 days are tolerated (the rating still counts); after 7 days without a rescan the badge shows outdated.
Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
vet verdict: vet: suspicious · score 80
- R3 · info [certain] — 只读 process 成员(能力触达面):process.env
- R3 · info [certain] (downgraded) — 直接访问 process.exit(Node 能力逃逸通道)
- R3 · info [certain] (downgraded) — 直接访问 process.exit(Node 能力逃逸通道)
- R3 · info [certain] — 只读 process 成员(能力触达面):process.platform
- R6 · info [heuristic] — 字符串特征:child_process 引用
vet is advisory and does not change dsh’s four-tier level.
• Static heuristic scan: done (5 files)
• Dependency vulnerabilities: requires deep audit (L3+)
• Permission sandboxing: requires runtime testing (L4+)
High-risk findings · 8 / 8
- criticalDynamic code execution via the Function constructorplugins/dsh-ugui-tools/lib/client.js:2051const factory = new Function("module", "exports", "'use strict';\n" + source + "\n;return module.exports;");
- criticalChild process module usage (Node.js)plugins/dsh-ugui-tools/lib/host.js:15import { execFile } from 'node:child_process'
- criticalShell command execution (exec / execSync)plugins/dsh-ugui-tools/lib/host.js:238execFile(
- criticalChild process module usage (Node.js)setup/install.mjs:12import { execFileSync } from 'node:child_process'
- criticalShell command execution (exec / execSync)setup/install.mjs:46execFileSync(process.platform === 'win32' ? 'pnpm.cmd' : 'pnpm', ['install'], { cwd: dirname(PROFILE_PKG), stdio: 'inherit' })
- warningmanifest-fs-unfencedagent.cordis.ymlMutating filesystem tool has no explicit fs backend in realm
- warningmanifest-search-unfencedagent.cordis.ymlSearch tool reads without an explicit fs mount
- warningmanifest-shell-unfencedagent.cordis.ymlShell tool without a sandbox runner or policy in realm
Heuristic static scan — may produce false positives. Review the source yourself before trusting.
Activity
Last commit 2026-08-20 · activity: Active
• Repo created: 2026-08-20
• Stars: ★ 0 · Forks: 0
• Health: Active — committed within last 30 days
